Skip to main content
Security

Security you can trust

Voting is about trust. We've built vote.direct with security at every layer, from encryption to audit trails to privacy-first practices.

vote.direct is designed for private organizational elections. It is not certified or intended for public governmental elections.

View Security Roadmap

How we protect your votes

Concrete controls, plus explicit limits on what they prove

Encryption in Transit and at Rest

Data is protected in transit with TLS and at rest with managed encryption. Recorded election events are checked with a SHA-256 hash chain.

Privacy by Design

Two anonymous modes, chosen per election. Anonymous mode withholds the voter-to-ballot link from organizer views, results and exports and keeps it in restricted storage for vote changes, proxies and recounts. Sealed ballot mode stores the ballot with no link to the voter at all — no field, no audit entry, no receipt log — and shuffles the box at close (permanent separation, built for Cal. Civ. Code §5110(c)(4)(B)(iv) and Fla. Stat. §718.128(2)(d)).

Secure Infrastructure

Row-level security enforced at the database layer, hosted on enterprise-grade cloud infrastructure with automatic backups.

Complete Audit Trail

Election events are timestamped and hash-linked, making later changes detectable through an integrity check.

Identity Verification

Email, phone, and optional government-ID checks raise identity assurance. Eligibility still depends on the organizer's roster and election rules.

Duplicate Prevention

Roster controls, unique credentials, verification checks, and submission safeguards are used to prevent duplicate voting.

Security Roadmap

Our commitment to security standards and compliance

NIST CSF 2.0 & OWASP Top 10

Documented

Internal control mappings; no certification implied

SOC 2 Readiness

Underway

Control documentation underway; no SOC 2 report issued

SOC 2 Type II

Planned

Independent examination planned as we scale

ISO 27001

Evaluating

No ISO 27001 certification currently held

As we grow, we're committed to pursuing formal certifications that match our customers' needs. View our full compliance page.

Our security practices

How we maintain security every day

Data Minimization

We limit collection to operational, security, and disclosed analytics needs. We do not sell personal information.

Secure Development

Type checks, linting, automated tests, production builds, dependency lockfiles, and security-focused review support each release.

Access Controls

Row-level policies and ownership or organization-role checks restrict ordinary users to authorized data. Privileged service operations are isolated.

Responsible Disclosure

We welcome security reports at [email protected] and commit to prompt investigation and fixes.

Incident Response

How we handle security incidents

Documented Response Plan

We maintain an incident-response plan covering detection, containment, eradication, recovery, communications, and follow-up. The plan references SOC 2 Trust Services Criteria; no SOC 2 report has been issued.

48-Hour User Notification

We aim to notify affected users within 48 hours after confirming a breach that affects their data, subject to lawful delays needed for investigation or law enforcement.

Transparent Post-Mortems

Our policy is to document significant incidents, the response, and corrective actions, and to share an appropriate customer-facing post-mortem when disclosure is safe and lawful.

Operational Monitoring

Centralized exception capture and operational alerts help the team investigate failures and suspicious conditions.

Report a vulnerability

Found a security issue? We take all reports seriously and respond promptly.

[email protected]

Talk to a person

Have an election coming up?

Call or text us and a real person picks up. Tell us what you are voting on and we will explain the setup and exact published price, even if you are not ready yet. At 1,000 voters, our regular price is at least 95% below two-way First-Class postage alone.

Or leave us your contact

Leave an email and we will reach out. No account, no card, no obligation.