Audit
Independent verification is a core requirement for trustworthy electronic voting. Electobox is designed so that published artefacts — anonymised ballot data, decryption transcripts, and declared results — can be checked without access to voter identities.
What auditors can verify
With the appropriate exports and trustee cooperation where required, an auditor can confirm that:
- Published results match the decrypted tally of the anonymised ballot set
- The cryptographic record is internally consistent (signatures, ciphertexts, and threshold decryption steps align with the documented protocol)
Scope of an audit
Operational controls (access management, logging, infrastructure hardening) complement cryptographic verification. Your audit plan should cover both the mathematical properties of the system and the organisational processes around elections.