footnote4a

Mass surveillance, government contracts, and other bedtime reading.

Flock's Bishop Fox engagement: Six months later

It has been six months since Flock engaged Bishop Fox and promised the results of security audits would be "communicated transparently." To date, no security issues have been fixed, and no results have been communicated.

by H.C. van Pelt
4 min read
security

Bishop Fox’s offensive security experts will engage in complex, multistage and multilayer adversarial testing across all of Flock’s products, both hardware and software. The results and any ensuing updates will be communicated transparently to reinforce confidence in Flock’s strong security posture.

Flock Safety Engages Bishop Fox to Set the Industry Standard in Cybersecurity for its Public Safety Platform, Flock via GlobeNewswire, Feb 2, 2026

That February 2026 press release followed signifiicant bad press after a series of vulnerabilities had been discovered:

Despite having been independently validated and assigned CVEs (including severity 9.8, CVE-2025-59407), Flock’s response has been — and continues to be — a combination of outright denial and deflection.

To any critical observer, it was obvious from the outset that the security audit by Bishop Fox was never going to work, and that the engagement was little more than a PR stunt. Flock even said as much when saying the goal wasn’t to improve its security but “to reinforce confidence” in it.

In a March 27, 2026, blog post (archive), Flock already quietly downgraded the Bishop Fox engagement from the “complex, multistage and multilayer adversarial testing across all of Flock’s products, both hardware and software” from the month before to a “regular annual penetration test.”[1]

Two months later, Flock’s CISO, Chris Castaldo, obliquely referenced outside audits in a YouTube video where he said, “[t]he really important thing when it comes to saying you’re secure — or your product is secure — is someone other than you doing that analysis.” He did not mention Bishop Fox — or anyone else — was conducting such an audit for Flock. Seems like something one might mention in a promotional video about security.

Another two months later — in July 2026, six months after the Bishop Fox announcement — Flock published a YouTube short where CEO Garrett Langley says: “We partnered with Bishop Fox months ago to start running an internal audit of how we can strengthen our security posture. We will continue to work with them for the years to come. Continuing to harden and protect this valuable technology.”[2]

Flock’s CVE entries have not been updated since late 2025, meaning the same vulnerabilities still exist across tens of thousands of cameras deployed nationwide, and used to support warrants and as evidence in criminal trials. There is no telling how many people have been arrested or convicted because of evidence sourced from Flock’s insecure system. According to Flock, it’s many.

In the span of six months, Flock went from announcing a complex across-the-board red-team exercise, where findings would be “communicated transparently” to an “internal audit” that appears to be nothing more than the minimum pentest required for SOC.2 compliance. Its “public safety” hardware and software is as insecure as it was six months ago.

While Langley and Castaldo are publishing YouTube videos minimizing the issues and reframing the Bishop Fox engagement, Flock sales won’t answer questions about the whole ordeal because you can’t believe what you hear on YouTube. Maybe they have a point.


  1. The industry standard for this appears to be having an intern at a buddy’s company run Metasploit and creating a few tickets for ops so it can be marked in the SOC.2 paperwork. ↩︎

  2. The phrase Flock chose is “protect the technology,” not “protect the data.” ↩︎