In Development — Phase 3
Votercare Elect

Gold Standard.
Provably accurate. Completely private.

Maximum-assurance digital voting for political parties, trade unions, and national ballots. No single party can read individual votes, falsify the result, or identify any voter — and every one of those claims is independently verifiable from published cryptographic proofs.

Votercare Elect
Speaker addressing a large crowd
What is Votercare Elect?

More trustworthy than paper — provably

Any organisation that runs its own digital voting faces an unavoidable conflict of interest: the central system controls both the voter list and the ballot box, which means it can — in principle — link votes to identities and alter results without anyone knowing. The only way to close that gap is a cryptographic third party that verifies eligibility and tallies votes whilst receiving no voter personal data whatsoever — no names, no phone numbers, no email addresses. Voter.Care is that third party, and Votercare Elect is its highest-assurance product.

Privacy — enforced at the protocol level, not by policy. Voter identity is never stored by the voting system. Eligibility is proved by a zero-knowledge credential. Votes are encrypted with homomorphic encryption — the operator tallies without decrypting any individual ballot. The private decryption key is split across independent trustees using Shamir's Secret Sharing and never assembled in one place at any point.

Accuracy — verifiable by anyone, not just claimed. The final tally includes a published cryptographic proof. Any voter, auditor, or journalist can download it and verify that every counted vote was validly cast, no vote was added or altered, and the arithmetic is correct. Every design decision traces to a documented, sourced rationale — not AI-generated assertion.

Honest scope. The central claim is that this design is more secure and more cost-effective than the UK's current voting infrastructure — not that it achieves theoretical perfection. Paper voting is retained as a mandatory parallel channel. Before any real votes go through Votercare Elect, an independent third-party cryptographic audit is a non-negotiable prerequisite.

Polling Service Features

The same ease of use as Votercare Poll — with identity assurance and mandatory anonymity built in.

Process overview — letter pins correspond to the features below
Enrolment
Before voting opens
ACredential-based access
Voting window
BPoll types
CAnonymity enforced
Tally
DResults dashboard
Audit
EEmbed & verify
FAudit trail
A

No voter account required

Voters authenticate using the cryptographic credential issued during identity verification. No Voter.Care account, no password, and no personal information collected at voting time.

B

Multiple poll types

Single choice, multiple choice, and ranked-choice voting. The same flexible question format as Votercare Poll — once your electorate is credentialed, running a ballot is as straightforward as running a poll.

C

Voter anonymity — enforced, not optional

Unlike Votercare Poll (where anonymity is a choice), Elect enforces it at the protocol level for every ballot. The organiser sees aggregate turnout, not who voted for what. Voter.Care cannot make that link either.

D

Results dashboard — live or sealed

Choose whether results are revealed in real time or held until the voting window closes. For national or high-stakes ballots it is often better to withhold the running tally to avoid influencing late voters. Either way, a final audited tally with a published cryptographic proof is produced at the close.

E

Embeddable results and verification

Embed the live tally and the final cryptographic proof on your own platform. The verification page is permanently linked and publicly accessible — not just a result, but evidence of how it was reached.

F

Audit trail — verified, not just logged

Every ballot produces a published cryptographic proof. Any voter, observer, or journalist can independently verify that every counted vote was validly cast, nothing was altered, and the arithmetic is correct.

Going deeper

Privacy & Integrity Features

Every control listed here is documented with its threat-model rationale, not just asserted.

Process overview — numbered pins correspond to the controls below
Enrolment
Before voting opens
1Identity proofing
2Maker-checker issuance
3ZK credential issued
Voting window
Credential ③ carried by voter
4Encrypted ballot cast
5Revote option
6Paper override
Tally
Ballots summed (④), then opened
7Threshold decrypt
Audit
8Register check
9CoP compliance

In-person identity proofing (IAL3-equivalent)

A trained human operator verifies identity in person or via supervised remote session. This is a one-time enrolment cost per voter, amortised across all future elections — the credential persists once issued.

Maker-checker credential issuance

No single operator can issue a credential unilaterally. A second, independent reviewer must countersign every issuance. Each issuance is cryptographically signed by the specific operator, enabling per-operator auditing.

Zero-knowledge anonymous credentials

Based on the Semaphore protocol. Eligibility is proved by a ZK group-membership proof. The system stores only cryptographic commitments — no names, emails, or voter records — and cannot link any cast vote to any individual.

Homomorphic ballot encryption

Votes are encrypted on-device before transmission. The operator tallies using homomorphic arithmetic — summing encrypted ballots without decrypting any of them. Individual vote content is never accessible to anyone during or after the election.

