This series has graded five suppliers of public-safety surveillance against a single question: does what the company tells the public match what it writes in its own binding documents? Flock Safety got 43, Motorola Solutions 46, Genetec 62, Axon 62, Rekor 41. The sixth entry breaks the pattern the first five established. Every previous card measured a distance between two documents. This one measures the distance between a document and nothing at all. Eight disclosure areas, scored 0–100, every measurement read from a page Neology published itself. Reporting on documents, not legal advice.
The method, and a harder limit than usual
Everything below was read from neology.com on July 31, 2026: the Privacy policy (Last updated: June 1, 2023), the Terms, the Information Security Policy for Third Parties (Last updated: April 4, 2025), the About page, the Road Safety & Enforcement section, the Law Enforcement & Public Safety page, and the product pages for neoForce™, neoGuard™, P720 and P497. No leaks, no contracts, no internal sources.
To establish what is not published rather than merely what this journal failed to find, the site’s own machine-readable index was used: neology.com/page-sitemap.xml, generated by the company’s SEO plugin, which enumerates thirty-two public pages. That list is reproduced in the sources below. It is the whole of Neology’s public web estate, and it is the basis for every statement in this card about an absence.
Three limits, stated before the grades.
First, the standing warning of this series: an absent disclosure is not proof of a bad practice. Nothing below establishes that Neology mishandled anyone’s data. A company can run a disciplined data operation and publish nothing about it. What this card measures is whether a resident, a council member, or a procurement officer can find out — and on that question the answer is checkable.
Second, and this deserves more weight here than on any previous card: Neology’s business model genuinely explains part of the silence. Flock hosts its customers’ plate reads and operates a shared national network; the data sits on Flock’s infrastructure, so Flock has a great deal to disclose. Neology largely sells cameras, roadside hardware and back-office software that agencies run on their own systems, plus tolling infrastructure operated under contract with transportation authorities. A supplier that never holds the data has less to say about retaining it. Where that explanation genuinely applies, this card credits it and says so in the judgment.
Third, that explanation has a limit, and the limit is the whole card. It accounts for silence about the agency’s data. It does not account for a privacy policy, published by a company whose entire business is converting images of vehicles into searchable records, that never uses the word “vehicle.”
The pattern
Set the two halves of Neology’s website beside each other.
The sales half is specific, confident, and unusually candid about capability. The Law Enforcement & Public Safety page sells MANTIS-4D software under the phrase “more than just a license plate,” and describes what it delivers as “Four dimensions of intelligence provided – where, what, who and when.” The Border Security section offers to let officers “detect and focus on suspect vehicles and their occupants,” and to process “vehicle data to support convoy, cohort and pattern analysis based on historical vehicle movements.”
Read that carefully, because no other vendor in this series says it. Flock’s Trust pages insist “It captures vehicles. Not people.” Genetec, Axon and Rekor all draw the same line in some form. Neology draws no line, because Neology is selling the thing on the other side of it: the who, the occupants, and the pattern of a vehicle’s movements over time.
The disclosure half is empty. Across thirty-two pages there is no ALPR usage and privacy policy, no retention period, no sharing standard, no access-control description, no audit-log description, no data-subject process, and no security page. The privacy policy that exists is a website-visitor notice — email addresses, IP addresses, browser type, cookies — of a kind found on any small business site. The words “license plate,” “ALPR,” “ANPR,” “vehicle” and “tolling” appear nowhere in its text.
For comparison, California Civil Code § 1798.90.51(b)(1) requires an ALPR operator to “Implement a usage and privacy policy in order to ensure that the collection, use, maintenance, sharing, and dissemination of ALPR information is consistent with respect for individuals’ privacy and civil liberties,” and provides that the policy “shall be available to the public in writing, and, if the ALPR operator has an Internet Web site, the usage and privacy policy shall be posted conspicuously on that Internet Web site.” The statute’s minimum contents include the authorized purposes, the titles of authorized personnel, the sharing restrictions, the named custodian, and the retention and destruction schedule.
