Trust Before It Was Required: Why Responsible Public Safety Technology Must Invite Scrutiny

Today, conversations about technology and privacy are everywhere. Artificial intelligence, facial recognition, license plate readers, drones, cameras, sensors, data aggregation, and other technologies have created important discussions about what information is collected, how it is used, who has access to it, how long it is retained, and what safeguards exist to protect the public.

Those are appropriate questions, particularly for companies operating in the public-safety technology space. But there is an even more fundamental question: 

Should technology companies wait for someone else to ask those questions, or should we be willing to ask them of ourselves?

For SoundThinking, that distinction is at the heart of responsible public-safety technology.

NYU Policing Project: An Independent Review We Chose to Undertake

In 2019, years before today’s heightened national conversation about artificial intelligence, data governance, and the expanding role of technology in public safety, SoundThinking®, then known as ShotSpotter®, engaged the Policing Project at New York University School of Law to conduct an independent privacy audit and assessment of ShotSpotter.

This was not simply an internal review. The Policing Project examined ShotSpotter’s policies, practices, and technology with a specific focus on personal privacy. Among the issues examined was whether the acoustic sensors used to detect impulsive sounds associated with gunfire created a meaningful risk of voice surveillance.

The Policing Project concluded that, overall, ShotSpotter presented relatively limited privacy risks and that the risk of voice surveillance was extremely low in practice. The audit also identified opportunities to further strengthen privacy protections.

That second part is important.

We did not undertake an independent audit simply to receive validation. We undertook it to learn.

When a company develops technology that operates in communities and supports public-safety decision-making, scrutiny comes with the territory. More importantly, responsible technology companies should not have to be forced into that scrutiny. We should invite it.

That principle remains important to SoundThinking today.

Independent review has limited value if an organization is unwilling to change.

The Policing Project made a series of recommendations intended to further strengthen the privacy protections surrounding ShotSpotter.  The recommendations addressed very practical questions about how audio should be handled, who should have access to it, how long it should be retained, and how the company should communicate those practices publicly.

SoundThinking adopted those recommendations, listed below, with minor modifications or qualifications:

  • Reducing the sensor audio buffer from 72 hours to approximately 30 hours.
  • Minimizing alert audio snippets to approximately one second before and one second after a detected incident.
  • Not providing precise sensor locations to law enforcement.
  • Denying requests and resisting subpoenas for audio beyond what is provided with an alert.
  • Restricting access to audio to a very small number of authorized ShotSpotter employees.
  • Requiring supervisor approval for any download of audio longer than one minute.
  • Creating and maintaining an audit trail of all audio access and regularly reviewing it.
  • Revising privacy and client-facing documents to more clearly describe policies and practices.
  • Where possible, avoiding placement of sensors in particularly sensitive locations.

The audit also raised an additional transparency issue related to third-party data sharing. While the Policing Project did not treat the sharing of aggregate gunfire data as a personal privacy issue, it recommended greater clarity around ShotSpotter’s data-sharing practices.

These may sound like technical or operational details, but taken together they represent something much larger. They demonstrate what responsible technology governance should look like:

Invite scrutiny. Listen to the findings. Make changes. Strengthen safeguards. Continue evaluating.

 An independent audit should never be simply a document that sits on a website. Its value comes from what an organization does with what it learns.

Privacy Shouldn’t Begin With Controversy

Too often, organizations begin serious conversations about privacy only after something happens: a controversy, lawsuit, legislative proposal, critical news story, community concern, or regulatory inquiry. At that point, the conversation can become defensive, focused on explaining why technology is safe, why existing policies are sufficient, or why public concerns may be based on misunderstandings.

 Privacy should be part of the conversation from the beginning.

That means asking difficult questions early. What does the technology collect, and what does it not collect? What could someone reasonably misunderstand about its capabilities? How is information retained? Who has access? What safeguards prevent inappropriate use? What policies should govern the technology? What forms of oversight might strengthen confidence in those safeguards?

It also means asking one of the most difficult questions for any organization: 

What might people outside our company see that we don’t?

That question requires humility, but it is essential to responsible innovation.

Independent Scrutiny Can Make Technology Better

There can be a natural reluctance for organizations to invite outsiders to examine what they do. After all, what happens if they find something that can be improved?

That is precisely the point.

Independent evaluation should not be viewed as an exercise designed to prove that an organization or technology is perfect. No technology is. Evaluation should help identify strengths, weaknesses, unintended consequences, opportunities for improvement, and areas where greater transparency may be necessary.

If an independent review identifies something that can be improved, improve it. If it identifies a misunderstanding about the technology, explain it. If it validates existing safeguards, document them. If it raises a question requiring additional research, study it.

The goal should not simply be to defend technology. The goal should be to continuously build better, more effective, and more responsible technology.

