Security you can trust
Voting is about trust. We've built vote.direct with security at every layer, from encryption to audit trails to privacy-first practices.
vote.direct is designed for private organizational elections. It is not certified or intended for public governmental elections.
View Security RoadmapHow we protect your votes
Concrete controls, plus explicit limits on what they prove
Encryption in Transit and at Rest
Data is protected in transit with TLS and at rest with managed encryption. Recorded election events are checked with a SHA-256 hash chain.
Privacy by Design
Two anonymous modes, chosen per election. Anonymous mode withholds the voter-to-ballot link from organizer views, results and exports and keeps it in restricted storage for vote changes, proxies and recounts. Sealed ballot mode stores the ballot with no link to the voter at all — no field, no audit entry, no receipt log — and shuffles the box at close (permanent separation, built for Cal. Civ. Code §5110(c)(4)(B)(iv) and Fla. Stat. §718.128(2)(d)).
Secure Infrastructure
Row-level security enforced at the database layer, hosted on enterprise-grade cloud infrastructure with automatic backups.
Complete Audit Trail
Election events are timestamped and hash-linked, making later changes detectable through an integrity check.
Identity Verification
Email, phone, and optional government-ID checks raise identity assurance. Eligibility still depends on the organizer's roster and election rules.
Duplicate Prevention
Roster controls, unique credentials, verification checks, and submission safeguards are used to prevent duplicate voting.
Security Roadmap
Our commitment to security standards and compliance
NIST CSF 2.0 & OWASP Top 10
Internal control mappings; no certification implied
SOC 2 Readiness
Control documentation underway; no SOC 2 report issued
SOC 2 Type II
Independent examination planned as we scale
ISO 27001
No ISO 27001 certification currently held
As we grow, we're committed to pursuing formal certifications that match our customers' needs. View our full compliance page.
Our security practices
How we maintain security every day
Data Minimization
We limit collection to operational, security, and disclosed analytics needs. We do not sell personal information.
Secure Development
Type checks, linting, automated tests, production builds, dependency lockfiles, and security-focused review support each release.
Access Controls
Row-level policies and ownership or organization-role checks restrict ordinary users to authorized data. Privileged service operations are isolated.
Responsible Disclosure
We welcome security reports at [email protected] and commit to prompt investigation and fixes.
Incident Response
How we handle security incidents
Documented Response Plan
We maintain an incident-response plan covering detection, containment, eradication, recovery, communications, and follow-up. The plan references SOC 2 Trust Services Criteria; no SOC 2 report has been issued.
48-Hour User Notification
We aim to notify affected users within 48 hours after confirming a breach that affects their data, subject to lawful delays needed for investigation or law enforcement.
Transparent Post-Mortems
Our policy is to document significant incidents, the response, and corrective actions, and to share an appropriate customer-facing post-mortem when disclosure is safe and lawful.
Operational Monitoring
Centralized exception capture and operational alerts help the team investigate failures and suspicious conditions.
Report a vulnerability
Found a security issue? We take all reports seriously and respond promptly.
[email protected]