Security Claims & Facts CLAIM CLAIMFlock has inadequate security standards. Flock has been hacked. FACT FACT
Flock is relentlessly focused on data Flock’s platform has never been integrity and security, and secures hacked. A recent YouTube video claims data in accordance with the highest “80,000 cameras” have been hacked. industry requirements. This includes This is false. The YouTuber in question strict encryption standards that use a gained limited access to one older 256-bit key to convert plain text into generation camera that had never been cipher – virtually impenetrable to connected to our system and had brute-force attacks. Flock adheres to never received a security update, which the following security frameworks and we push out frequently. Flock cameras certifications, amongst others:
are not connected to each other; access to one does not provide accessISO 27001 compliance certification to any others. No access to Flock’s (an international framework for IT cloud environment is possible via a security) camera. All customer data collected by SOC 2 Type II, assessed by an audit Flock devices is encrypted at rest, in that assesses an organization’s transit, and while stored in the cloud. controls over its data and system Flock’s cloud storage has never been NIST 800-53, an information compromised. security standard defined by the National Institute of Standards and Technology (NIST)
Secure By Design principles program authored by the Cybersecurity and Infrastructure Security Agency (CISA)
flocksafety.com (866) 901-1781 | support@flocksafety.comCLAIM clAIM It is possible to hack into Flock’s cloud Flock does not update our hardware or database from a Flock camera. mitigate identified vulnerabilities in our FACT hardware system. It is not possible to hack into Flock’s FACT cloud database from a Flock camera. Alleged vulnerabilities circulating on the Flock publicly discloses identified internet have no effect on our cloud vulnerabilities on a regular basis to the platform, where evidence and metadata public vulnerability database is stored. Images sent to the cloud are maintained by MITRE, most recently in fully encrypted in transit. May 2025. Vulnerability identification and remediation is an ongoing process.
CLAIM CLAIM Flock does not require Multi-Factor Foreign adversaries have access to the Authentication for customers. Flock system. FACT FACT In November 2024, Flock made Multi- There is zero evidence that foreign actors Factor Authentication (MFA) the have or have had any access whatsoever to default for all users, supported Flock’s system or cloud platform. through common providers including Okta and Google Authenticator. For Single Sign-On (SSO), Flock supports multiple authentication methods including SAML, OIDC, and Azure- specific SSO. Following the decision to make MFA default, Flock proactively conducted outreach to thousands of law enforcement agencies to help them enable MFA, and the vast majority of Flock’s law enforcement customers now use either MFA or SSO.
flocksafety.com (866) 901-1781 | support@flocksafety.com