How it works Verification Transparency Platforms Blog Get early access
Blog · Position

Why we will not run your government election yet

The technology is not the binding constraint, and pretending otherwise would be the fastest way to lose the trust the product is built on.

Build anything in this space and the question arrives within a week: could this run a real election? A national one?

The honest answer is no — not near-term — and the reason is not that the cryptography is not ready. It is that binding public elections sit inside a legal and procedural apparatus that no amount of engineering elegance moves. Certification regimes, custody requirements, recount procedure, accessibility law, and a standard of evidence that has to survive an adversarial challenge in court. Those constraints are the product's environment. Reasoning from what the category does, rather than from what is actually true, is how you end up building something impressive that cannot legally be used.

The failure mode we are avoiding

A product that markets itself for government elections while quietly not being usable for them spends its credibility to buy attention. For most companies that is a survivable trade. For this one it is fatal, because the entire proposition is that our claims can be checked. A single overstated claim invites the reader to assume the checkable ones are decorated too.

We would rather be boring and correct on the way in.

Where the same machinery is immediately useful

Non-binding verified polling, at any scale. No certification regime governs what a poll may claim about a population — which is precisely why unverified polling is so weak. A verified panel with published composition, a suppression floor and a stated privacy budget is a materially different kind of evidence from a number with a margin of error and no account of who answered.

Binding votes inside organisations. HOAs, associations, boards, co-ops and member organisations hold votes that are legally meaningful to the people casting them, under governing documents rather than election law. They have real disputes, real quorum rules, and frequently no audit trail worth the name. Every hard part we have built — personhood, one token, an on-chain tally, an exportable audit trail — lands directly on that problem, today, without asking a legislature for permission.

What would have to change

We are not saying never. We are saying the gating items are not on our roadmap because they are not ours to ship: certification pathways that contemplate cryptographic tallies, a settled legal answer on custody and recount for a distributed record, and accessibility standards met in the room rather than in a spec. Those move on a timescale set by institutions.

What we can do meanwhile is build the thing so that when those constraints move, the engineering is not the reason we are unready — and be publicly specific about which of our capabilities are shipped, which are specified, and which are aspiration. That list lives on the mechanism page, and it is deliberately unflattering.

The general rule

A transparency product does not get to be selectively transparent about itself. If we will not publish a demographic cell with four people behind it, we should not publish a capability claim with four months of work behind it either. Same principle, applied inward.

← All posts

Hold us to the checkable version.

Join the waitlist for testnet access and the verification reports unverified polls never publish.

Get early access