Straight answers
Questions boards actually ask.
The ones that come up before a board signs anything, answered without the hedging. Where the honest answer is “not yet”, it says so.
Do voters need to install anything?
No. There is no app, no account, and nothing to download. Members vote in a normal web browser using a private code you send them, from a phone or a computer. Behind the scenes there’s a public, tamper-evident record of every ballot, so the result can be independently recounted, but you and your members never have to think about the plumbing, only about the result you can check. The whole system is open source, so anyone can inspect exactly how it works.
Are votes really anonymous?
Yes. A member’s ballot can’t be linked back to them: not by other members, not by the board, not even by Plainvote. That’s enforced by the math, not by a promise. At the same time, the public arithmetic proves no extra ballots were added.
What if a member loses their code?
You issue a replacement from the console, and doing so cancels the old one. That is deliberate rather than a limitation: we never keep a copy of a code that could be re-sent, so the only way to replace one is to replace it. The member gets a fresh link, the old link stops working, and the roll size does not change.
What if a member’s computer is infected?
On Managed elections we mail each voter a return-code sheet. After voting, they check a short code against their sheet to confirm the system recorded the choice they actually made, a check that malware on their device can’t fake. It’s optional, and honest about what it does and doesn’t protect.
Who keeps the record?
Right now, we do. The system is built for several organizations to keep the record in parallel, each signing with its own key, and recruiting independent keepers is on our roadmap, and we’ll name them here once they’re in place. Until then, what protects your result isn’t our good behaviour. The record is public and tamper-evident, so anyone who keeps their own copy (a candidate, an observer, you) can prove it if it ever changes. That check doesn’t depend on who runs the servers.
Has it been independently audited?
The software is fully open source and every election is independently recountable today. That’s a stronger everyday check than most closed vendors offer. A formal third-party security audit is on our roadmap, and we publish an honest account of exactly what the system does and does not guarantee (it’s designed for organizational elections, not binding government ones). We’d rather tell you the limits than oversell.
Can we run it ourselves?
Yes: the entire voting engine, everything that records, counts and verifies ballots, is open source (AGPL-3.0). Technical organizations can self-host it; everyone else pays us to run it so they don’t have to. Either way, the recount tool works the same, and nothing about the result depends on trusting us specifically.
Still deciding?
Every scenario is priced on the page, so there is nothing to wait for. If your question is not here, email us and a person will answer it.