How a sealed ballot works
The link between a member and their ballot is separated and discarded, the box closes at the deadline, and the stored order is shuffled at close.
Step by step
- 1
The ballot arrives with a name on it
A member proves control of the email or phone on your roster, then marks a ballot. Right now the ballot and the member are linked. They have to be, or nothing stops a second vote.
- 2
The name comes off, and is not kept
In sealed-ballot mode the identity is separated and discarded. Not hidden from the board view, not held in restricted storage. No field, no audit entry, no receipt log ties this ballot to that member.
- 3
The box closes at the deadline
Sealed ballots go into a box nobody opens early. There is no live tally to watch and no changing a vote after it is cast, because changing one would need a link back to the voter.
- 4
The box is shuffled at close
When the election closes the stored order is mixed. The sequence ballots arrived in stops being a clue about who cast which one.
- 5
Nothing is left to re-pair
The result is countable and the audit record still proves the count. What nobody can produce, the board and vote.direct included, is the member behind any single ballot.
What this does not claim
Sealed-ballot mode is one of two anonymous modes, and it is a choice you make per election. It suits statutes that require permanent separation. It also gives up things some boards need: no vote changes after submission, no live tally, and no way to answer a member who asks how their own ballot was recorded. If you need those, anonymous mode keeps the link in restricted storage instead. We will tell you which one your statute points to. We will never tell you that you are compliant.
Read the detail on the security page.