Security

Run elections with confidence.

Security you can check, described precisely. Below is what PollGuard does today — and, just as importantly, what it does not yet do.

What protects your election

Each of these is implemented and in use today.

🔒

Encrypted connections

All traffic runs over TLS. Certificates are monitored and renewed automatically so the site cannot silently lapse.

🔑

Hardened authentication

Passwords are hashed with Argon2id at OWASP-recommended parameters. Accounts lock after five failed attempts. Sessions use short-lived access tokens with rotating refresh tokens and reuse detection.

🧾

Per-ballot receipts

Every ballot produces a SHA-256 receipt. Any voter can look up their receipt and confirm their ballot was recorded, without revealing how they voted.

👤

Human-reviewed verification

Document, face and liveness checks are scored automatically, then every verification is reviewed by an administrator. Nothing is approved by the model alone.

One member, one ballot

Eligibility is checked against membership status and verification level, and the system enforces a single ballot per position.

🛡

Rate limiting and abuse controls

Login, voting and verification endpoints are individually rate limited to resist brute-force and automated abuse.

What we do not claim

Election technology attracts a lot of overstatement. We would rather you knew exactly where the boundaries are, because these are the questions a careful auditor will ask.

  • We do not currently offer end-to-end verifiable voting. Receipts let an individual voter confirm their own ballot was recorded. There is no public bulletin board that lets a third party independently recompute the result.
  • We do not claim homomorphic tallying, a blockchain audit trail, or post-quantum cryptography. These are on our roadmap and are listed unpriced on our pricing page. We will not sell them until they are real.
  • Ballot secrecy is operational, not cryptographic. Ballots are protected by access controls rather than a cryptographic separation of voter and choice. If your election requires a mathematically guaranteed secret ballot, talk to us before you commit.
  • Our audit log is not tamper-evident. It records actions for review, but it is not currently hash-chained or signed, so it should be treated as an operational record rather than cryptographic proof.

If any of this is a blocker for your election, we would rather tell you now than after the vote.

Member data and Kenyan law

Running verification means handling sensitive personal data — identity documents, facial images and, where used, fingerprint enrolment. We treat that as regulated data under the Data Protection Act, 2019.

  • Members are told what is collected and why before verification begins.
  • Identity data is used for verification and eligibility, not for marketing or profiling.
  • Members can request a copy of their data or ask for their account to be deleted.
  • Access to member records is restricted by role and recorded.

Read our privacy policy and data protection notice for the detail.

Have a security question we have not answered?

We will answer plainly, including where the answer is “not yet”.