Alfred Lewers Jr., MPA

Vice President, Trauma Response & Community Engagement

“Trust Us” Is Not a Privacy Strategy

Public-safety technology companies occupy a unique position. Our customers may include police departments, cities, counties, and other government entities, but our stakeholders extend far beyond the organizations purchasing the technology. They include residents, elected officials, community organizations, researchers, civil-rights and privacy organizations, police officers, police executives, prosecutors, and many others.

Those stakeholders will not always agree about technology, and we should not expect them to. Disagreement does not eliminate our responsibility to engage. In many cases, disagreement makes engagement even more important.

Simply asking people to trust a company or technology is not enough. We should be prepared to explain what the technology does and does not do, what information it uses, what safeguards are in place, how those safeguards are evaluated, what limitations exist, and what independent reviewers have found.

The 2019 audit recommendations provide a practical example. Trust is strengthened when people can see specific limits on data retention, restrictions on access, audit trails, supervisory approval, protections against unnecessary disclosure, and clear public-facing policies.

Trust should be supported by evidence, transparency, safeguards, and accountability, not simply requested.

Responsible Technology Goes Beyond Privacy

The lesson extends beyond privacy. Public-safety technology companies also have responsibilities involving governance, transparency, effectiveness, training, implementation, community engagement, and program evaluation.

It is important to ask whether a technology performs as intended, but that should only be the beginning. We should also ask whether agencies are using it effectively, whether appropriate policies and procedures are in place, whether personnel are properly trained, whether outcomes are being measured, and whether there are unintended consequences.

We should ask whether community members understand the technology’s purpose and limitations. Public officials should be able to understand and communicate the value residents are receiving from their investment. And whenever appropriate, we should be willing to work with independent researchers who can test assumptions, evaluate outcomes, and help identify opportunities for improvement.

These questions should not threaten technology companies. They should make us better.

Our Responsibility Doesn’t End at Deployment

One principle that continues to shape our thinking at SoundThinking is that public-safety technology companies must see themselves as more than vendors. A vendor sells something. A partner accepts responsibility for helping ensure that the technology delivers on its intended purpose.

That means supporting strong policies and training, helping customers establish meaningful metrics, evaluating implementation, listening to the officers and other practitioners who use the technology, and engaging with the communities where it operates. It means taking privacy concerns seriously, listening to critics, acknowledging limitations, and continually looking for ways to strengthen safeguards and improve performance.

It also means helping customers evaluate not simply whether a technology functions, but whether the overall program is producing meaningful public-safety outcomes.

Technology alone rarely solves a complex public-safety problem. Technology works within an ecosystem of people, policies, procedures, training, leadership, community relationships, and other resources. Responsible technology companies should understand that larger environment and remain engaged in it.

Setting a Higher Standard for Responsible Innovation

Responsible innovation does not mean having every answer. It means being willing to ask difficult questions and invite people into the conversation who may see things differently. It means subjecting assumptions to scrutiny, measuring outcomes rather than simply making claims, and being willing to change when evidence identifies a better approach.

The 2019 privacy audit provides a useful example of that philosophy. The important story is not simply that an independent organization examined ShotSpotter and found relatively limited privacy risks. The more important story is that recommendations were made, we listened, and we implemented changes.

Reducing data retention, narrowing audio snippets, limiting access, creating audit trails, strengthening supervisory review, restricting disclosure, improving transparency, and considering sensitive sensor placement are examples of translating privacy principles into operational practice.

That is what independent scrutiny should accomplish.

Privacy, transparency, accountability, community engagement, and effectiveness are not obstacles to innovation. They are essential components of responsible innovation.

Public safety technology will continue to evolve, and our responsibility must adapt with it. Communities should not have to choose between innovation and accountability, between effective technology and privacy, or between public safety and public trust.

They should expect all of them.

And those of us who develop and support public-safety technology should expect the same of ourselves.

Let’s Continue the Conversation

We also recognize that conversations about public-safety technology, privacy, program evaluation, and community trust are best when they happen directly and openly.

If your organization, community, or jurisdiction would like to learn more about SoundThinking’s technology, privacy safeguards, responsible-use practices, community engagement approach, or how we work with customers to evaluate and strengthen their programs, our teams are available to participate in information sessions and discussions.

Our Government Affairs, Community Engagement, and Customer Success teams regularly work with elected officials, public-safety leaders, government executives, community organizations, and other stakeholders to answer questions, provide context, and support informed conversations about public-safety technology.

To request an information session or begin a conversation, email us at communityengagement@soundthinking.com.

We welcome the questions. We welcome the scrutiny. And we welcome the opportunity to have the conversation.

Was this article helpful?

Alfred Lewers Jr.

About the Author

Alfred Lewers Jr.

Alfred Lewers Jr., Vice President, Trauma Response & Community Engagement at SoundThinking, is a retired Assistant Chief of Police with the Miami Gardens Police Department, where he was instrumental in building the 300-member force from the ground up and managing the department's public safety technology strategies. He has also served as a Lieutenant with the Fort Lauderdale Police Department and a Senior Law Enforcement Project Manager with the Police Foundation.

View Author Profile

Search for More Insights