Vigilant Solutions ALPR
Vigilant Solutions · ALPR Camera
✓ Reviewed
Index
Vigilant Solutions builds automated licence plate reader (ALPR) cameras — fixed on poles and mounted on vehicles — that photograph every passing car, convert the plate to text, and store it with the date, time and GPS location. Unlike almost everything else in this catalogue, the people captured are not customers: drivers never opt in, are never notified, and cannot see, correct or delete their records. Vigilant pools commercially collected scans, gathered through an affiliated subsidiary (DRN), with scans contributed by police departments into a shared national database that agencies query through the LEARN platform. That pool is genuinely enormous and overwhelmingly innocent — EFF found 173 agencies across 23 states logged roughly 2.5 billion scans in 2016–17, of which only 0.5% matched any wanted-vehicle list. The same data is licensed commercially to financial institutions and other permitted-user classes, and ACLU records obtained under FOIA show more than 9,000 ICE agents were given access under a $6.1 million contract, letting immigration agents reconstruct where a car has been. Vigilant's own published policy says it keeps the data "as long as it has commercial value," offers no individual opt-out, and reserves the right to rewrite the policy retroactively. Independent security work has repeatedly found the hardware leaky: CISA published seven vulnerabilities in 2024 including sensitive data and credentials stored in clear text, and in January 2025 researchers found roughly 170 unencrypted ALPR streams pushing live video and plate reads onto the open internet with no password at all. Vigilant is now owned by Motorola Solutions, which acquired VaaS International Holdings for $445 million in January 2019.
Why this rating
POLICY 10 = 100 -20 sells-data (Vigilant's own LPR Usage and Privacy Policy, §D "Sale, Sharing or Transfer of LPR Data": "The company licenses our commercially collected LPR data to customers"; §A authorised use (1) is "By customers to identify or ascertain the location of a specific vehicle under circumstances when there is a legitimate commercial interest", and (3) permits the company "to provide market research information to customers based on aggregated LPR data") -15 broker-disclosure (§A gives as "Examples of permitted users and uses of the system and data" both "Entities subject to Sections 6801 to 6809 of the United States Code" — the GLBA financial-institution classes — and "Entities to which information may be disclosed as a permissible use pursuant to Section 2721 of Title 18", the DPPA permitted-user classes; the list is explicitly exemplary rather than exhaustive, and there is no named-recipient list and no cap on onward licensing) -15 indefinite-retention (§G Retention, verbatim: "The company retains LPR data as long as it has commercial value." No maximum period; deletion is governed only by whether "the cost to maintain the data exceeds its value") -15 no-opt-out (§A: "The company does NOT make the ALPR system or data it contains available to individuals for personal, non-commercial purposes", and §C asserts "The company is not aware of any individual privacy interest applicable to the anonymous LPR data contained in the system" — the policy provides no access, correction, deletion or opt-out route for the drivers scanned, who are not parties to any agreement) -10 unilateral-change (§H, verbatim: "The company reserves the right to revise this policy at any point in the future and such changes will be retroactively applicable to data collected prior to any revision of this policy" — retroactive amendment means no commitment made at collection time is durable) -10 law-enforcement-loose (§A authorised use (2) is simply "By law enforcement agencies for law enforcement purposes", and §D states "the company allows law enforcement agencies to query the system directly for law enforcement purposes consistent with this policy" — no warrant or legal-process requirement, no excluded agencies, and no purpose limitation beyond the phrase itself; the ACLU's FOIA records, below, show what that clause delivered in practice) -5 sensitive-collection (§ intro defines the record as "images of license plates, plus the date, time and location when the images were collected", which accumulates into precise historical movement patterns for an identifiable vehicle). Not applied: policy-vagueness (the policy is unusually explicit about what it permits — these deductions are for plainly authorised practices, not ambiguity; the one arguably misleading claim, that LPR data "does not include any personally identifying information (PII)" and is "anonymous", is contradicted within the same document, which concedes users "may have access to vehicle registration