Security & Certifications in Electronic Voting
At EVoting we guarantee the highest security standards in electronic voting and digital participation processes. Our platform combines international certifications, advanced cryptography, external audits and regulatory compliance to ensure the integrity, privacy and legal validity of every process.
Our origin: cryptography and academia
EVoting was founded in 2013 as a spin-off of Inria Chile —the local branch of the French National Institute for Research in Digital Science and Technology—, created by computer science and cryptography researchers from the University of Chile.
Its founding team brings together PhDs in computing from the University of Nice-Sophia Antipolis, the École Polytechnique and the École Normale Supérieure in Paris. That scientific foundation is what underpins the cryptographic design of every vote.
International Certification ISO/IEC 27001:2022
We hold ISO/IEC 27001:2022 certification, the most demanding global standard for Information Security Management Systems (ISMS).
This certification validates our controls in:
- Confidentiality of information
- Integrity of electoral data
- Platform availability throughout the entire process
We ensure rigorous risk management and data protection under international standards.
Advanced Cryptography and Vote Secrecy
Each vote is encrypted on the voter's device, and the tally is performed over the encrypted votes (homomorphic encryption): only the consolidated result is decrypted, through a key ceremony held in custody by the court or auditor of the process. An individual vote is never decrypted.
- Homomorphic encryption: votes are counted without the need to decrypt them one by one.
- Key ceremony: opening the tally requires the concurrence of keys distributed in the custody of third parties (court or auditor), so that neither EVoting nor the organiser can open the votes on their own.
- Ballot secrecy by design: the cryptographic architecture separates the voter's identity from their choice.
Privacy and Data Protection Policy
We apply a strict Personal Data Protection Policy based on the principle of privacy by design.
- Limited use of information: Voter roll data is used exclusively to authenticate and validate voting rights.
- Secure data deletion: Once results have been ratified, certified deletion protocols are executed for sensitive data, safeguarding confidentiality after the process concludes.
Ethical Hacking and External Audits
The platform is periodically subjected to penetration tests (pentesting) carried out by independent experts.
These audits enable us to:
- Identify and mitigate vulnerabilities
- Validate the system's robustness against real-world threats
- Continuously strengthen our technological infrastructure
In addition, the system incorporates verifiable logs that allow external auditing without compromising voter anonymity.
Authorisations and Legal Validity
- Chilean Labour Directorate: EVoting was the first company to receive a favourable ruling from the Chilean Labour Directorate to carry out electronic voting in trade union organisations and State employee associations (Ruling ORD. No. 3362/053, 2014). Our code was physically reviewed by the authority, a level of validation that sets us apart from any other provider.
- Compensation Funds: we hold a ruling from the Chilean Labour Directorate for affiliation and de-affiliation processes to Family Allowance Compensation Funds (Cajas de Compensación de Asignación Familiar) (Ruling ORD. No. 4969/0079, 2016).
- Electoral backing: we are a technology provider for the Electoral Service of Chile (SERVEL) and received the Tech for Democracy 2023 recognition.
Frequently asked questions
Find answers to the most common questions about our services.