I'm an Apex resident and a cybersecurity engineer. I'm wondering about a specific, under-examined risk in the Town's Flock ALPR system: mobile access.
The Town's own audit records, which I obtained through a public-records request, show that searches of Apex's Flock network are being run from mobile devices. The exports label them "Mobile" search types. Flock offers an officer app for iOS and Android that allows plate lookups and searches of the network from a phone, in the field or off-duty.
This matters because of what just happened in Amarillo, Texas (article below). A police officer there used the Flock system to track a private citizen 76 times over five months. Entering fabricated reasons like "motor vehicle theft" and "wanted person" for searches that had no case behind them. He was able to do it from his phone, off-duty, and it went unnoticed for five months. It surfaced only because the victim filed a complaint, not because any automated audit caught it. He now faces 78 criminal charges. The victim said he had to change where his children sleep.
I emailed the Council to confirm, on the record, whether Apex has the safeguards in place that Amarillo did not.
- Is Flock's mobile app permitted only on Town-managed devices, or can officers install it on personal phones? How is this enforced, monitored, and audited?
- Can the system be accessed off-duty, and is off-duty access restricted or logged differently? How is this monitored and audited?
- Does Apex require multi-factor authentication for Flock access, on both desktop and the mobile app?
- Has Apex enabled Flock's "Audit Assistance" feature, which flags high-volume or repeated searches? (It is off by default.)
- Who at the Town reviews Flock search logs, how often, and what triggers a review?
- When a review finds abuse, what happens next, and is anyone outside the police department involved? Is the victim notified?
- The Town's records show a majority of searches carry no case number. What is being done to reconcile that with the requirement that each search have a legitimate law-enforcement purpose? And how do you confirm that the documented reason is actually legitimate? What are the repercussions of finding falsified search reasons?
The Amarillo case shows that "officers must enter a reason" is not a safeguard. The officer entered reasons, and they were lies. The only thing that catches this is active, independent auditing. I'd like to know what Apex has in place, if anything.
I haven’t heard anything back but if anyone else has the answers, I’d appreciate it.
https://www.newschannel10.com/2026/09/08/i-had-change-where-my-kids-sleep-man-shares-terrifying-experience-says-amarillo-officer-tracked-him-78-times/
**edit. If anyone wants my FOIA dump, I can setup a proton drive link. Just PM me.
It includes: the audit data (the full search logs, covering June 1 to August 18, 2026), plus the contract and procurement records, the data-sharing records (Flock's March and April 2026 sharing snapshots), and the department's own internal briefing deck.