Neology is headquartered at 1917 Palomar Oaks Way, Carlsbad, California. Flock, DRN and Vigilant each publish a California ALPR policy. Neology publishes none.
This card does not assert that Neology is in violation of that statute, and readers should not read it that way. Whether Neology meets the statutory definition of an “ALPR operator” — “a person that operates an ALPR system” — depends on facts about specific contracts that its public documents do not settle. That ambiguity is the finding. A California resident cannot determine, from anything Neology publishes, whether the company operates ALPR systems in their state, and therefore cannot determine whether the policy they are entitled to read is missing or simply inapplicable.
The scored card
The usual warning: every factual figure below is a measurement, quoted from a named Neology page. The final grade is not. It is the journal’s editorial judgment of how well each disclosure area holds up. We publish the reasoning so you can argue with the math.
Scale: 85+ disclosures accurate and consistent throughout · 65–84 solid, with real but limited gaps · 45–64 mixed — meaningful divergence alongside genuine substantiation · 25–44 the public-facing claim is materially broader than the documents support · under 25 the claim and the documents describe different products.
Whether a plate-data policy exists at all
Thirty-two pages, none of them about plate dataThe lowest score this series has recorded in any area. Neology's published legal set is complete and short: Cookies, Privacy, Terms, Disclaimer, Supplier Code of Conduct, UK Exclusive Payment Terms, Opt-out Preferences, and an Information Security Policy for Third Parties. There is no trust centre, no security page, no compliance page, and no ALPR or ANPR usage and privacy policy. The Privacy policy is dated "Last updated: June 1, 2023" and is a generic website notice: it enumerates "Email address, First name and last name, Phone number, Address, State, Province, ZIP/Postal code, City, Usage Data," and defines Usage Data as "Your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit." Its retention clause reads in full: "The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy." Its disclosure clause reads: "The Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency)." Every one of those sentences is about a website visitor. None is about the subject of the company's business. The grade is not zero for two reasons that matter: the document that exists is honestly labelled and does not make false claims about plate data — it simply does not address it — and Neology's supplier-facing posture, graded separately below, demonstrates that the company can write a serious data-governance document when it chooses to. It has not chosen to write one facing the public.
Data retention
A schedule demanded of suppliers, published for nobodyThere is no published retention period for plate reads anywhere on neology.com — no default, no maximum, no configurable range, no statement that the customer sets it, and no statement that the company does. This is the fourth clock in the [retention explainer](/articles/alpr-retention-clocks-explainer.html) run to its logical end: three of the previously audited vendors at least said out loud that the number belongs to the buyer, which told a council where to look. Neology says nothing, which tells a council nothing. The mitigating explanation carries real force here — an equipment supplier whose customer runs the back office genuinely may hold no reads at all — but it is undercut by the company's own supplier policy, which shows precisely what Neology considers an adequate retention disclosure when it is the party at risk. That document instructs third parties that Neology's "data should only be retained for as long as necessary to fulfil the contract or legal requirements" and that they "must ensure secure destruction of data when it is no longer needed, using recognized data wiping methods (e.g., NIST SP 800-88)." A named destruction standard, a stated limiting principle, and a contractual hook. Nothing of the kind is published about the license plate reads.
Candour about what the product does
"More than just a license plate" — where, what, who and whenThe highest score on this card, and it is a genuine credit rather than a consolation prize. Every other vendor in this series has been marked down in this area for a contradiction: a Trust page promising the system watches vehicles and not people, sitting alongside a product page selling person search. Neology has no such contradiction, because it never makes the promise. Its Law Enforcement page states the capability plainly — "Four dimensions of intelligence provided – where, what, who and when supported by our 'more than just a license plate' MANTIS-4D software" — and its Border Security section describes detecting "suspect vehicles and their occupants" and running "convoy, cohort and pattern analysis based on historical vehicle movements." A reader of those sentences understands what is being sold. That is worth more than a reassuring sentence that a product page later contradicts, and this card says so. The deduction, and it is substantial, is that the candour is confined to the half of the site written for buyers. The half written for the public — the Privacy policy — describes a company that collects email addresses. A resident who goes looking for what Neology does with data is routed to a document about cookies, while the sentence describing four-dimensional intelligence on the "who" sits three clicks away under a sales heading. Both halves are true. Only one is addressed to the person being photographed.
