Minnesota Security Consortium (MNSec)
20 ALPR audits across 18 agencies. Of the 20 we have read in full, 17 recorded zero findings (85%). Individual findings break down as 3 material. 3 ghost findings — problems described in a report’s narrative but never recorded. Depth: checklist, deep / technical, substantive.
18
Agencies audited
20
Audits filed
85%
Zero findings
3
Real findings
Flags
The pattern here is a template that clears everyone it touches.
Tested the system, not the paperwork
At least one audit examined the live platform, its logs, or its exports.
Ghost findings
3 problems described in the report narrative but never recorded as a finding — found it, then left it off the record.
Audits its own members
A member-funded body auditing the agencies that fund it.
Law enforcement background
The firm’s principal or governing board includes current or former police personnel.
Audits by this auditor
Found compliant on all items; no findings.
Read the audit (LRL 261008) →Found compliant on all items; no findings.
Read the audit (LRL 260987) →Found compliant on all items; no findings. Separate from Richfield BWC audit (260637).
Read the audit (LRL 260900) →Found compliant on all items; no findings.
Read the audit (LRL 260189) →Found compliant on all items; no findings.
Read the audit (LRL 260679) →No findings or recommendations recorded. All 8 statutory sub-areas (policy, retention, data security/access, data classification, inter-agency sharing, public log of use, BCA notification, biennial audit planning) marked compliant. Auditor reviewed the Flock admin/retention control panel and sampled one month (July 2026) of inter-agency data-sharing requests; no exceptions surfaced in that sample.
Read the audit (LRL 261268) →First audit of West Saint Paul PD's new Flock system (10 stationary units, operational 9/1/25–6/30/26). MNSec found the agency compliant on policy, retention (30-day Flock default), access control (inactive users confirmed deactivated), data classification, interagency sharing (a full month sampled, all justified), public log of use (monthly reports reviewed), BCA notification, and breach notification. No exceptions noted. Companion AXON-system audit filed the same season under LRL 261168.
Read the audit (LRL 261167) →Second Flock-system audit for this agency. No findings.
Read the audit (LRL 260248) →First Flock-system audit (system installed 2024). No findings.
Read the audit (LRL 260144) →GHOST FINDING — a problem found and fixed during the audit but never recorded as a finding. The report states Oakdale 'now compiles monthly reports' meeting the subd. 5 public-log requirement and that 'as a result of this audit' the department 'is now in compliance with this part of the statute' — meaning it was out of compliance until the auditor showed up. Final report: compliant, no findings recorded. Rated as no findings because that is what the report records. See FinePrint feed: The ghost findings of Minnesota's ALPR audits.
Read the audit (LRL 251753) →First audit of the new Flock system. Compliant on data collection, retention, access control, classification, inter-agency sharing, public log of use, and BCA notification. Found only partially compliant on breach notification: the department's general Incident Response policy covers some elements but MNSec recommended additional breach-reporting elements be added to conform to subd. 7(a) and Minn. Stat. 13.055.
Read the audit (LRL 251737) →MNSec recommended Champlin develop a breach-notification policy conforming to Minn. Stat. § 13.824, subd. 7(a) and Minn. Stat. § 13.055 — identical recommendation to the companion Flock-system audit.
Read the audit (LRL 251686) →No findings. Auditor given direct administrative access to the live Axon system rather than relying on screen prints supplied by the agency.
Read the audit (LRL 251684) →MNSec recommended Champlin develop a breach-notification policy conforming to Minn. Stat. § 13.824, subd. 7(a) and Minn. Stat. § 13.055 — a substantive finding, not a rubber-stamp result.
Read the audit (LRL 251685) →No findings. Auditor given direct administrative access to the live Flock system rather than relying on screen prints supplied by the agency.
Read the audit (LRL 251683) →Found compliant on all items; no findings. First audit of the new Flock system.
Read the audit (LRL 251639) →Found compliant on all items; no findings.
Read the audit (LRL 251619) →GHOST FINDING — The report records zero findings, yet its own narrative recommends that Orono "develop a standalone breach policy," noting that breach procedures currently exist only as a reference inside the department's ALPR policy (Policy 3059.0) rather than as a standalone document. A missing or partial breach-notification policy scores as Material under FinePrint's calibration; MNSec described the gap, recommended a fix, and still returned a clean sheet. Everything else was reported compliant: 30-day Flock retention (statutory max 60), role-based access with regular administrative review, ALPR data classified as private, inter-agency sharing requests tracked by agency/requesting party/case number, monthly compliance reports available on records request, BCA notification confirmed, and a commitment to biennial independent audits. Three stationary/flex Flock devices, no squad-mounted units. See "The ghost findings of Minnesota's ALPR audits."
Read the audit (LRL 251707) →GHOST FINDING — a problem the audit describes but never records. Marked compliant with zero findings, yet the narrative notes the office had not been maintaining a standard set of Log of Use reports, a Minn. Stat. 13.824 subd. 5 requirement, in the now-retired BOSS system. No formal discrepancy was recorded and MNSec offered to assist with future systems. Rated as no findings because that is what the report records; flagged as a major issue because the described gap appears to violate the statute. See FinePrint feed: The ghost findings of Minnesota's ALPR audits.
Read the audit (LRL 250871) →No findings. MNSec was given administrative access to the PIPS Technology BOSS system; all 6 mobile devices carried 2-day retention settings and no plate reads were detectable after 2 days. Audit trail sampled; log of use reports maintained in BOSS; no inter-agency sharing requests during the period.
Read the audit (LRL 240398) →These figures describe what the filed reports contain. They are not an allegation that any audit was improper or that any agency is out of compliance with Minn. Stat. § 13.824. If you believe a record here is wrong, tell us and we will correct it.
← All auditors