Gold Standard.
Provably accurate. Completely private.
Maximum-assurance digital voting for political parties, trade unions, and national ballots. No single party can read individual votes, falsify the result, or identify any voter — and every one of those claims is independently verifiable from published cryptographic proofs.
More trustworthy than paper — provably
Any organisation that runs its own digital voting faces an unavoidable conflict of interest: the central system controls both the voter list and the ballot box, which means it can — in principle — link votes to identities and alter results without anyone knowing. The only way to close that gap is a cryptographic third party that verifies eligibility and tallies votes whilst receiving no voter personal data whatsoever — no names, no phone numbers, no email addresses. Voter.Care is that third party, and Votercare Elect is its highest-assurance product.
Privacy — enforced at the protocol level, not by policy. Voter identity is never stored by the voting system. Eligibility is proved by a zero-knowledge credential. Votes are encrypted with homomorphic encryption — the operator tallies without decrypting any individual ballot. The private decryption key is split across independent trustees using Shamir's Secret Sharing and never assembled in one place at any point.
Accuracy — verifiable by anyone, not just claimed. The final tally includes a published cryptographic proof. Any voter, auditor, or journalist can download it and verify that every counted vote was validly cast, no vote was added or altered, and the arithmetic is correct. Every design decision traces to a documented, sourced rationale — not AI-generated assertion.
Honest scope. The central claim is that this design is more secure and more cost-effective than the UK's current voting infrastructure — not that it achieves theoretical perfection. Paper voting is retained as a mandatory parallel channel. Before any real votes go through Votercare Elect, an independent third-party cryptographic audit is a non-negotiable prerequisite.
Polling Service Features
The same ease of use as Votercare Poll — with identity assurance and mandatory anonymity built in.
No voter account required
Voters authenticate using the cryptographic credential issued during identity verification. No Voter.Care account, no password, and no personal information collected at voting time.
Multiple poll types
Single choice, multiple choice, and ranked-choice voting. The same flexible question format as Votercare Poll — once your electorate is credentialed, running a ballot is as straightforward as running a poll.
Voter anonymity — enforced, not optional
Unlike Votercare Poll (where anonymity is a choice), Elect enforces it at the protocol level for every ballot. The organiser sees aggregate turnout, not who voted for what. Voter.Care cannot make that link either.
Results dashboard — live or sealed
Choose whether results are revealed in real time or held until the voting window closes. For national or high-stakes ballots it is often better to withhold the running tally to avoid influencing late voters. Either way, a final audited tally with a published cryptographic proof is produced at the close.
Embeddable results and verification
Embed the live tally and the final cryptographic proof on your own platform. The verification page is permanently linked and publicly accessible — not just a result, but evidence of how it was reached.
Audit trail — verified, not just logged
Every ballot produces a published cryptographic proof. Any voter, observer, or journalist can independently verify that every counted vote was validly cast, nothing was altered, and the arithmetic is correct.
Privacy & Integrity Features
Every control listed here is documented with its threat-model rationale, not just asserted.
In-person identity proofing (IAL3-equivalent)
A trained human operator verifies identity in person or via supervised remote session. This is a one-time enrolment cost per voter, amortised across all future elections — the credential persists once issued.
Maker-checker credential issuance
No single operator can issue a credential unilaterally. A second, independent reviewer must countersign every issuance. Each issuance is cryptographically signed by the specific operator, enabling per-operator auditing.
Zero-knowledge anonymous credentials
Based on the Semaphore protocol. Eligibility is proved by a ZK group-membership proof. The system stores only cryptographic commitments — no names, emails, or voter records — and cannot link any cast vote to any individual.
Homomorphic ballot encryption
Votes are encrypted on-device before transmission. The operator tallies using homomorphic arithmetic — summing encrypted ballots without decrypting any of them. Individual vote content is never accessible to anyone during or after the election.
