On the Scent48

The Vendor Audit Scorecard: Seven Companies, Fifty-Six Measurements, One Number — 48.

Over seven entries, the Vendor Audit held the private companies that sell license plate readers, video analytics, and AI-drafted police reports to public-safety agencies against one question: does what the company tells the public match what it writes into its own product pages, privacy policies, and legal filings? Same method every time — eight disclosure areas, each scored 0–100 from a document the company published or filed itself, no leaks, no contracts, no internal sources. This is the scorecard. First where the record lands, then the numbers. Reporting on documents, not legal advice.

Where the record lands

Fifty-six individually graded disclosure areas across seven vendors. Sorted by what they actually measure rather than by which company wrote them, they fall into three groups — and, as with the Capitol Audit before it, the groups do not overlap by company. They overlap by kind of claim.

Mechanism — disclosed with real specificity, and the reason no card in this series scored near zero:

  • Access controls and audit logging: named field lists, role-based permissions, and purpose-documented searches, corroborated in a governing policy, at three separate vendors (Flock, 75; Motorola, 75; ELSAG, 76)
  • Security certification claims naming a real, checkable framework — FedRAMP High and ISO/IEC 42001, not a badge — at the top of the series (Axon, 88)
  • A subpoena-notification commitment naming the process rather than leaving it open-ended, at two vendors independently (Axon and ELSAG)
  • Amendment terms that bind the vendor as written, rather than reserving a unilateral rewrite (Genetec, 82)
  • A data-ownership commitment with no carve-out anywhere in the document set (Axon, 90)

Marketing — the summary sentence, and where nearly every card lost its points:

  • Impact statistics with no citation, no year, no methodology, repeated at a different magnitude on a different page — at four separate vendors (Flock, 15; Neology, 20; ELSAG, 25; Axon, 38)
  • “Vehicles, not people” and its variants, stated flatly on the reassurance page beside a product that does the opposite — at three vendors (Flock, 20; Motorola, 30; ELSAG, 22)
  • “Automatic deletion” stated without the carve-out that makes it conditional, at three vendors (Motorola, 25; Rekor, 35; Neology, 10)
  • The lowest score in the entire series: a company with no ALPR-specific privacy policy at all, on a website that spent July serving hidden pharmacy-spam links in its own navigation menu (Neology, 10 and 12)

Reservation — the same conceptual question, opposite answers, depending on what the vendor keeps for itself:

  • Data ownership and third-party access, the single widest spread on any recurring question in the series: a perpetual, sublicensable, transferable license to the vendor at the bottom (Rekor, 15) against a clean, carve-out-free ownership commitment at the top (Axon, 90)
  • Policy currency: a six-year-old governing document that disagrees with its own date, sitting underneath the best substantive terms in the series (Genetec, 25), against a policy dated within the audit window but silent about the product launched most recently (ELSAG, 45)
  • A retroactive amendment clause allowing a policy to be rewritten and applied backward to data already collected (Motorola)

The honest verdict: this is not a story about interchangeable vendors selling the same product under different names. A sixteen-point spread separates Genetec and Axon at 62 from Flock at 43, and a jurisdiction choosing between them is making a real choice with real consequences. But underneath that spread sits a fault line that does not care which vendor you pick. Every card in this series scored its mechanism disclosures — who can log in, what gets recorded, what a certification actually names — higher than its summary disclosures — what the system is, what it captures, how impactful it has been. The companies that scored well did not do it by writing better marketing copy. They did it by reserving less discretion for themselves in the documents that bind.

The scored card

The same warning as every entry in this series: every underlying figure is a measurement — a quoted sentence from a named, linked company page, sourced in the entry it came from. These grades are not. They are the journal’s editorial judgment of how well each vendor’s disclosures hold up against its own documents. We publish the reasoning so you can argue with the math.

Scale: 85+ disclosures accurate and consistent throughout · 65–84 solid, with real but limited gaps · 45–64 mixed — meaningful divergence alongside genuine substantiation · 25–44 the public-facing claim is materially broader than the documents support · under 25 the claim and the documents describe different products.

62
1

Genetec

The best terms in the series, filed in a document six years old

Tied for the highest score in the series, and it earns it by reserving comparatively little for itself: amendment terms that bind as written (82), a data-ownership commitment with real teeth (76), and sharing language that requires the customer to opt in rather than opt out (68). The drag is not substance, it is paperwork — the governing Global Privacy Policy is dated 2020, references certifications from 2023, and describes a product catalogue from 2019, all while disagreeing with itself about its own currency (25). A company that could fix its worst score in an afternoon by updating one document, sitting on the best terms this series has read.

62
2

Axon

FedRAMP High and ISO 42001 — and silence about who wrote the police report

Tied for the top score, and the only vendor in the series to prove the compliance work is fully possible: FedRAMP High, ISO/IEC 42001, a clean data-ownership commitment (90), a security-certification stack that names actual auditors rather than adjectives (88). The failure moved rather than disappeared — nothing Axon publishes says whether an AI-drafted police report discloses its own origin to a defense attorney, or whether body-camera footage feeding the model also trains it (28 and 35). The same company that made every other promise on this card checkable left its newest product, Draft One, the least documented.

51
3

Leonardo/ELSAG

A real privacy commitment that never learned its own newest product's name

The card that broke this series' pattern in both directions. ELSAG wrote one of the two or three best ALPR-specific privacy documents this series has read — named retention windows, CJIS-aligned access controls (76), a subpoena-notice commitment matched elsewhere only by Axon (70) — and still landed in the middle of the field, because that document never once mentions SignalTrace, the company's own product for fingerprinting the personal electronics that travel with a car (22). A vendor that proved silence is not the cheapest way to a low score, and that a good document about half a product line is not the same as a good document.

