VOTERSBALLOTVERIFIED TALLY···ZKPROOFAnonymous credentialidentity never storedE2E VERIFIEDHomomorphic encryptionvote sealed until final tallyGuardian 1Guardian 2Guardian 3k-of-n thresholdA54%B31%C15%AUDITABLEThreshold trustee decryptionpublicly auditable resultFeature 1: Credentials without identity1Feature 2: Trusted-authority credential issuance (Votercare Elect)2Feature 3: Zero-knowledge eligibility proof3Feature 4: Homomorphic ballot encryption4Feature 5: Threshold trustee decryption (Votercare Elect)5Feature 6: Public cryptographic audit trail6VERIFIEDbadge · embeddableFeature 7: Embeddable verification badge7Both productsVotercare Elect only (2, 5)click a pin to explore

Create a poll in seconds. Results in real time.

Choose anonymous tallying or link responses to voter identities — you decide. Vote privacy and tally integrity are protected by verifiable cryptography, not just promises.

Votercare Poll verification badgeVotercare Elect verification badge
Voter.Care Verification Badges

Proof your voters can verify themselves

Every Voter.Care deployment ships with an embeddable verification badge — a live-fetched widget tied to that specific poll's cryptographic record. Voters click it to see real evidence, not marketing copy. Tier-specific, poll-specific, and anti-spoofed by design.

How verification badges work

How accuracy and privacy are achieved

Seven techniques — numbered on the diagram above — work together so every vote is counted correctly and no voter can be identified. Blue = both products · Gold = Votercare Elect only.

1
Both products

Credentials without identity

Your identity is never stored by the voting system

Voters register by generating a secret key on their own device. They share only a cryptographic commitment derived from that key — the system adds it to a Merkle tree of eligible commitments, but never sees or stores the key itself. No name, phone number, or email address is required or retained in the voting system. For a live event, registration can be as simple as scanning a QR code at the door; for an organisational poll, it integrates with an existing membership or employee directory to confirm eligibility, then discards the personal data once the commitment is issued. Eligibility is proved mathematically at vote time — not by looking you up in a database.

2
Votercare Elect only

Trusted-authority credential issuance

Votercare Elect only — identity verified before voting begins

Before a voter can participate in an Elect election, their identity is verified in person or via supervised remote session to a government-grade standard (NIST IAL3-equivalent). A trained operator issues the cryptographic credential — but a second, independent operator must co-sign every issuance, so no single person can create a fraudulent voter. The resulting credential is stored in the voter's own device or wallet; no central voter registry is held by the system.

3
Both products

Zero-knowledge eligibility proof

Prove you can vote without saying who you are

At vote time, your device generates a zero-knowledge proof of group membership — mathematically proving you hold a valid credential — plus a per-election nullifier derived from your secret. The nullifier blocks double-voting without linking either cast to your identity.

4
Both products

Homomorphic ballot encryption

Votes are tallied without anyone reading them

Your vote is encrypted on your device before transmission. The system sums encrypted ballots using homomorphic arithmetic — addition without decryption — so nobody reads individual votes, not even the operator. Only the aggregate result is ever revealed. At any point you can also trigger a Benaloh challenge: your device proves it encrypted your vote correctly by revealing its randomness, but a challenged ballot is discarded rather than counted — so there is no coercible receipt.

5
Votercare Elect only

Threshold trustee decryption

No single party can reveal or falsify the result

The tally is only decryptable when a quorum (k-of-n) of independent trustees act together. The private key is mathematically split across them using Shamir's Secret Sharing and never assembled in one place at any point. One trustee coerced or compromised cannot alter the outcome.

6
Both products

Public cryptographic audit trail

Anyone can independently verify the final count

The final tally includes a published cryptographic proof any technically capable party can verify independently. Checking the arithmetic closes the end-to-end loop: the proof links the complete set of valid encrypted ballots, the accumulated homomorphic sum of those ciphertexts, and the decrypted final tally. Verifying it confirms the result is precisely the sum of those specific ballots and nothing else. Because the proof ties the output to specific input ciphertexts, it is impossible to silently add a vote (would require forging a ZK eligibility proof, computationally infeasible), remove a vote (breaks the accumulation proof), or alter the tally after decryption (breaks the decryption proof). A correct arithmetic check means the count is accurate — independently of whether you trust Voter.Care or the poll organiser.

7
Both products

Embeddable verification badge

The public face of the cryptographic proof — for voters to check themselves

Every poll generates a live-fetched embeddable badge, tied to that poll's cryptographic proof record in Voter.Care's backend. Anyone — voter, auditor, journalist, regulator — can click it to verify independently that the poll used the techniques described above, backed by the actual published evidence: nullifier set, ZK proofs, and encrypted tally. The badge cannot be detached or spoofed: it visibly breaks if separated from a verified, live poll record. Poll owners embed it on their platform or results page as a verifiable trust signal for their audience.

Blog

News and articles

Read about our design decisions, the cryptographic techniques behind our products, and the real-world problems we're solving.

Visit the Blog

Interested in Voter.Care?

Whether you're a trade union, political party, professional body, or media company — we'd love to hear from you.

Get in touch