The technology to run a provably correct, end-to-end verifiable election already exists, and it's running today. What's missing is a path through the institutions that actually run American elections. This is that path.
Confidence in an election doesn't come from being told to trust it — it comes from being able to check it yourself. The mathematics for a provably correct, end-to-end verifiable election already exist and already work outside a lab. What has never existed is a way through the thousands of separate authorities who would have to say yes before any of it touches a binding public election. Anyone who claims American elections can be fixed with software alone has misread which part of the problem is actually hard.
There is no universal federal voter credential to build on. Creating one — deciding who issues it, who's eligible, how it's revoked, how privacy is protected — is a political fight measured in decades, not a technical task. A strategy that waits for it will wait a very long time.
US elections are administered by the states and run day to day by thousands of local jurisdictions, each with its own equipment, rules, procurement process, and certification path. There is no single yes that makes a system national.
Voting-system certification is slow and expensive by design — that's not bureaucratic drag, it's the safeguard that keeps untested systems out of binding elections. A serious strategy works with that cycle, not around it.
Any change to a binding public election invites a legal challenge, and it should — the stakes are too high for anything less. A system that can't survive a courtroom under pressure isn't a real system yet. It's a demo.
Authority moves from published, reproducible audits — not from lobbying, and not from a mandate.
Unions, professional associations, party caucuses, cooperatives, boards, and student governments already control their own membership rolls and their own rules. That's what makes them the right place to start: a binding verifiable election can run in weeks, not years, because there's no larger jurisdiction to negotiate with first.
A completed, binding election with a published audit that independent observers — not just the organization that ran it — were able to reproduce.
Non-binding public pilots run in parallel to a paper-governed election, alongside small municipal races in jurisdictions that choose to opt in. Nothing here is asked to replace a certified result — the goal is a track record, run in public, under real conditions.
Multiple clean audits across different kinds of jurisdictions, plus at least one adversarial review — an outside team trying deliberately to break the result — that failed.
States, not Congress, are where election authority actually sits — a single state can choose to move without waiting on federal action. This phase means meeting that state's own certification requirements and fitting cleanly into the risk-limiting-audit practice it already uses.
Certification in at least one state, and a track record that has survived a contested election — not just a quiet one.
This is not a federal mandate and not a single national system. It's a capability — proven, certified, open, and independently audited — that any jurisdiction can choose to adopt, on its own timeline, the way jurisdictions already choose their own equipment and vendors today.
Enough independent deployments, in enough different places, that adopting it is a procurement decision — not an act of faith.
The direction of travel is set by what gets published and reproduced, not by who lobbies hardest for the next phase.
A voter-verified paper record stays authoritative at every stage. Verification is added on top of it; it never replaces the count.
Every deployment, at every phase, is audited against its paper record to a stated confidence level. No exceptions for scale.
The full election record is published so any third party — not just an approved observer — can independently reproduce the result. Verifiability is the product.
The system stores exactly one bit per voter: eligible, yes or no. It is not a person-finder, a status database, or a purge tool — and those capabilities are left out by the cryptography itself, not kept out by policy that could later change.
A cryptographer audits the protocol. Election-law counsel reviews enrollment tiers, due process, and the law of whatever jurisdiction is involved. Neither step is done by the people who built the system.
The math and the paper trail don't take a side. A system only its winners are willing to defend has already failed at the one job it has.
Internet voting as a replacement for paper. Every design in this plan keeps a voter-verified paper record as the authority. Nothing here proposes voting by app instead of by ballot.
A national identity system. This does not require, and does not build toward, a universal ID. Each organization or jurisdiction verifies eligibility against its own existing roll.
A federal mandate. No phase of this depends on Congress requiring anyone to adopt anything. Adoption is a choice, made one jurisdiction at a time.
Replacing election officials. Verification is a tool for the people already running elections, not a system meant to work around them.
A claim that this stops all fraud. No system stops every bad act by every person. What this delivers is confidence anyone can verify — not a guarantee that requires taking anyone's word for it, including ours.
Deepfakes and off-camera coercion are not solved problems. Re-voting before close is a genuine mitigation — a coerced or sold vote can be quietly undone — but it is a mitigation, not a cure.
This is the standing hard problem of any remote voting system, not something unique to this one. Encryption on the device doesn't help if the device itself is lying about what it's encrypting.
What holds up in an organization of a few hundred members doesn't automatically hold at the scale, and under the adversarial pressure, of a large public electorate. Each phase has to prove that for itself.
Federalism and certification cycles are not obstacles to route around with better marketing. This plan could take longer than a single election cycle, or several.
These are named here first, not buried in an appendix, because a plan that hides its own weaknesses isn't one you should trust more — it's one you should trust less.
A complete, working, end-to-end verifiable election system exists right now and can be tested in a browser — no signup, nothing to install.
Open the live demonstration →Phase 1 begins with a single binding election inside one organization. That first pilot is currently being scoped.
Read the pilot proposal →Nothing described in this plan has been deployed in a binding public election. Phase 1 is where that begins — one organization, one race, one published audit at a time.
This is a multi-year, institution-by-institution plan. It moves at the speed of the people willing to run the first pilot, fund the first audits, and ask the first honest questions.
Host a Phase 1 pilot — a board seat, an officer race, or a bylaw vote — and own the first published audit.
Underwrite the audits. Each phase is unlocked by a published, reproducible audit report — that's the actual cost of moving this plan forward.
Ask what a Phase 2 parallel pilot would require in your jurisdiction. That conversation doesn't commit you to anything binding.
Kristen Hall · Born Between 2 Generals LLC · kristen@bornbetween2generals.com