Trust & compliance
The facts, not a wall of badges.
What we run on, who else processes your data, what we have and have not been certified for, and what has actually gone wrong.
Infrastructure and data location
PollGuard runs on dedicated cloud infrastructure, with the application, database and cache under our control rather than spread across third-party services. Uploaded verification material and media are stored on the same controlled infrastructure.
We will confirm the specific hosting region in writing as part of a data processing agreement — we would rather put that in your contract than make a general claim on a web page.
Availability posture
Be aware of this before you plan a high-stakes election: PollGuard currently runs as a single-region deployment without automatic failover. Multi-region high availability is on our roadmap. For any significant election we agree a capacity and support arrangement in advance, and maintenance is scheduled away from active voting windows. We do not publish an uptime percentage, because we do not yet operate a status page and will not invent a figure.
Security practices in place
Encryption in transit
All traffic runs over TLS, with certificates monitored and renewed automatically.
Credential handling
Passwords hashed with Argon2id at OWASP-recommended parameters, account lockout after repeated failures, short-lived access tokens with rotating refresh tokens and reuse detection.
Role-based access
Administrator capabilities are permission-scoped, including branch-level scoping, and administrative actions are recorded.
Abuse controls
Per-route rate limiting on authentication, voting and verification endpoints, with security headers and a locked-down cross-origin policy.
Human review of identity
No member is approved or rejected by an automated model alone; every verification passes through an administrator.
Availability monitoring
Automated checks on certificate expiry, application health and public reachability, with alerting to our team.
Subprocessors
These third parties may process data on our behalf. Each acts on our instructions and may not use your data for its own purposes.
- Cloud hosting provider — compute, database and storage for the application.
- Let’s Encrypt — issues the TLS certificates that secure connections. No personal data is shared.
- Google (Gemini API) — AI-assisted reading of identity documents during verification. Document images are transmitted for processing.
- Safaricom (M-Pesa Daraja) — mobile money payments for invoices. Billing data only; no voter or ballot data.
- Stripe — card payments for invoices. Billing data only; no voter or ballot data.
- SMS gateway — delivery of notifications and one-time passcodes. Recipient phone numbers and message content only. A production provider is configured per deployment; where none is configured, SMS is not sent.
We will notify customers of a material change to this list. Ask us for the current version with provider names and regions as part of your data processing agreement.
Certifications: what we do not have
PollGuard holds no ISO 27001 certification and no SOC 2 report, and we have not completed an independent third-party penetration test that we can share. If a procurement process requires either, we will tell you plainly that we cannot meet it today rather than gesture at a roadmap.
What we can provide is this page, our security page — which states precisely what our system does and does not prove — a data processing agreement, and direct access to the people who built it.
Incident history
- 11–15 July 2026 — TLS certificate expiry. The public certificate lapsed because an automated renewal job ran with an environment that could not locate a required binary, so renewals had been failing silently. Visitors saw a browser security warning and the login page was unreachable for some users. No data was exposed and no election was in progress. Resolved by reissuing the certificate; root cause fixed in the renewal job, and automated certificate-expiry monitoring added so a silent failure cannot recur.
We will record material incidents here with what happened, the impact, and what changed as a result.
Reporting a vulnerability
If you believe you have found a security issue, please contact us with enough detail to reproduce it, and give us a reasonable opportunity to fix it before disclosing publicly. We will acknowledge your report, keep you updated, and credit you if you would like that. Please do not test against a live election, and do not access data belonging to anyone other than yourself.
Need a data processing agreement?
Ask us and we will send the current DPA and subprocessor list.