Counts, users, reasons, case references, cameras, recipients, coverage state, and visible review gaps.
What do you want to review?
Attach an authorized Flock-shaped export, open a public evidence fixture, or continue the current review.
Choose the Flock record you need to check. Load it here. Get an operational answer and a city-held receipt.
AXM Witness reads an authorized export locally, recognizes the activity it contains, shows what was searched, detected, shared, or missing, and preserves the exact file underneath the review. It never turns a clean receipt into a claim that the vendor delivered records the city never received.
Source identity, frozen field recognition, record sequence, commitments, signatures, faults, and downloadable receipts.
An ordinary export cannot answer that alone. Useful cursors, high-water marks, signed inventories, or an independent origin witness are required.
Five steps from export to receipt
You do not need to understand hashes or custody packets before beginning. Those controls remain available after the operational review.
Detections, searches, exports and shares, or camera coverage.
Select, drop, or paste an authorized file. Nothing is uploaded.
Witness shows which fields it recognized and leaves uncertainty visible.
The exact file and interpretation are frozen before records enter custody.
Review findings, proof level, open limits, and the city-held receipt.
What are you trying to check?
Choose the operational question first. The page then tells you what file to provide and what answer it can return.
Load the export and inspect what Witness recognized
Menu names and columns can vary by agency configuration and product release. The selected file is preserved by exact bytes, while uncertain interpretation remains correctable before admission.
Source provenance pending.
Limitations pending.
The next preserved export will be attached to the existing review, retain the prior source version, and return the review to Ready.
Auto-detect record family
Load an authorized export and let Witness inspect it locally.
An authorized CSV, JSON, NDJSON, TSV, or text export
A record time plus recognizable user, camera, recipient, query, status, or event fields.
A plain-language activity review plus a city-held receipt
Witness will show the activity present, visible field gaps, source custody result, achieved proof level, and open completeness boundary.
Waiting for a source
Choose a review family and load an authorized export.
This freezes the exact file and recognized field map, creates the local custody session, runs verification, and opens the relevant findings. It does not transmit the source or connect to Flock.
Advanced: review or correct recognized fields
The current review is loading.
Representative data is open. Start a new review to load an authorized export and repeat the same governed flow.
Detections, searches, disclosures, and coverage entries present in the supplied source.
Operational gaps and unresolved proof boundaries remain visible even when custody verification passes.
Verification will recompute the source, field map, sequence, chain, signatures, and fault ledger.
Pre-delivery omission remains open unless the source provides useful completeness or independent-origin evidence.
What appears in the supplied export
What requires attention
Recent source activity0 records
Advanced: inspect how the source became a city-held receipt
pendingThe browser generates a local signing key. Production custody remains city-held Ed25519 with independently distributed trust roots.
Selected event commitment
No packet selected.
Commitment chain
Select an admitted packet to inspect its source identity, packet identity, prior chain, current chain, and signature.
Vehicle detections
Review the supplied plate or vehicle reads by capture time, camera, location, direction, and available vehicle attributes. The local display may show authorized source values; public receipts do not.
Whether the selected file was preserved exactly, each supplied detection can be attributed to a row and camera, and the admitted sequence can be recomputed. It cannot prove that a vendor-exclusive system delivered every detection that existed upstream.
No vehicle detections are present in the current review.
Import a detection export or open the representative sample.
Search audit
Review each supplied search by user, time, reason, case reference, query, and result count. Missing fields remain visible and are never filled in by the demonstrator.
Who ran the search, when it occurred, the supplied investigative reason, whether a case reference was recorded, and whether the exact audit file later changed. A case reference may be optional in the source workflow; Witness reports its presence without inventing a policy violation.
No searches are present in the current review.
Import an authorized search audit or open the representative sample.
Camera coverage
Review the supplied inventory, camera state, last-seen information, source cursor, high-water mark, and declared gap state. Coverage claims rise only as high as the evidence actually present.
A normal file can support receipt integrity. Monotonic cursors, useful high-water marks, or signed inventories can support delivery-completeness checks. Only an independently witnessed origin path can make silent pre-delivery omission detectable without relying on the vendor.
No coverage records are present in the current review.
Import camera inventory or coverage evidence, or open the representative sample.
Every review item has an owner, permitted action, rationale, and retained disposition.
The operational issue and the custody result remain separate. A supervisor can assign, acknowledge, request replacement evidence, approve, refuse, reopen, or close the review without leaving its source and receipt context.
Download the result a reviewer can keep.
The receipt separates the operational review from the cryptographic proof. Public exports omit raw rows and ordinary identifiers. Exact source bytes enter a private local package only through explicit opt-in.
PENDING
Run verification to recompute the custody state.
The current source has not yet been verified.
The verification report will state whether the selected file and city-held sequence recompute cleanly, then preserve the upstream completeness boundary separately.
Record-family counts, achieved proof level, source identity, faults, verification checks, and explicit exclusions. No raw source rows.
All demonstrator tables and verification metadata. Exact source bytes remain excluded unless you opt in below.
The latest recomputation of source identity, packet identity, sequence, chain, cursor, signature, privacy, and package-boundary controls.
The same local application, containing the representative sample and no automatic network requests.
The department can export the complete local ledger, including exact source bytes and its local signing material, inside a passphrase-encrypted AES-256-GCM envelope. Restore verifies the envelope before replacing this browser store and continues under the same local trust root.
Inspect the custody database and exact source object
Selected row
Select a row to inspect the stored object.