information, and other sources of PII, which they may correlate with LPR data" — noted but not separately scored to avoid double-counting sensitive-collection). Scored against the full text of Vigilant's own policy (PDF, internal creation date 6 April 2016, mirrored by San Rafael PD; Vigilant's own policy URL now redirects to a Motorola product page). The materially identical retention, authorised-use and permitted-recipient clauses remain live today on sibling subsidiary DRN's California ALPR privacy policy, so this is current language, not a historical artefact. EVIDENCE 23 = 100 -20 ice-database-access (ACLU, 13 Mar 2019: FOIA records show ICE obtained access to Vigilant's ALPR database under "a $6.1 million contract", with "more than 9,000 ICE agents" granted access, drawing on data from "Over 80 local law enforcement agencies" "from over a dozen states" and comprising "over 5 billion points of location information" from private sources plus "an additional 1.5 billion records" from law enforcement) -20 mass-non-consensual-collection (EFF "Data Driven", from agency public-records responses: "173 agencies from 23 states and the federal government accounted for roughly 2.5-billion license plate scans in 2016 and 2017"; only 0.5% matched a hotlist, i.e. "99.5% of the license plates captured by ALPR are actually not connected to a public safety interest"; "Of the 200 agencies we have received records from, 130 reported that they were sending data to Vigilant Solutions's NVLS", described by EFF as "a pool of data accessed by scores of agencies, the identities of which are not readily apparent in the records"; agencies shared directly with around 160 other agencies on average, and "Ten agencies were directly sharing with in excess of 800 other agencies in addition to NVLS") -15 unauthenticated-exposure (404 Media, 7 Jan 2025: roughly 170 unencrypted Motorola ALPR streams were found pushing colour and infrared video plus plate data onto the open internet with no authentication; a proof-of-concept script built by Will Freeman, creator of the ALPR-mapping project DeFlock, decodes the streams, and the resulting "spreadsheet he sent me shows a car's make, model, color, and license plate number associated with the specific time that they drove past an unencrypted ALPR near Chicago." Matt Brown of Brown Fine Security separately documented Reaper HD vulnerabilities in a series of videos. Motorola called the ReaperHD "a legacy device, sales of which were discontinued in June 2022" and attributed exposure to "Some customer-modified network configurations") -12 state-audit-findings (California State Auditor Report 2019-118, February 2020: "230 police and sheriff departments currently use an ALPR system, and 36 plan to use one", and "most—70 percent—of those that have an ALPR system reported using a company called Vigilant Solutions, LLC"; three of the four audited agencies use cloud storage and "None of the contracts these three agencies have with their cloud storage vendors include all necessary data safeguards"; "Los Angeles currently has more than 320 million images" of which "only 400,000 (0.1 percent)... generated an immediate match"; "the agencies have conducted little to no auditing and monitoring" of user searches, and "Los Angeles has not developed an ALPR policy at all." Reduced from a larger deduction on review because the auditor does not name Vigilant as the cloud vendor for the three agencies whose contracts lacked safeguards — that finding is agency-side, so only the market-dominance and oversight findings are Vigilant-specific) -10 cve-cluster (CISA advisory ICSA-24-165-19, June 2024, covering seven CVEs in the Vigilant Fixed LPR Coms Box (BCAV1F2-C600, firmware 3.1.171.9 and prior). CVE-2024-38280 (CVSS v4 7.0 High) — "An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text"; CVE-2024-38281 (CVSS v4 8.6 High) — "An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device"). Not applied: no verified FTC, state-AG or foreign-regulator enforcement action against Vigilant/Motorola over ALPR was located; unadjudicated private litigation was not scored. Also not applied: a figure of "137 deployments across 22 states" appeared in drafting but could not be verified in any source loaded — the nearest verified figure is EFF's 173 agencies across 23 states, which is what this record asserts. Two claims were removed at verification for lack of a loadable source: a severity split of the seven 2024 CVEs, and the identity of the party who reported them to CISA (the CISA advisory page returns HTTP 403 and is not archived). Evidence remains capped well below a clean score because the harms above are documented rather than merely alleged, and because the subjects of this collection are the general public, who cannot consent to, inspect or avoid it.
