
📄 Companion Report: For full financial modeling, legal citations, and contract safeguards, read the Detailed Policy Report (PDF).
Public Safety Without Surveillance Abuse: Protecting Resident Privacy and Data Sovereignty
Mark Leonard | Fountain Valley City Council candidate
The short version
Modern forensic tools help our police solve property crimes and recover stolen vehicles. However, I permanently oppose contracting with Flock Safety or any vendor that compromises local data sovereignty, maintains documented cybersecurity vulnerabilities, or enables warrantless nationwide surveillance tracking. Public safety and constitutional rights are not opposing goals. Fountain Valley must establish strict standards for public safety technology: local data custody, an automated 30-day deletion schedule, strict prohibitions on warrantless out-of-state sharing, and mandatory public audit logs.
Modern police tools vs. third-party surveillance dragnets
Automated License Plate Readers (ALPR) are effective when deployed with narrowly scoped search criteria tied to active felony investigations. But outsourcing city surveillance infrastructure to centralized private cloud vendors creates profound constitutional and cybersecurity risks.
Flock Safety pools vehicle movement data into an interconnected national network accessible to thousands of outside entities. In June 2024, a Norfolk, Virginia Circuit Court ruling determined that warrantless, dragnet collection of vehicle location data violates Fourth Amendment protections against unreasonable searches.
Documented cybersecurity vulnerabilities
Entrusting municipal surveillance data to third-party multi-tenant cloud platforms creates severe digital liability:
- In late 2025, an independent security audit exposed an unauthenticated vulnerability revealing 335,701 Flock camera locations nationwide.
- Federal lawmakers called for FTC investigations regarding stolen police credentials that exposed cloud-hosted camera networks to unauthorized external actors.
Under California Civil Code § 1798.90.5 et seq. (SB 34 - Automated License Plate Reader Privacy Act), public agencies must maintain strict operational security and public transparency. Entrusting municipal surveillance to high-risk private cloud providers exposes the city to major legal and security liabilities.
A four-point standard for Fountain Valley public safety technology
Fountain Valley should enforce four non-negotiable requirements for any public safety technology:
- Local sovereign data custody: All data collected in Fountain Valley must remain the property of the city, stored in encrypted local custody, and governed by an automatic 30-day hard purge for all non-hit data.
- Strict prohibition on warrantless sharing: Prohibit open-ended data sharing with outside federal agencies, out-of-state entities, or private corporations without a specific judicial search warrant.
- Immutable audit logging: Require every individual search query to be tied to an official police report case number, with mandatory quarterly public compliance audits.
- Independent third-party penetration testing: Require annual independent cybersecurity penetration tests and source code reviews before approving or renewing any vendor contract.
Leading with discipline and accountability
As a Marine Corps veteran and operations analyst, I know that real security depends on discipline, clear rules of engagement, and institutional accountability. We can support our local police department with effective investigative tools while vigorously defending the Fourth Amendment privacy rights of every Fountain Valley resident.
Mark Leonard is running for Fountain Valley City Council.
📄 Download Companion Report: Read the full Detailed Policy Report & Financial Analysis (PDF)



