ABOUT NOREC.US

Surveillance is easier to accept when nobody tells you it is there.

NoRec.US is an independent privacy and public-records project documenting government surveillance technology, connected systems, and the records that establish how they operate.

This project did not begin with a theory that every camera, database, or government employee is malicious. It began with a simpler question: what is being collected, who can search it, who can receive it, how long does it exist, and why did most of us never hear about it?

HOW THIS STARTED

One camera became a much larger question.

NoRec.US grew out of concern about automated license plate readers, particularly networked systems such as Flock Safety cameras. A license-plate camera can look simple when considered by itself: a camera sees a vehicle, records a plate, and helps an agency find a vehicle of interest.

The larger questions begin with the surrounding system.

Where does the observation go? How long is it retained? What else is recorded with it? Which agencies can search it? Can another jurisdiction search it? Can observations from many locations be combined? Can the resulting history reveal where a vehicle has been, which vehicles repeatedly appear together, or patterns that were never visible from a single camera?

That led to a broader concern: data fusion. Modern surveillance is not necessarily one extraordinary sensor watching everything. It can be many ordinary systems whose records become far more revealing when they are searchable, shareable, retained, and combined.

THE MOMENT THAT CLARIFIED THE PROJECT

If people do not know a system exists, meaningful public debate is difficult.

On September 9, 2026, while researching Illinois surveillance law, the founder of NoRec.US learned that Illinois law expressly addresses facial-recognition search services involving photographs maintained by the Secretary of State for driver's licenses, permits, and identification cards.

That discovery was striking precisely because it was not obscure personal information. It was written into Illinois law. Yet someone who actively follows privacy, surveillance, public records, and government technology had gone through the Illinois credentialing process without coming away aware of that facial-recognition framework.

PERSONAL EXPERIENCE — NOT A GENERAL CLAIM

The founder does not recall being informed at the DMV that photographs maintained by the Secretary of State are subject to statutory provisions concerning facial-recognition search services. NoRec.US has not established that Illinois DMV facilities universally fail to provide such notice, and does not present that personal experience as proof of a statewide practice.

One person's experience cannot establish statewide notice practices. It does illustrate a broader problem: consequential surveillance capabilities can be lawful and publicly documented while remaining largely invisible to the people represented in the underlying records.

WHAT NOREC IS

An evidence project with a point of view.

NoRec.US is strongly pro-privacy and skeptical of population-scale surveillance. It is not politically neutral about whether governments and their contractors should accumulate increasingly searchable records of people's identities, movements, associations, vehicles, devices, and activities.

That does not mean the evidence gets bent to fit the position.

Surveillance technologies can have legitimate uses. A facial-recognition search may help identify the unknown suspect in a serious violent crime. An ALPR may locate a stolen vehicle or generate a useful lead in an abduction. Cameras can document events accurately. Data sharing can help an agency pursue evidence held in another jurisdiction.

Those benefits deserve to be stated plainly because the real debate begins after acknowledging them: what infrastructure is justified to obtain those benefits, what population should be made searchable, what safeguards constrain access, what happens to innocent people's records, and what occurs when the system inevitably outlives the circumstances under which it was first approved?

THE STANDARD

Show the record. Mark the uncertainty.

NoRec.US is built around three labels:

DOCUMENTED

The record establishes it.

A statute, regulation, contract, policy, public record, agency publication, technical record, or other sufficiently reliable source directly supports the claim.

UNKNOWN

We do not have the answer.

The available evidence does not establish the fact. An inference may seem plausible, but plausibility is not documentation.

UNDER INVESTIGATION

There is a question worth answering.

The issue is being researched through records requests, source comparison, or other evidence capable of resolving it.

A statute can establish that a facial-recognition search service exists without establishing historical retention. A vendor can offer a capability without proving that a particular agency enabled it. Those distinctions remain explicit throughout the site.

“We don't know” is an acceptable result. It is often the beginning of the next records request.

PRIMARY SOURCES FIRST

Read the underlying record.

Wherever practical, claims link directly to the material supporting them: statutes, regulations, government policies, contracts, procurement records, meeting records, audits, technical documentation, FOIA responses, and other primary sources.