46
4

Motorola Solutions

Two datasets, one true story told about each

Three points above Flock on a fundamentally different architecture, which was the first evidence for this series' central claim: swap the vendor, keep the capability, and the same disclosure gaps reappear. Motorola's access controls and impact disclosures are genuinely specific (75 and 70), but its promises are precisely true about the data an agency collects and silent about the commercially sourced dataset layered on top, where unlimited retention and corporate ownership live (25 and 28). A retroactive amendment clause lets the company rewrite the governing policy and apply it backward to data already collected — a term that outlives any single card in this series.

43
5

Flock Safety

The pilot card, and the one that set the method

The card that opened the series and established its yardstick. Access controls and the facial-recognition denial hold up well under scrutiny (75 and 72), corroborated field-by-field in the governing LPR Policy. Everything summarized in a sentence performs worse: an impact statistic quoted at three different magnitudes on three different pages (15), "captures vehicles, not people" beside a product whose advertised search is "man in blue shirt and cowboy hat" (20), and a flat "no national database" answer beside a product named the National LPR Network (30). Not concealment so much as segregation — every carve-out is disclosed somewhere on Flock's own site, just never on the page a resident is sent to.

41
6

Rekor Systems

A privacy framework and a perpetual license, in two documents that never meet

The only publicly traded company in the series, which means an audited 10-K sits alongside the marketing — and discloses substantial doubt about the company's ability to continue as a going concern (58, for the one area this series can check against a filing instead of a webpage). Three weeks before this card was built, Rekor published a privacy framework positioning itself against the Flock backlash; nothing in that framework binds the company, and its actual terms of service grant Rekor a perpetual, sublicensable, transferable license to commercially use the license plate data it collects (15) alongside a share-by-default clause that requires an agency to opt out rather than opt in (28). Publishing a framework and reserving a commercial license over the same data are not contradictory acts, and that is the finding.

28
7

Neology

The lowest score in the series, because there was almost nothing to grade

Across all thirty-two public pages this series could find, Neology publishes no ALPR-specific usage and privacy policy, no retention period, no sharing standard, and no access-control description (10 and 12) — even as its MANTIS-4D software is marketed under the phrase "more than just a license plate: where, what, who and when" (55 for candour, the one area where saying the quiet part out loud earned credit). On July 31, 2026, every sampled page on neology.com, including its own Information Security Policy for third-party suppliers, served hidden spam links to foreign pharmacy sites in its site-wide navigation — evidence about the condition of the property publishing every assurance the company makes, not evidence of a data breach. A company that did not fail this audit so much as decline to sit it.

48 / 100
Seven vendors' public disclosures · averaged across all fifty-six graded areas

Forty-eight — almost precisely the midpoint, and, as with the Capitol Audit’s 51, the average is the least interesting number on the page. Two vendors cluster at 62. Two cluster at 43 and 41. One sits alone at the bottom, at 28. The middle of the distribution is thin, occupied only by ELSAG at 51 and Motorola at 46, which is the hinge where the series turns from vendors that reserve little to vendors that reserve a great deal.

The last word

Three findings carry more weight than the average.

First: the fault line is not company size, architecture, or how long the vendor has been in the ALPR business — it is what the vendor reserves for itself. Genetec and Axon sit at the top not because their marketing is more careful than Flock’s or Rekor’s. It is because their governing documents give away more than they keep: Axon’s clean ownership commitment, Genetec’s amendment terms that bind as written. Rekor and Neology sit at the bottom because their documents keep the most — a perpetual commercial license in one case, no ALPR-specific document at all in the other. Every card in between is a company that gave away some things and kept others, and the score tracks the ratio almost exactly.

Second: mechanism disclosures beat marketing disclosures at every single vendor, with no exception. Access controls, audit logging, and named security certifications scored above the vendor’s own average at all seven companies. Impact statistics, “vehicles not people” claims, and headline retention promises scored below it at all seven. This is not a coincidence of which questions this series happened to ask — it is a structural feature of how these documents get written. A field list in a technical policy is drafted by engineers describing what the system actually does. A sentence on a trust page is drafted by marketing describing what the system is supposed to sound like. The audit keeps finding the gap between those two departments, at company after company, regardless of the product underneath.

Third: in every single card where a company’s newest product was the weak point, it was the same failure — the privacy document was written for the product line that existed when it was drafted, and nobody went back and added the newest one. Flock’s FreeForm person search sits outside the Trust center’s “vehicles, not people” promise. Axon’s Draft One AI report sits outside every commitment the company makes about tamper-proof evidence. ELSAG’s SignalTrace device-fingerprinting sits outside a privacy commitment that is otherwise the best-written document of its kind this series has read. Three different companies, three different products, one identical shape: the newest capability is always the one the privacy page hasn’t caught up to yet, because updating that page requires someone to notice the gap and choose to close it, and nothing about selling the new product requires that step.

Tempora mutantur, nos et mutamur in illis — the times change, and we change with them. The vendors in this series keep this half of the maxim: the product line moves, the sales language moves with it. It is the privacy document, written once and rarely revisited, that stops changing — which means the newest and least-tested capability a company sells is, card after card, the one its own public promises say the least about.


Sources & methodology:


This closes the Vendor Audit as an active investigation. Its seven entries remain published and linked above, and now live together on the Series page rather than the standing On the Scent feed.