Draft — placeholder page
This page exists so the site structure is complete and navigable. The copy is a skeleton, not finished content: it has not been written, fact-checked against the product truth inventory, or reviewed. This page isnoindex and excluded from sitemap.xml until its entry is removed from DRAFT_PAGES insrc/site/config.mjs.
Security at BallotLink
For an inspector or management company doing diligence before they will consider the product — they search for this page by name, and its absence is disqualifying.
Planned sections
Each of these becomes an H2 with an answer block of 40 words or fewer directly beneath it, then the proof.
- Who can reach a ballot
- What is recorded when a ballot is opened
- When results come into existence
- Where data is stored
- How data is encrypted
- How authentication works
- Record retention
- Backups and disaster recovery
- How to report a vulnerability
Needed before this page can be written
- This page is drafted from the truth inventory (§3) and nothing else. Half its natural headings land in bucket C, which means Brandon answers them before a word is written.
- Encryption: TLS in transit is true at the edge; encryption at rest is unverified. Not claimable until checked.
- Authentication wording comes from Brandon directly — it is sensitive and must not be paraphrased.
- Retention: state the legal requirement, not a product guarantee. No formal retention policy is implemented.
- Backups are real and restore-verified, but described generically until Brandon approves specifics.
- Never on this page: certifications of any kind (none are held), “tamper evidence” as a named mechanism, MFA (designed, not built), or a contested-election reconstruction workflow. All bucket B.
- A security contact address for vulnerability reports — Brandon’s call.
Meanwhile
The pages that are written are the homepage, the guide forInspectors of Elections, and the one for election services companies.