Revoting + coercion resistance
Voters may re-cast during the advance voting period; only the last vote counts. A coercer supervising a vote can never be certain it wasn't overridden later, in private — removing the incentive to coerce in the first place.
Paper ballot override
An in-person paper vote always overrides any digital vote from that voter — the ultimate fallback for coercion and a full system resilience guarantee. The digital channel is an addition, not a replacement.
Threshold (k-of-n) trustee decryption
The tally is decryptable only when a quorum of independent trustees act together. The private key is split using Shamir's Secret Sharing and never assembled in one place. One trustee coerced or compromised cannot alter the outcome.
Population reconciliation
Aggregate credential counts are cross-checked against known eligible population at national, constituency, and per-operator granularity. Localised spikes that stay invisible nationally are detected statistically without exposing any personal data.
UK Code of Practice compliant — and beyond
Designed against the 2026 Code of Practice on Electronic and Workplace Balloting. The zero-personal-data credential model exceeds the Code's personal-email/SMS requirement by eliminating the interception risk structurally rather than mitigating it.
A rigorous trust model
Security properties that can be verified, not just claimed.
No single point of trust
Power is deliberately split across voters, operators, trustees, and auditors. No single party can compromise integrity alone.
Statistical deterrence
Where absolute guarantees are cryptographically impossible (Benaloh challenge, revoting), the system provides well-designed statistical deterrents with a high, unpredictable detection probability.
Defence in depth
Multiple independent controls address the same threat — device malware, credential fraud, trustee collusion — rather than relying on any single mechanism.
Documented threat model
A full adversary table (A1–A17) is published alongside the design, so every assumed attacker and every mitigation can be independently reviewed.
Self-assessed against the NIST Cybersecurity Framework Election Infrastructure Profile
Votercare Elect has been assessed against NIST VTS 200-1 — the risk management framework used across the US election ecosystem. We found strong alignment on transparency, voter privacy, ballot secrecy, auditability, and data protection, with identified gaps documented openly and on the development roadmap.
Read the full self-assessment →Who Votercare Elect is built for
Political parties
Leadership elections, policy ballots, and internal governance for new and established political parties.
Trade unions
Industrial action ballots, leadership elections, and political fund ballots under the 2026 UK Code of Practice on Electronic and Workplace Balloting.
Professional bodies
High-stakes governance elections for medical, legal, engineering and other regulated professional membership organisations.
2026 Trade Union Electronic Balloting Reform
The Employment Rights Act 2025 and the Trade Unions (Permissible Means of Voting) Order 2026 authorise electronic balloting for trade unions for the first time, with a draft Code of Practice expected in force August 2026. The Code requires the "responsible person" to actively assess the security of the proposed voting method. Votercare Elect is designed to make that assessment straightforward — every security control is documented, sourced, and independently verifiable.
Built on established prior art
No novel cryptographic primitives are invented. The design reuses established, peer-reviewed protocols — Semaphore, ElectionGuard, Shamir's Secret Sharing — rather than designing new schemes from scratch.
Flexible integration, tailored to your organisation
Votercare Elect can be integrated via a hosted web app, embeddable widget, REST API, or native no-code plugin — for both the voter-facing ballot and the operator credential issuance workflow. The right approach depends on your existing platforms, technical capacity, and the scale of your election. Voter.Care will work closely with you to identify and implement the best option for your specific context.
Get in touch to discuss your requirements →Give members verifiable proof, not a promise
Every Votercare Elect deployment comes with an embeddable gold-standard verification badge. Any member can click it to see that specific ballot's verification record — confirming in-person identity proofing, maker-checker issuance, threshold trustee decryption, and the published cryptographic tally proof. The linked page also explains plainly what the badge does and does not guarantee.
How verification badges work →Interested in Votercare Elect?
We're seeking pilot partners — political parties, trade unions, and professional bodies interested in a rigorously documented, independently auditable voting system.
Register your interest