Impact statistics
90 percent, 30 percent, thousands of agencies, no footnoteThe Law Enforcement page claims the analytics deliver "demonstratable impact – reducing investigative hours by upto 90% whilst increasing solve rates by over 30%," and that the platform is "trusted by thousands of Agencies" over a "Platform evolution over 20 years." None of the three figures carries a source, a study, a sample, a date, or a definition of what a solve rate is measured against. This is the same failure that produced Flock's lowest score, with one difference that cuts both ways: Flock at least published an Impact Census disclosing its survey design and sample size, so the mismatch there was between a headline and a real underlying document. Neology publishes no underlying document at all, so there is nothing to check the claim against. A partial credit is warranted for what the company does not do: the About page's "By The Numbers" panel is scrupulous by comparison, listing "1993 founded, 15,000 toll devices, 5,000 lanes, 130,000,000 transponders" — countable infrastructure facts rather than crime-solving claims — and Neology makes no equivalent of the "percent of U.S. crime solved" assertion that anchors this series' lowest measurement. The company inflates in one room and counts carefully in another.
Data ownership and sharing
A good sentence, in a sales bullet, with nothing behind itNeology makes the strongest ownership claim of any vendor in this series, and makes it in the weakest possible place. The Law Enforcement page states: "Data ownership retained by the Agency with complete control over who and when to share it using our Data Sharing, Audit and Inter-operability capability." Compare that against the sentence that earned Rekor a 15 in this area — a perpetual, sublicensable, transferable licence over the same category of data — and Neology's position is, on its face, the better one for a public agency. It is also unenforceable as published, because it appears as the sixth bullet in a marketing list rather than in any terms of service, privacy policy or contractual document available to the public. Neology's actual Terms govern use of the website. There is no published commitment that the company will not use customer plate data, no statement of what Neology may do with data that passes through its systems, no third-party disclosure standard, and no equivalent of Genetec's "We do not sell or rent any personal data to any third party" or Axon's undertaking not to use customer content for commercial purposes. The score reflects the split precisely: a claim this good, made this informally, is worth something to a buyer with a lawyer and nothing to a resident with a question.
Security certification claims
"Certified SOC 1 and SOC 2 compliant," on the About pageNeology's entire published security-certification posture is one clause on the About page, between a patent count and a product description: "We hold over 200 granted and pending patents and are certified SOC 1 and SOC 2 compliant." There is no report, no summary, no auditor named, no date, no scope, no statement of which systems or products are covered, and no distinction between Type I and Type II — the distinction that separates a snapshot of control design from a test of whether the controls actually operated over a period. The phrasing is loose in a way that matters: SOC 2 is an attestation, not a certification, and SOC 1 is a report on controls over financial reporting, which has essentially nothing to do with protecting license plate data and everything to do with a tolling company's revenue systems. Bundling the two as evidence of data protection conflates a financial-audit artefact with a security one. Set that against how the rest of the field handles the same claim: Rekor names SOC 2 and links the publicly distributable SOC 3 report; Genetec does the same; Flock names SOC 2 Type II and ISO 27001 in the policy that governs. Neology's underlying certifications may be entirely real — the claim is specific enough to be falsifiable and there is no reason to doubt it — but a compliance assertion that cannot be scoped or dated by the reader is a statement of reputation, not a disclosure.