What it is
- Camera
- GPS / location
- Requires a cloud account
- Manufacturer
- Vigilant Solutions
- Category
- ALPR Camera
- Model years
- 2016–present (documented span; Motorola Solutions acquired parent company VaaS International Holdings, including Vigilan
- Market status
- Current
- Companion app
- LEARN (Law Enforcement Archival & Reporting Network) — agency-facing web platform; NVLS (National Vehicle Location Service) shared national data pool
The evidence 8
Independent research, regulatory action, lawsuits, breaches and journalism about this device — the "what actually happens" axis. Each links to its source.
-
Vigilant's own ALPR policy, published to satisfy California SB 34. Section G states verbatim: 'The company retains LPR data as long as it has commercial value.' Section D confirms the company 'licenses our commercially collected LPR data to customers' and 'allows law enforcement agencies to query the system directly for law enforcement purposes.' Section A gives as examples of permitted users entities subject to Sections 6801 to 6809 of the United States Code (GLBA) and entities permitted under Section 2721 of Title 18 (DPPA), and states the system is not made available 'to individuals for personal, non-commercial purposes.' Section C asserts the company 'is not aware of any individual privacy interest applicable to the anonymous LPR data.' Section H reserves the right to revise the policy at any time with changes 'retroactively applicable to data collected prior to any revision.'
Why it matters here: The primary document for every POLICY-axis deduction. Full text was extracted and read at verification; all quoted clauses are verbatim. Vigilant's own URL now redirects to a Motorola product page, so this agency-hosted copy is the openable version; the same clauses remain live on sibling subsidiary DRN's site. The 2016-04-06 date is the PDF's own embedded creation date.
-
FOIA records show ICE gained access to Vigilant Solutions' ALPR database under 'a $6.1 million contract', with 'more than 9,000 ICE agents' granted access to data from 'Over 80 local law enforcement agencies' 'from over a dozen states' — 'over 5 billion points of location information' from private sources plus 'an additional 1.5 billion records' from law enforcement.
Why it matters here: Proves the law-enforcement-loose clause is not theoretical: the policy's unqualified 'law enforcement purposes' language operationally delivered nationwide vehicle location histories to immigration enforcement.
-
EFF's analysis of agency public-records responses found '173 agencies from 23 states and the federal government accounted for roughly 2.5-billion license plate scans in 2016 and 2017', with only 0.5% matching a hotlist — meaning '99.5% of the license plates captured by ALPR are actually not connected to a public safety interest.' 'Of the 200 agencies we have received records from, 130 reported that they were sending data to Vigilant Solutions's NVLS', which EFF describes as 'a pool of data accessed by scores of agencies, the identities of which are not readily apparent in the records.' Agencies shared directly with around 160 other agencies on average, and 'Ten agencies were directly sharing with in excess of 800 other agencies in addition to NVLS.'
Why it matters here: The core quantification of involuntary mass capture and of NVLS as the aggregation point. The 99.5% figure establishes that the overwhelming majority of people in this database are under no suspicion whatsoever. The page carries no publication date, so none is asserted.
-
A statutory performance audit issued February 2020 — not an enforcement action. Found '230 police and sheriff departments currently use an ALPR system, and 36 plan to use one', and that 'most—70 percent—of those that have an ALPR system reported using a company called Vigilant Solutions, LLC.' Three of the four audited agencies (Fresno, Marin, Sacramento) use cloud storage, and 'None of the contracts these three agencies have with their cloud storage vendors include all necessary data safeguards' — the auditor does not name the vendor. 'Sacramento recorded 1.7 million images in one week'; 'Los Angeles currently has more than 320 million images' of which 'only 400,000 (0.1 percent)... generated an immediate match'. The agencies 'have conducted little to no auditing and monitoring' of user searches, and 'Los Angeles has not developed an ALPR policy at all.'