Exact source custody
The source table retains name, media type, byte count, SHA-256, parser disposition, mapping identity, and the exact local bytes.
The work begins from public evidence, not from a vendor permission gate.
AXM Witness now carries pinned empirical excerpts, documented audit schemas, current Palm Springs portal metrics, and registered open-source camera ecosystems. Every source stays classified by what it actually is: exact excerpt, indexed snapshot, documented schema, normalized derivative, or community heuristic.
Organization, Network, Public Audit, SharedNetworks, event log, portal usage, policy, agency access, agency survey, and camera candidates.
Real public rows with upstream commits, blob identities, byte counts, and source classifications.
Official portal, public records, newsroom corpus, accountability community, DeFlock/OSM, and Flock Finder/WiGLE.
Authorized access is needed for live conformance and stronger evidence, not for building the empirical adapter floor.
Current public target state
The official transparency page was indexed with a July 24, 2026 update. This is a current public declaration, not retained portal HTML and not the current Public Search Audit CSV.
Use the sources now available
The buttons below stage a real excerpt, a current public snapshot, or an explicitly marked schema/derivative fixture. The classification follows the source into the review.
The News & Observer Private Eyes
More than 360 transparency portals, usage statements, sharing relationships, policy snapshots, agency surveys, and a 50.4 MB combined public-search-audit corpus.
Have I Been Flocked schema floor
Documented Organization Audit, Network Audit, Public Audit, SharedNetworks, event-log, and settings evidence families derived from public-records releases.
MuckRock productions
Agency responses can contain original audit CSVs, network-sharing files, event logs, and settings screenshots. The campaign register records discovered productions but does not pretend their bytes were acquired here.
DeFlock and OpenStreetMap
Crowdsourced ALPR reporting supplies independent deployment hypotheses, OSM tagging, and field-verification targets outside the vendor portal.
Flock Finder and WiGLE
OUI and SSID observations provide candidate locations and observation windows. They remain stale, incomplete, and unconfirmed until corroborated.
What can be recognized now
Recognition does not convert a derivative into an original, a portal statement into operational truth, or a candidate camera into confirmed inventory.
| Adapter | Operational object | Empirical floor | Primary limitation |
|---|---|---|---|
flock.organization-audit@1 | Search accountability | Documented released-file schema | Original electronic export not yet retained |
flock.network-audit@1 | Cross-network searches | Documented redacted schema | Operator and plate fields commonly redacted |
flock.public-search-audit@1 | Public search history | 50.4 MB upstream corpus pinned | Current PSPD CSV endpoint not materialized |
flock.shared-networks@1 | Sharing relationships | Documented columns plus portal names | Directionality requires original file |
flock.event-log@1 | Administrative actions | Documented event-log columns | Live event taxonomy unqualified |
flock.transparency-usage@1 | Portal metrics | Pinned real excerpts | Agency/vendor declaration only |
flock.transparency-policy@1 | Published policy | Pinned real excerpts | Publication does not prove enforcement |
flock.agency-access@1 | External access graph | 1.69 MB upstream blob pinned | Full bytes not acquired here |
flock.agency-survey@1 | Agency deployment survey | Pinned real excerpt | Survey/records synthesis |
community.flock-finder-camera-candidates@1 | Candidate camera inventory | Pinned exact public excerpt | Heuristic and unconfirmed |
Partner access is a conformance gate, not the starting gun.
Public evidence already supports source custody, schema detection, redaction handling, drift tests, sharing graphs, policy comparison, portal history, and candidate-inventory reconciliation.
Conform against the current PSPD environment.
Live API behavior, current original exports, PSPD identity and policy, useful completeness denominators, and an independent origin witness remain separate gates.
Roles constrain actions; the review history preserves who exercised authority.
This demonstrator uses synthetic local identities. Production PSPD identity, policy, retention, and key ceremony remain integration requirements rather than implied capabilities.
Demonstration identities do not establish real municipal authentication or employment standing.
Local receipt generation does not select or enforce an approved records schedule.
Browser-generated demonstration keys do not replace city-held signing keys and independently distributed trust roots.
Representative adapters do not establish a live API, export schema, completeness denominator, or origin-independent feed.
See exactly what the city can prove, and where the vendor still controls the denominator.
AXM Witness keeps three claims separate: integrity of records received, completeness of the vendor-declared delivery stream, and independent proof at the point of origin.
Received records unchanged
The city can prove that a record received into municipal custody was retained, sequenced, signed, and not later altered without detection.
- Exact source-file identity
- Frozen field recognition
- Packet and chain recomputation
- Deletion, duplication, and reordering detection
- Portable public and private receipts
Vendor-declared stream complete
The delivery contract supplies monotonic cursors, high-water marks, or signed inventories that let the city identify gaps between the stream the vendor declares and the records delivered.
- Cursor namespace and epoch
- Expected-next continuity
- High-water or inventory denominator
- Explicit gap and rollback faults
- Still dependent on vendor declaration quality
Independent origin witness
The event is committed by a city-controlled or independently witnessed path before vendor-exclusive custody, making silent pre-delivery omission independently detectable.
- Camera-side or edge-side commitment
- Independently admitted source key
- Dual delivery or controlled network boundary
- Origin signature verification
- Cannot be inferred from an ordinary export
Can Palm Springs independently detect a capture, search, or disclosure that the vendor omitted before it entered city custody, or can it only prove that records delivered to the city were not altered afterward?
Each drill mutates an isolated clone and runs the same verifier. A drill passes only when the planted defect is detected or explicitly classified outside the achieved proof level.