Security in electronic voting ISO/IEC 27001:2022 International Certification
Three independent backers —ISO 27001, annual Hackmetrix audits and rulings from Chile's Labour Directorate— certify that every election we run is secure and legally valid.
Certifications that back every process
None of our certifications are a decorative seal: each is the result of an independent external assessment. ISO/IEC 27001:2022 certifies our information security management, Hackmetrix audits the platform's resilience against real attacks every year, and Chile's Labour Directorate formally ruled on the legal validity of our union processes. Three different lenses, one goal: making every election secure and trustworthy.
ISO/IEC 27001:2022: the most demanding standard in information security
It is the only internationally certifiable standard for Information Security Management Systems (ISMS), and it applies to the entire organisation, not just the technology platform.
- Confidentiality, integrity and availability: the three pillars of the ISMS are verified in every election we run.
- Annual maintenance audit: an accredited certification body verifies every year that controls remain current and effective.
- Risk management and continuity: electoral process risks are identified, mitigated and backed by a documented continuity plan.
Certified scope
- Risk management
- Access controls
- Operations security
- Business continuity
Annual cybersecurity audits with Hackmetrix
Every year, Hackmetrix —a company specialising in offensive security— audits the EVoting platform through penetration testing (pentesting) and vulnerability analysis, independently from the ISO 27001 certification.
- Annual pentesting: external experts simulate real attacks against the web application, APIs and infrastructure before each election season.
- Findings documented and fixed: every vulnerability detected is remediated and verified before the platform goes into production.
- Input for continuous improvement: the results of these audits feed the continuous improvement cycle required by the certified ISMS.
Regulatory recognition in Chile: Labour Directorate and CMF
EVoting holds explicit recognition from two Chilean regulators: the Labour Directorate, which enabled electronic voting for unions and public-sector bodies, and the CMF, whose General Rule No. 435 authorizes remote voting for shareholder meetings.
- Ruling ORD. No. 3362/053 (2014): enables electronic voting in union elections, following a physical review of the source code by the authority.
- Ruling ORD. No. 4969/0079 (2016): enables the use of EVoting for affiliation and disaffiliation processes at Family Allowance Compensation Funds.
- Ruling ORD. No. 758, Labour Directorate (2025): enables the use of EVoting for votes by Joint Health and Safety Committees (CPHS) and Bipartite Training Committees.
- Ongoing legal validity: every union process operated with EVoting complies with the Labour Directorate's current requirements.
- Alignment with NCG 435: Chile's Financial Market Commission (CMF) General Rule No. 435 (NCG 435) explicitly authorizes remote voting and participation mechanisms for shareholder meetings, a framework under which the platform operates in full compliance.
Certified security at every layer of the process
Three independent backers that complement each other in every election we run.
ISO/IEC 27001:2022
Current ISMS certification, with an annual maintenance audit by an accredited body.
Hackmetrix audit
Annual pentesting carried out by independent offensive security experts.
Labour Directorate
Two rulings (2014 and 2016) enabling electronic voting for unions and Compensation Funds.
Continuous improvement
Every audit and every finding feeds back into the certified ISMS improvement cycle.