VoteAlly platform background
Back to Home
Trust Center

Enterprise-Grade Security.
Built for Trust.

Security isn't just a feature - it's the foundation of democracy. We employ defense-in-depth strategies to ensure that every vote is verifiable, anonymous, and immutable.

Voter Anonymity

We enforce a strict cryptographic decoupling of voters from their ballots. While we verifyeligibility to vote, the contents of the vote are encrypted in a way that makes it mathematically impossible to trace a specific choice back to a specific individual. Your voice is counted; your identity is protected.

Defense-in-Depth Infrastructure

Our platform is hosted on SOC 2 Type II compliant infrastructure. The network is protected by enterprise-grade DDoS mitigation and Web Application Firewalls (WAF), inspecting traffic at the edge.

End-to-End Encryption

Data is encrypted in transit using TLS 1.3 and at rest using AES-256. Sensitive fields, including ballot choices, are encrypted at the application layer before storage, ensuring that even a database compromise would yield no readable voting data.

Zero-Trust Authentication

We utilize high-entropy magic links for passwordless authentication, eliminating the risk of compromised passwords. Access logic is protected by granular Role-Based Access Control (RBAC) and strict, IP-aware rate limiting to prevent brute-force attacks.

Comprehensive Audit Trails

Every administrative action - from creating an election to viewing results - is persistently logged with actor attribution. These strict audit trails allow for complete transparency and accountability for election organizers.

AI Data Handling: Zero Data Retention

VoteAlly's AI session assistant and readiness advisor are processed through the Vercel AI Gateway under zero data retention (ZDR) agreements with all model providers. Only structural session configuration is sent; voter personal information is never included. Under these agreements, prompts and responses are not retained or used for model training by any provider.

How it works

  • Session config is sent to the AI Gateway for analysis
  • The gateway routes to the active model provider under ZDR
  • The response is returned and the request data is discarded
  • No voter PII, ballot data, or results are ever sent to AI

Data protection posture

  • Vercel is VoteAlly's sole AI subprocessor
  • Model providers are Vercel's subprocessors, not ours
  • The active provider may change; all enforce ZDR
  • See Vercel's ZDR docs for the provider list

Security posture last reviewed: July 28, 2026