Secondary reporting and research can provide context and identify records worth pursuing. When the underlying document is available, readers should be able to inspect it directly.

Citations stay close to the claims they support so the underlying record is easy to inspect.

WHY THE SCOPE IS BROADER THAN FLOCK

The network matters as much as the sensor.

Flock Safety and automated license plate readers helped start this project, but NoRec.US is not an anti-Flock website and is not limited to ALPRs. Vendors change. Contracts end. New sensors appear. Databases become interoperable. Capabilities that were once expensive become routine.

The enduring questions are about systems and power:

  • Can a person, vehicle, device, or location be identified?
  • Can observations be searched retrospectively?
  • Can records be combined to reveal patterns?
  • Who owns or operates the infrastructure?
  • Which agencies, contractors, or jurisdictions can access it?
  • What legal predicate, if any, is required?
  • How long is information retained?
  • Can it be exported or shared again?
  • Is access logged and independently audited?
  • What happens after a breach, compromised credential, bad query, or policy change?

A surveillance system should be evaluated not only by what its operator says it is for today, but by what the architecture makes possible tomorrow.

WHY SECURITY BELONGS IN A PRIVACY PROJECT

Good intentions do not patch vulnerabilities.

Assume every authorized user acts in good faith. Sensitive databases still depend on administrators, credentials, software, networks, contractors, backups, integrations, endpoints, and human beings.

Systems get breached. Credentials get phished. Vendors are compromised. Software has vulnerabilities. Access is misconfigured. Employees make mistakes. A database can expose people even when nobody who was supposed to use it intended harm.

That is one reason data minimization matters. Information that was never collected cannot later leak from that collection. Information deleted under a meaningful retention policy is no longer sitting there waiting for a future compromise. Information never shared does not become another organization's security obligation.

Biometrics make this question particularly important. Passwords can be changed. Keys can be rotated. A face is not a replaceable credential. That does not mean every exposed facial image or template can automatically defeat every biometric system; it means the underlying characteristic is persistent, so careless collection and retention can create unusually durable consequences.

COMMERCIAL SURVEILLANCE

Public power can be privately packaged.

Private companies can build useful technology, often faster and more efficiently than an agency could build it internally. The fact that a system has a vendor is not proof that the system is abusive.

Commercialization does, however, add another incentive to the equation. A surveillance vendor can benefit from more customers, more integrations, larger networks, new capabilities, longer contracts, and greater dependence on its platform. Public agencies can gain powerful capabilities without building the underlying infrastructure themselves.

NoRec.US therefore follows the money as well as the technology: contracts, subscriptions, grants, procurement records, renewals, vendor representations, data-sharing arrangements, and the rules governing what happens to information when an agency changes providers.

Taxpayers should be able to see what surveillance capabilities they are purchasing and the conditions attached to them.

WHAT THIS PROJECT IS NOT

No assumption of bad intent.

NoRec.US is not built around the claim that every camera is sinister, every police officer is abusing a database, every contractor is stealing data, or every unexplained technical capability is secretly active.

It is also not a promise of ideological neutrality. The project begins from the view that privacy has value, that surveillance power deserves scrutiny, and that population-scale tracking or identification should carry a substantial burden of justification.

The standard is simple: criticize what can be demonstrated, investigate what cannot, correct what turns out to be wrong, and do not manufacture certainty because a stronger headline would be more exciting.

OPEN BY DESIGN

Copy it. Check it. Improve it. Use it.

The project's original code is open source, and contributions from developers, researchers, journalists, public-records researchers, privacy advocates, subject-matter experts, and skeptical readers are welcome.

If another project can use the research, reproduce the website, build a better interface, mirror public records, challenge an interpretation, or turn the material into something that reaches people NoRec never would, that is a success.

The objective is to make the underlying information harder to overlook and easier to verify.

THE POINT

You cannot meaningfully debate a system you do not know exists.

People may look at the same evidence and reach different conclusions about what surveillance is justified. That disagreement is legitimate.

But first, the evidence has to be visible.

NoRec.US exists to put it in front of you.

COMMUNITY

Follow the research or contribute.

NoRec.US is open to researchers, journalists, developers, and anyone interested in documenting surveillance systems with verifiable evidence.