Security in electronic voting Ethical Hacking and External Audits

Periodic penetration tests by independent experts and verifiable records that enable full audits without compromising voter anonymity.

  • ISO 27001
  • Legal & technical validity
  • Results in minutes
  • Live support

Security is tested, not just declared

The best security controls are those that have been tested by adversaries. EVoting subjects its platform to penetration tests conducted by independent experts, complemented by external audits that verify system integrity without compromising the votes.

Periodic penetration testing (pentesting)

Offensive security experts actively seek vulnerabilities in the platform, simulating real attacks.

  • Independence: tests are carried out by specialised external companies with no conflict of interest with EVoting.
  • Full scope: the web application, APIs, infrastructure and authentication mechanisms are all evaluated.
  • Documented mitigation: all detected vulnerabilities are corrected and verified before each electoral process.

Types of tests

  • Injection & OWASP Top 10
  • Privilege escalation
  • Authentication attacks
  • Social engineering

Verifiable records and external auditing

The system generates cryptographically verifiable records that allow the integrity of the process to be checked without revealing individual preferences.

  • Auditable logs: every system action is recorded with a cryptographic integrity seal, enabling detection of any subsequent manipulation.
  • Designated external auditor: the organisation can appoint an independent auditor to verify the process in real time.
  • Transparency without breaking secrecy: the audit verifies that votes were counted correctly without accessing individual preferences.

Periodic pentesting

Penetration tests conducted before each election season by external experts.

Mitigated vulnerabilities

Every finding is corrected and verified before the platform goes into production.

Intact records

Every action is recorded with a cryptographic seal; any subsequent alteration is detectable.

Independent auditor

The organisation can appoint an external auditor to verify the process in real time.

Need a process with external auditing?