Access controls and audit logging
Rigorous standards, all of them pointed outwardNeology's Information Security Policy for Third Parties, last updated April 4, 2025, is a serious document — the most detailed thing the company publishes, and better than what several higher-scoring vendors put in writing. It requires third parties to "implement Role-Based Access Control (RBAC)," to protect access through "mandatory multi-factor authentication (MFA)," to follow "the principle of least privilege (PoLP)," to apply "end-to-end encryption for all sensitive data (including PII) both at rest... and in transit" complying with "industry standards such as AES-256," to run periodic vulnerability assessments and penetration testing, to conduct background checks before granting access, and to notify Neology of any breach "immediately, and no later than 24 hours from the discovery of the incident." It names a real accountable officer — the company's Chief Information Security Officer, Sean Goodbody, listed on the About page, with [email protected] published as the contact. Every requirement above is imposed on somebody else. There is no published counterpart describing the access controls inside Neology's own products: no statement that a user must authenticate individually, no statement that a search is attributed to a named officer, no statement that a purpose is recorded, and no statement of what an audit trail contains or how long it survives — the five fields Motorola enumerates and the field list this series has used as the test of whether misuse can be reconstructed. The product pages offer one word on the subject: neoGuard provides "Data protection using data encryption," with no standard named, from a company that specifies AES-256 when instructing its vendors. The single mention of auditing on the customer-facing side is the marketing phrase "Data Sharing, Audit and Inter-operability capability." That a capability exists is useful to know. What it records is not disclosed.
The state of the estate publishing the claims
Hidden pharmacy spam, injected site-wide, including on the security policyOn July 31, 2026, every page sampled on neology.com served the following markup inside its site-wide navigation menu, immediately after the "neoRide: Mobile Payments" item: <div style="position:absolute;left:-52954px;"> containing three links, to apotheke-frankfurt.com, apotheke-vienna.com and farmacia-sevilla.com, with the anchor text "xifaxan germany," "amoxil germany" and "imipramina spain." The div positions the links roughly fifty-three thousand pixels off the left edge of the screen, so a human visitor never sees them and a search engine does. Six such links across two hidden containers appeared on all seven pages tested, including the homepage, the About page, the Terms, and — the reason this is a graded area rather than a footnote — the Information Security Policy for Third Parties, the page carrying the 24-hour breach-notification requirement and the CISO's address. Hidden off-site link injection of this kind is the standard signature of a compromised or unpatched content management system; the site runs WordPress with an SEO plugin that generates its sitemap. What this card can state is exactly what is quoted above: the markup was present, at those URLs, on that date. It does not establish that Neology suffered a breach, that any internal system was reached, or that any customer, tolling or license plate data was affected or is at risk. A marketing website is very often maintained by people and on infrastructure entirely separate from the products, and it would be unfair to read this as evidence about neoGuard or MANTIS-4D. It is evidence about one thing only, and that thing is squarely within this series' remit: the condition of the web property through which the company publishes every security assurance it makes.
Twenty-eight — the lowest in the series by thirteen points, below Rekor’s 41 and half of Axon’s and Genetec’s 62. It belongs to the only vendor of the six that publishes no document at all about the data its products exist to collect.
The last word
Three findings carry more weight than the average.
First: this card had to be built differently, and the reason is the finding. The first five entries in this series worked by setting two of a company’s own documents beside each other and reading them together — a Trust page against a product page, a press release against a terms of service, a marketing claim against an SEC filing. That method requires two documents. Neology publishes one relevant document, and it is about cookies. The distance measured here is not between a promise and a qualification; it is between a product sold on four dimensions of intelligence including the who, and a public record that does not concede the product exists.
Second: Neology knows exactly how to write the missing document, because it has already written it for itself. The Information Security Policy for Third Parties specifies role-based access control, mandatory multi-factor authentication, least privilege, AES-256 at rest and in transit, penetration testing, background checks, named accountability, NIST SP 800-88 destruction, and breach notification inside twenty-four hours. It is a better data-governance document than several higher-scoring vendors publish. Every clause of it protects Neology from its suppliers. The company that can specify a destruction standard when its own data is at stake publishes no retention period for the photographs of your car — and the asymmetry is not an oversight of drafting skill, because the skill is demonstrably there.