Why it matters here: An official government body quantifying Vigilant's market dominance in the largest US state market, and documenting near-total absence of oversight over who searches the data and why. Kind reclassified from regulatory-action to investigative-report at verification because this is an audit, not an enforcement action.
-
By Jason Koebler. Roughly 170 unencrypted Motorola ALPR streams have been found broadcasting colour and infrared video plus collected plate data to the open internet in real time, without authentication. Will Freeman, creator of the ALPR-mapping project DeFlock, built a proof-of-concept script that decodes the streams; the resulting 'spreadsheet he sent me shows a car's make, model, color, and license plate number associated with the specific time that they drove past an unencrypted ALPR near Chicago.' Matt Brown of Brown Fine Security separately 'made a series of YouTube videos showing vulnerabilities in a Motorola Reaper HD ALPR.' Motorola responded that the ReaperHD is 'a legacy device, sales of which were discontinued in June 2022', attributed exposure to 'Some customer-modified network configurations', and said it was developing firmware with additional security hardening.
Why it matters here: Demonstrates that data collected without consent was additionally exposed to anyone on the internet — the public bears the risk of a system it never agreed to and cannot audit. Attribution corrected at verification: the 170-stream count and the decoding tool are Freeman/DeFlock, not Matt Brown.
-
One of seven vulnerabilities (CVE-2024-38279 through CVE-2024-38285) disclosed in June 2024 in the Vigilant Fixed LPR Coms Box (BCAV1F2-C600, firmware 3.1.171.9 and earlier) under CISA advisory ICSA-24-165-19. CVE-2024-38280 (CVSS v4 7.0 High, assigned by ICS-CERT): 'An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text.' The companion CVE-2024-38281 (CVSS v4 8.6 High) states: 'An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.'
Why it matters here: Vendor-confirmed, government-published proof that fielded Vigilant hardware stored sensitive data and credentials unencrypted and shipped hard-coded credentials — concrete security failings independent of any policy claim. Both CVEs were loaded directly on NVD; the CISA advisory page itself is bot-gated (403) and unarchived, so no claim resting solely on it is asserted.
-
The currently live policy of Vigilant's sibling subsidiary, which collects the commercial half of the shared plate pool. It carries materially the same clauses as Vigilant's: 'The company retains LPR data as long as it has commercial value'; authorised uses include locating a specific vehicle 'under circumstances when there is a legitimate commercial interest' and use 'by law enforcement agencies for law enforcement purposes'; permissible recipients include 'Financial services companies and other businesses that have a legitimate commercial interest', 'Entities subject to Sections 6801 to 6809 of the United States Code' and 'Entities to which information may be disclosed as a permissible use pursuant to Section 2721 of Title 18'; and law enforcement query access is provided 'Through and affiliate subsidiary of our parent company' (typo in original) — that affiliate being Vigilant. The policy provides no individual opt-out.
Why it matters here: Establishes that the permissive retention, sale and law-enforcement-access language scored on the POLICY axis is current published policy today, not a 2016 artefact, and documents the DRN-to-Vigilant pipeline by which commercially collected scans reach police.
-
Motorola Solutions' own press release announcing the acquisition of VaaS International Holdings: 'Motorola Solutions paid a purchase price of $445 million in a combination of cash and equity.' Names the two subsidiaries — Vigilant Solutions, serving law enforcement users, and Digital Recognition Network (DRN), serving commercial customers.
Why it matters here: Primary confirmation of the corporate structure asserted in this record: Vigilant and DRN are sibling subsidiaries under Motorola Solutions, which is why DRN's live policy language is probative of Vigilant's. Scores no deduction; included so the ownership and date claims in the summary are citable.
Descriptive, cited, not legal advice; ratings are versioned and corrections create a new version. Data from the IoT Info Grabber DB research project, CC BY-SA 4.0.