23 lines
1.2 KiB
Markdown
23 lines
1.2 KiB
Markdown
# GovOPlaN Voting
|
|
|
|
`govoplan-voting` owns governed ballot definitions, frozen electorate
|
|
snapshots, ballot casting and replacement, deterministic tallying, result
|
|
certification, challenges, annulment, and provider evidence.
|
|
|
|
The native `recorded` assurance profile is auditable but not secret: active
|
|
ballots are stored so that a result can be reconstructed. Confidential,
|
|
secret, and externally certified profiles fail closed unless an explicit
|
|
`voting.provider.<provider>` capability is installed. Providers return only
|
|
aggregate results and evidence through the public Voting boundary. The bundled
|
|
`local_confidential` provider stores cast selections only as Encryption-owned
|
|
server-envelope ciphertext in provider-specific shared SQL tables. It is
|
|
confidential at rest, but it is not anonymous, secret, coercion-resistant, or
|
|
externally certified.
|
|
|
|
Committee and other modules retain their deliberation or business context and
|
|
refer to Voting ballots through the `voting.ballots` capability. Informal
|
|
preference and availability collection remains in `govoplan-poll`.
|
|
|
|
See [the domain and assurance boundary](docs/VOTING_DOMAIN.md) for operations,
|
|
security, recovery, and integration details.
|