Don't take our word
for the result.
RosterVote writes every meeting to a signed, sealed record. You don't have to trust us. You can recompute the result yourself from the exported record, in a browser, with nothing to install.
How you can check nothing was changed
Four ideas. The verifier walks you through the same four.
Every event is one entry
A ballot cast, a vote closed, a member checked in: each becomes its own entry in the meeting's record. Each entry carries a fingerprint (a hash) of its own contents.
RosterVote signs a seal
RosterVote signs a seal over the record each time a vote closes. That one signature stands for every entry sealed so far.
Any change shows in the root
Change any sealed entry and the seal covering it no longer matches its signature. A record changed and signed again gets a different root, which is why you compare the root with the one your organization published.
Anyone can recompute it
Export the recount bundle and anyone can check it: recompute every entry's fingerprint, rebuild every seal, and recount every tally from the raw ballots. None of it depends on what RosterVote's own servers say. The verifier checks each signature with the key in the bundle. To be sure the bundle is your organization's, compare its latest signed root with the one your organization published.
✓ 70 leaves verified · 4 signed roots · tallies recounted
Every voter gets a receipt
On any secret vote (a secret ballot, a single-winner ballot, a slate or an election), every voter gets a private tracking code and a receipt that confirms their ballot counted. It reveals nothing about how anyone else voted. A roll-call vote is recorded next to the voter's name instead. The record is signed and sealed when each vote closes, so anyone can recount the tallies and winners from the record, and compare them and the signed root with the published result.
Verify it yourself — two ways
No account and nothing to install. It never has to trust RosterVote's own servers.
The browser verifier
Drop a recount bundle into /verify. It recomputes every fingerprint, checks every seal and recounts every tally, right there in your browser. Nothing you load ever leaves your device. You can also download one self-contained copy that keeps working on your computer, with no server, for as long as you keep the file.
The command-line recount
recount.js runs the same check from the command line. It is a small script anyone can read, and it needs only Node. The browser page and recount.js share one verification file, so they can never disagree.
Try it on a real bundle
In any meeting, open the Records tab and use Recount bundle. It downloads the exact file both tools read. If a secret ballot, single-winner ballot, slate or election is still open with votes cast — including one laid on the table without being closed — the export waits until it closes. The ledger itself shows those ballots were cast without their choices, and no downloadable file carries that ballot's choices until it closes. Open the verifier and drop it in.
Common questions
Does verifying a result require installing anything?
No. Anyone can open the verifier in a browser, with no install and no account. It recomputes every fingerprint and every tally, and reproduces each decided vote's result straight from the exported record. It runs offline too.
What exactly does "verified" mean here?
The verifier's checks must all pass. Every entry's fingerprint matches its own contents. Every seal recomputes from the entries it covers. No seal number repeats, and no seal covers fewer entries than the one before it. Every entry is covered by a seal. Each decided vote's signed result matches its recount. The verifier checks each signature with the key in the bundle. To be sure the bundle is your organization's, compare its latest signed root with the one your organization published. Then check that the recomputed tallies match what was published. A bundle with no seal yet shows as "Not yet sealed." One with entries added since the last seal shows as "Not fully sealed." Neither is shown as verified.
What if verification fails?
The verifier names the check that failed: an entry that no longer matches its own recorded fingerprint, a seal whose entries no longer recompute to it, a seal whose signature does not verify, a seal that repeats the number of the one before it or covers fewer entries, or a vote whose signed result does not match its recount. It tells you not to trust the result until you contact the organization.
How does a voter know their own vote counted?
See "Every voter gets a receipt" above: a private tracking code and a receipt, or, on a roll-call vote, the record next to the voter's name.
See it work on a real result
Open the verifier, or talk to us about running your next meeting on RosterVote.