Third, and this is the one that generalises past this vendor: a disclosure audit can only grade what is disclosed, which means silence is the most effective response to being audited. Flock scored 43 partly because it published an Impact Census that could be checked against its own headline. Rekor scored 41 partly because it filed a 10-K under penalty of law. Neology scores 28 having published almost nothing — and if the incentive a series like this creates is that candour costs points, the series is measuring the wrong thing. So let this be said plainly: the five vendors that scored higher did so because they wrote things down. A vendor that publishes nothing has not passed the audit. It has declined to sit it, and the correct response from a purchasing jurisdiction is not reassurance but a records request, a contract clause, and a written answer to the seven questions this card could not find one for.
That is the practical use of a card that ends at 28. Every scored area above is a question with a blank where an answer should be, and every one of them can be asked in a procurement document, a council hearing, or a public-records request: what is the retention period, who can search, is the search attributed, is a purpose recorded, what does the audit log keep and for how long, may the vendor use the data, and to whom may it be disclosed. The blanks are the agenda.
Qui tacet consentire videtur — one who stays silent is taken to consent. It is a serviceable rule for courtrooms. It is a poor rule for procurement, where a vendor’s silence is taken instead as a clean record, and where the only way to convert silence into a commitment is to write the question into the contract before signing it.
Sources & methodology:
- All disclosures graded on this card were read from pages published by Neology on the public web on July 31, 2026; no internal documents, contracts, or non-public sources were used.
- The complete public page inventory used to establish every statement of absence — thirty-two pages — was taken from the company’s own machine-readable index: neology.com/page-sitemap.xml
- “Last updated: June 1, 2023,” the enumerated categories of personal data, the Usage Data definition, “The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy,” and the disclosure-to-public-authorities clause: Neology Privacy Policy
- Role-Based Access Control, mandatory multi-factor authentication, principle of least privilege, AES-256 encryption at rest and in transit, vulnerability assessment and penetration testing, background checks, “no later than 24 hours from the discovery of the incident,” NIST SP 800-88 destruction, ISO 27001 / NIST CSF / SOC 2 / PCI DSS / ISO 27017 requirements, and the [email protected] contact; Last updated April 4, 2025: Information Security Policy for Third Parties
- “More than just a license plate,” “Four dimensions of intelligence provided – where, what, who and when,” MANTIS-4D, “reducing investigative hours by upto 90% whilst increasing solve rates by over 30%,” “trusted by thousands of Agencies,” “Data ownership retained by the Agency with complete control over who and when to share it using our Data Sharing, Audit and Inter-operability capability,” and the border-security description of “suspect vehicles and their occupants” and “convoy, cohort and pattern analysis based on historical vehicle movements”: Law Enforcement & Public Safety
- “Data protection using data encryption,” hotlist processing, and “Easy access to large amounts of historical and real-time data”: neoGuard™
- The enforcement product range and the [email protected] contacts: Road Safety & Enforcement
- “We hold over 200 granted and pending patents and are certified SOC 1 and SOC 2 compliant,” the “By The Numbers” figures, the Carlsbad headquarters address, the 650+ employee count, and the leadership listing naming Sean Goodbody as Chief Information Security Officer: About Neology
- The hidden injected links quoted in area 8 were read from the raw HTML served at the URLs above on July 31, 2026, and were present on every page sampled. This journal makes no claim that any Neology system, product, or customer data was compromised.
- “Implement a usage and privacy policy,” the requirement that it “shall be available to the public in writing, and, if the ALPR operator has an Internet Web site, the usage and privacy policy shall be posted conspicuously on that Internet Web site,” and the minimum contents: California Civil Code § 1798.90.51. The definition of “ALPR operator” as “a person that operates an ALPR system”: § 1798.90.5. This card does not assert that Neology is an ALPR operator within the meaning of the statute or that it is in violation of it.
- The comparison cards: Flock Safety, 43 · Motorola Solutions, 46 · Genetec, 62 · Axon, 62 · Rekor, 41
- The retention clocks this card refers to: Four Vendors, Four Retention Policies, and Almost No Numbers
- The grades are the journal’s editorial judgment; every underlying factual claim above is quoted from a Neology-published page as cited. An absence of published disclosure is not evidence of an improper practice, and nothing in this card establishes that Neology mishandled any data.