Policy, law & configuration
Ten safeguards stated in Burbank's policy and configuration, and the state statutes behind them.
30-day retention
Policy 462 sets a 30-day retention limit with automatic deletion, subject to investigative and legal-preservation exceptions.
California-only sharing
Policy 462 restricts sharing to California — more restrictive than the state baseline. It's a Burbank policy and configuration choice, not an SB 34 mandate.
No civil immigration use
Policy 462 and the California Values Act framework restrict use of the data for civil immigration enforcement.
Search logging & justification
BPD states every search is logged with a user ID and time stamp and requires a case or reference number and a reason.
Annual audit
Policy 462 requires an annual audit of the ALPR system; BPD states supervisory audits check for misuse.
Role-based access + MFA
BPD states access is limited to trained authorized personnel via role-based permissions and multifactor authentication.
No sale of data
Policy 462 states ALPR data "shall not be sold to any entity, either public or private."
Published usage & privacy policy
California Civil Code §§1798.90.51–.53 require operators to adopt and post a usage/privacy policy: authorized purposes, personnel, monitoring, retention, and destruction.
Reasonable security & access records
State law requires reasonable security procedures protecting ALPR data and records of who accesses it.
Alert verification through CLETS
Policy 462 states officers "should verify" an ALPR response through CLETS before acting on an alert. The word "should" reads as advisory rather than mandatory.
California's SB 34 (2015), the California Values Act (SB 54), and Civil Code §§1798.90.5–.55 set the statewide rules. Full citations and links are on the Sources page.
How the data is secured
The stated security posture for the platform Burbank uses — from Flock's documentation, plus what an independent registry confirms.
Encryption in transit
Data crossing public networks uses "TLS 1.2 or better" with a NIST-aligned cipher suite (AES128-SHA256 or better).
Encryption at rest
Stored data uses "encryption-at-rest to AES256 or better." Burbank likewise cites AES-256.
Least-privilege access
Access permissions are "role-based grants, on the principle of least privilege," and "multifactor authentication is mandatory."
Audit logging
Every search is recorded with a user ID and time stamp and must relate to a specific investigation; intrusion detection runs with real-time logging.
FedRAMP authorized (Low)
The "Flock Safety Platform" is listed on the U.S. FedRAMP Marketplace, authorized July 25, 2025 — at the Low impact level, not Moderate or High.
SOC 2 & ISO listed
Flock lists SOC 2 Type II, ISO/IEC 27001, and CJIS. Flock notes SOC 2 is "an opinion-based audit, not a certification"; the reports are access-gated.
Who owns the data & how sharing works
Contract and configuration terms that govern ownership, sale, and how data can leave the system.
The agency owns the data
Contract terms · Flock & BPD
Customer ownership
"All right, title, and interest in and to Customer Data belong to and are retained by Customer." Burbank states the City retains ownership of all its data.
No sale; unauthorized sharing is a breach
Flock "shall not sell Customer Data"; sharing not authorized by the customer "shall constitute a prima facie breach." All sharing is "off by default."
Agency-controlled sharing
Sharing "never happens automatically" and is turned on by the agency. A national network and "National Lookup" exist; Burbank states these are disabled.
Where data is stored
Cloud storage & encrypted lifecycle · Flock
Amazon Web Services, encrypted lifecycle
Flock uses AWS cloud storage and KMS-based encryption, with data "encrypted throughout its entire lifecycle, from on-device to storage in the cloud."
Criminal-justice data in AWS GovCloud
"All CJIS data is stored in the AWS GovCloud and is only available to Law Enforcement agencies." Data is not stored outside the United States.
The one event that tested access governance
Two May 2025 federal (VA Police) searches crossed Burbank's stated boundary and were caught by the Department's own audit — evidence that access controls depend on active auditing.
Reading the security question honestly
Flock publishes strong stated safeguards and holds a low-level federal FedRAMP authorization and third-party attestations; Burbank adds AES-256 encryption, ISO 27001 storage, CISA "Secure by Design," multifactor authentication, and yearly audits. On Burbank's own record there is no identified breach, and the one documented access event was surfaced by audit and corrected. "Secure" is therefore best read as encrypted and certified at the platform level, with residual risk concentrated in configuration and access governance — which is why the audit that caught the VA searches matters.
Check the underlying rules yourself.
The source library contains the policy, California statutes, contract material, and vendor security documentation referenced above.