The record establishes it.
A statute, regulation, contract, policy, public record, agency publication, technical record, or other sufficiently reliable source directly supports the claim.
ABOUT NOREC.US
NoRec.US is an independent privacy and public-records project documenting government surveillance technology, connected systems, and the records that establish how they operate.
This project did not begin with a theory that every camera, database, or government employee is malicious. It began with a simpler question: what is being collected, who can search it, who can receive it, how long does it exist, and why did most of us never hear about it?
HOW THIS STARTED
NoRec.US grew out of concern about automated license plate readers, particularly networked systems such as Flock Safety cameras. A license-plate camera can look simple when considered by itself: a camera sees a vehicle, records a plate, and helps an agency find a vehicle of interest.
The larger questions begin with the surrounding system.
Where does the observation go? How long is it retained? What else is recorded with it? Which agencies can search it? Can another jurisdiction search it? Can observations from many locations be combined? Can the resulting history reveal where a vehicle has been, which vehicles repeatedly appear together, or patterns that were never visible from a single camera?
That led to a broader concern: data fusion. Modern surveillance is not necessarily one extraordinary sensor watching everything. It can be many ordinary systems whose records become far more revealing when they are searchable, shareable, retained, and combined.
THE MOMENT THAT CLARIFIED THE PROJECT
On September 9, 2026, while researching Illinois surveillance law, the founder of NoRec.US learned that Illinois law expressly addresses facial-recognition search services involving photographs maintained by the Secretary of State for driver's licenses, permits, and identification cards.
That discovery was striking precisely because it was not obscure personal information. It was written into Illinois law. Yet someone who actively follows privacy, surveillance, public records, and government technology had gone through the Illinois credentialing process without coming away aware of that facial-recognition framework.
The founder does not recall being informed at the DMV that photographs maintained by the Secretary of State are subject to statutory provisions concerning facial-recognition search services. NoRec.US has not established that Illinois DMV facilities universally fail to provide such notice, and does not present that personal experience as proof of a statewide practice.
One person's experience cannot establish statewide notice practices. It does illustrate a broader problem: consequential surveillance capabilities can be lawful and publicly documented while remaining largely invisible to the people represented in the underlying records.
WHAT NOREC IS
NoRec.US is strongly pro-privacy and skeptical of population-scale surveillance. It is not politically neutral about whether governments and their contractors should accumulate increasingly searchable records of people's identities, movements, associations, vehicles, devices, and activities.
That does not mean the evidence gets bent to fit the position.
Surveillance technologies can have legitimate uses. A facial-recognition search may help identify the unknown suspect in a serious violent crime. An ALPR may locate a stolen vehicle or generate a useful lead in an abduction. Cameras can document events accurately. Data sharing can help an agency pursue evidence held in another jurisdiction.
Those benefits deserve to be stated plainly because the real debate begins after acknowledging them: what infrastructure is justified to obtain those benefits, what population should be made searchable, what safeguards constrain access, what happens to innocent people's records, and what occurs when the system inevitably outlives the circumstances under which it was first approved?
THE STANDARD
NoRec.US is built around three labels:
A statute, regulation, contract, policy, public record, agency publication, technical record, or other sufficiently reliable source directly supports the claim.
The available evidence does not establish the fact. An inference may seem plausible, but plausibility is not documentation.
The issue is being researched through records requests, source comparison, or other evidence capable of resolving it.
A statute can establish that a facial-recognition search service exists without establishing historical retention. A vendor can offer a capability without proving that a particular agency enabled it. Those distinctions remain explicit throughout the site.
“We don't know” is an acceptable result. It is often the beginning of the next records request.
PRIMARY SOURCES FIRST
Wherever practical, claims link directly to the material supporting them: statutes, regulations, government policies, contracts, procurement records, meeting records, audits, technical documentation, FOIA responses, and other primary sources.
Secondary reporting and research can provide context and identify records worth pursuing. When the underlying document is available, readers should be able to inspect it directly.
Citations stay close to the claims they support so the underlying record is easy to inspect.
WHY THE SCOPE IS BROADER THAN FLOCK
Flock Safety and automated license plate readers helped start this project, but NoRec.US is not an anti-Flock website and is not limited to ALPRs. Vendors change. Contracts end. New sensors appear. Databases become interoperable. Capabilities that were once expensive become routine.
The enduring questions are about systems and power:
A surveillance system should be evaluated not only by what its operator says it is for today, but by what the architecture makes possible tomorrow.
WHY SECURITY BELONGS IN A PRIVACY PROJECT
Assume every authorized user acts in good faith. Sensitive databases still depend on administrators, credentials, software, networks, contractors, backups, integrations, endpoints, and human beings.
Systems get breached. Credentials get phished. Vendors are compromised. Software has vulnerabilities. Access is misconfigured. Employees make mistakes. A database can expose people even when nobody who was supposed to use it intended harm.
That is one reason data minimization matters. Information that was never collected cannot later leak from that collection. Information deleted under a meaningful retention policy is no longer sitting there waiting for a future compromise. Information never shared does not become another organization's security obligation.
Biometrics make this question particularly important. Passwords can be changed. Keys can be rotated. A face is not a replaceable credential. That does not mean every exposed facial image or template can automatically defeat every biometric system; it means the underlying characteristic is persistent, so careless collection and retention can create unusually durable consequences.
COMMERCIAL SURVEILLANCE
Private companies can build useful technology, often faster and more efficiently than an agency could build it internally. The fact that a system has a vendor is not proof that the system is abusive.
Commercialization does, however, add another incentive to the equation. A surveillance vendor can benefit from more customers, more integrations, larger networks, new capabilities, longer contracts, and greater dependence on its platform. Public agencies can gain powerful capabilities without building the underlying infrastructure themselves.
NoRec.US therefore follows the money as well as the technology: contracts, subscriptions, grants, procurement records, renewals, vendor representations, data-sharing arrangements, and the rules governing what happens to information when an agency changes providers.
Taxpayers should be able to see what surveillance capabilities they are purchasing and the conditions attached to them.
WHAT THIS PROJECT IS NOT
NoRec.US is not built around the claim that every camera is sinister, every police officer is abusing a database, every contractor is stealing data, or every unexplained technical capability is secretly active.
It is also not a promise of ideological neutrality. The project begins from the view that privacy has value, that surveillance power deserves scrutiny, and that population-scale tracking or identification should carry a substantial burden of justification.
The standard is simple: criticize what can be demonstrated, investigate what cannot, correct what turns out to be wrong, and do not manufacture certainty because a stronger headline would be more exciting.
OPEN BY DESIGN
The project's original code is open source, and contributions from developers, researchers, journalists, public-records researchers, privacy advocates, subject-matter experts, and skeptical readers are welcome.
If another project can use the research, reproduce the website, build a better interface, mirror public records, challenge an interpretation, or turn the material into something that reaches people NoRec never would, that is a success.
The objective is to make the underlying information harder to overlook and easier to verify.
THE POINT
People may look at the same evidence and reach different conclusions about what surveillance is justified. That disagreement is legitimate.
But first, the evidence has to be visible.
NoRec.US exists to put it in front of you.
COMMUNITY
NoRec.US is open to researchers, journalists, developers, and anyone interested in documenting surveillance systems with verifiable evidence.