Revoting + coercion resistance

Voters may re-cast during the advance voting period; only the last vote counts. A coercer supervising a vote can never be certain it wasn't overridden later, in private — removing the incentive to coerce in the first place.

Paper ballot override

An in-person paper vote always overrides any digital vote from that voter — the ultimate fallback for coercion and a full system resilience guarantee. The digital channel is an addition, not a replacement.

Threshold (k-of-n) trustee decryption

The tally is decryptable only when a quorum of independent trustees act together. The private key is split using Shamir's Secret Sharing and never assembled in one place. One trustee coerced or compromised cannot alter the outcome.

Population reconciliation

Aggregate credential counts are cross-checked against known eligible population at national, constituency, and per-operator granularity. Localised spikes that stay invisible nationally are detected statistically without exposing any personal data.

UK Code of Practice compliant — and beyond

Designed against the 2026 Code of Practice on Electronic and Workplace Balloting. The zero-personal-data credential model exceeds the Code's personal-email/SMS requirement by eliminating the interception risk structurally rather than mitigating it.

A rigorous trust model

Security properties that can be verified, not just claimed.

No single point of trust

Power is deliberately split across voters, operators, trustees, and auditors. No single party can compromise integrity alone.

Statistical deterrence

Where absolute guarantees are cryptographically impossible (Benaloh challenge, revoting), the system provides well-designed statistical deterrents with a high, unpredictable detection probability.

Defence in depth

Multiple independent controls address the same threat — device malware, credential fraud, trustee collusion — rather than relying on any single mechanism.

Documented threat model

A full adversary table (A1–A17) is published alongside the design, so every assumed attacker and every mitigation can be independently reviewed.

Standards alignment

Self-assessed against the NIST Cybersecurity Framework Election Infrastructure Profile

Votercare Elect has been assessed against NIST VTS 200-1 — the risk management framework used across the US election ecosystem. We found strong alignment on transparency, voter privacy, ballot secrecy, auditability, and data protection, with identified gaps documented openly and on the development roadmap.

Read the full self-assessment →
Target markets

Who Votercare Elect is built for

🏛️

Political parties

Leadership elections, policy ballots, and internal governance for new and established political parties.

⚒️

Trade unions

Industrial action ballots, leadership elections, and political fund ballots under the 2026 UK Code of Practice on Electronic and Workplace Balloting.

📋

Professional bodies

High-stakes governance elections for medical, legal, engineering and other regulated professional membership organisations.

UK Regulatory context

2026 Trade Union Electronic Balloting Reform

The Employment Rights Act 2025 and the Trade Unions (Permissible Means of Voting) Order 2026 authorise electronic balloting for trade unions for the first time, with a draft Code of Practice expected in force August 2026. The Code requires the "responsible person" to actively assess the security of the proposed voting method. Votercare Elect is designed to make that assessment straightforward — every security control is documented, sourced, and independently verifiable.

Workers gathered in a formal meeting
Technology

Built on established prior art

ZK Proofs & Credentials
Semaphore protocol (PSE)
Key management
Shamir's Secret Sharing (k-of-n trustees)
Coercion resistance
Revoting (last-vote-wins) + paper override
Codebase
Open source, reproducible builds

No novel cryptographic primitives are invented. The design reuses established, peer-reviewed protocols — Semaphore, ElectionGuard, Shamir's Secret Sharing — rather than designing new schemes from scratch.

Implementation

Flexible integration, tailored to your organisation

Votercare Elect can be integrated via a hosted web app, embeddable widget, REST API, or native no-code plugin — for both the voter-facing ballot and the operator credential issuance workflow. The right approach depends on your existing platforms, technical capacity, and the scale of your election. Voter.Care will work closely with you to identify and implement the best option for your specific context.

Get in touch to discuss your requirements →
Server infrastructure for secure digital systems
Votercare Elect verification badge
Voter.Care Verification Badge

Give members verifiable proof, not a promise

Every Votercare Elect deployment comes with an embeddable gold-standard verification badge. Any member can click it to see that specific ballot's verification record — confirming in-person identity proofing, maker-checker issuance, threshold trustee decryption, and the published cryptographic tally proof. The linked page also explains plainly what the badge does and does not guarantee.

How verification badges work →

Interested in Votercare Elect?

We're seeking pilot partners — political parties, trade unions, and professional bodies interested in a rigorously documented, independently auditable voting system.

Register your interest