White paper · August 2026

Provable Custody

Why mail-ballot disputes cannot be settled with better recordkeeping, and what would settle them instead.

Prepared for election administrators, state election directors, and the officials who procure election technology. The text below is the paper as written; the tables are rendered from the same source.

Executive Summary

A mail ballot passes through eight to twelve custody transfers between the moment it is printed and the moment it is tabulated. At each transfer, the fact of the transfer is recorded — in an application log, on a paper form, in a spreadsheet, in a vendor's database. In nearly every jurisdiction, those records are accurate.

They are also, structurally, unverifiable by anyone outside the office that holds them. When a mail ballot batch is challenged, the election official's only available response is an assurance about their own records. That assurance is usually true and never sufficient, because it asks the challenger to accept the word of the party under challenge.

This paper argues that the resulting impasse is a property of the record format, not of the people keeping the records — and that it is fixable. Cryptographic custody techniques that are routine in financial audit, pharmaceutical manufacturing, and software supply chains produce a record that is append-only, independently anchored, and verifiable by a party who distrusts its author. Applied to mail ballot custody, they change what an election official is able to offer: not a better assurance, but evidence.

We also state plainly what this does not do. It does not reveal how anyone voted. It does not verify that a ballot was counted correctly. It does not establish that a ballot was legitimately cast. Each of those is a separate system with a separate audit, and conflating them is the most common way this technology is oversold.

1. The Custody Problem

1.1 The lifecycle nobody counts

Ask an election administrator how many times a mail ballot changes hands and most will answer four or five. The actual sequence, in a typical all-mail jurisdiction:

Print vendor receives the voter file extract and produces the ballot package

Package enters the postal stream outbound, acquiring an Intelligent Mail Barcode

USPS processes it through one or more facilities

The voter receives, marks, and returns it — by mail or to a drop box

USPS processes it inbound, or a two-person team retrieves the drop box

The election office receives and logs it

Signature verification

Sorting and batching

Extraction — the envelope and ballot are separated, permanently severing the link to the voter

Tabulation

Storage under federal and state retention requirements

Between eight and twelve custody transfers, depending on jurisdiction and drop-box handling. Each generates a record. Each record is held by the party that performed the transfer.

1.2 Why more diligence does not solve it

The instinctive response to custody doubt is procedural: more forms, more signatures, more two-person integrity, more video. These are good practices and jurisdictions that adopt them run better elections. They do not resolve the underlying problem, because every one of them produces another record held by the same party.

The constraint is logical, not operational. No quantity of self-held documentation can settle a dispute in which the holder is an interested party. A challenger who doubts the records is not going to be persuaded by more of them. This is why custody arguments recur cycle after cycle without resolution: both sides are behaving reasonably given a record format that cannot adjudicate between them.

1.3 An engineering failure, not a character failure

This distinction matters more than any technical content in this paper, and it should govern how the problem is discussed publicly.

Election officials are not failing at their jobs. In the overwhelming majority of cases the custody records are complete, contemporaneous, and correct. The failure is that the record format lacks a property — tamper-evidence verifiable by an outside party — which no amount of professional diligence can supply. Officials have been absorbing the reputational cost of a design gap in the tools they were given.

Correct and provably correct are different properties. Only one of them ends an argument.

2. What Other Fields Did About This

Election administration is not the first field to face an adversarial custody problem. Three others solved it structurally, and their solutions converge on the same architecture.

The problem

The structural solution

Forensic laboratories

Evidence integrity determines whether a case survives challenge in court

Sealed, signed, timestamped transfer records; independent verification at trial

Pharmaceutical manufacturing

A counterfeit or diverted drug must be detectable across a global supply chain

Serialized units with cryptographically verifiable custody events at every handoff

Financial audit

A ledger controlled by the audited party cannot audit that party

Append-only journals, external attestation, independent reconciliation

The common pattern: stop asking the custodian to be trusted, and give the custodian a way to be checked. In each field the change was initially resisted as an implication of bad faith and subsequently understood as protection for the honest participant — because it is the honest participant who currently has no way to demonstrate their honesty.

3. What Verifiable Custody Provides

3.1 The three properties

A custody record with evidentiary value has three properties beyond ordinary logging. Described here at the level of what they guarantee, not how they are constructed.

Append-only. Records may be added but not modified or deleted. A correction is a new record referencing the original — the same discipline a general ledger has used for six hundred years. Errors become visible and corrected rather than erased, which is a stronger position than an apparently clean record that cannot be distinguished from a scrubbed one.

Signed at the moment of the event. Each custody transfer is attributed to a specific role and key at the time it occurs, not reconstructed afterward. This establishes who recorded what, and when — and makes after-the-fact fabrication distinguishable from contemporaneous record-keeping.

Externally anchored. The system periodically publishes a short commitment to the entire record so far. Any subsequent alteration to any earlier record breaks that commitment visibly. This is the property that closes the trust gap: without it, an append-only log is still a log the operator controls.

3.2 What a voter actually receives

An inclusion proof is a short piece of data demonstrating that one specific record is part of a published set, without exposing the rest of the set. A voter checking their ballot receives a proof they can verify with an independent tool.

What it establishes: this specific custody event, for this specific ballot envelope, was part of the record the office published at that time, and that record has not been altered since.

3.3 What it does not establish — stated without hedging

Overclaiming here is the fastest way to destroy the trust this technology is meant to build. A voter told that verification means more than it does, who later learns otherwise, becomes a permanent adversary — and rightly so. The limits must be stated in the same breath as the capability.

It does not reveal how anyone voted. Custody is tracked at the envelope level and the link between voter and ballot is severed at extraction by design. Ballot secrecy is preserved.

It does not verify that a ballot was counted correctly. Tabulation is a separate system, audited separately — typically by a risk-limiting audit.

It does not establish that a ballot was legitimately cast. Voter eligibility and signature verification are separate processes with separate controls.

It does not prevent tampering. It makes tampering detectable. Nothing in this category is tamper-proof, and any vendor using that word should be asked what they mean by it.

4. Where This Sits in the Regulatory Landscape

4.1 Outside the voting system boundary — by design

VVSG 2.0 governs voting systems: equipment that marks, casts, or tabulates votes. A mail-ballot custody and provenance service does none of these. It is an election system, and VVSG 2.0 in fact requires that election systems be air-gapped from the voting system.

The practical consequence for a procuring jurisdiction: there is no EAC certification queue to wait behind. Custody infrastructure can be evaluated and deployed on a standard software procurement timeline while voting-system vendors work through multi-year recertification. The corresponding obligation is that with no federal certification to rely on, the jurisdiction's own technical evaluation has to be substantive. Section 7 of the companion curriculum provides a question bank for exactly this.

4.2 The compliance stack that does apply

What it covers

Status

SOC 2 Type II

Operating effectiveness of security controls over time

Readiness assessment underway

StateRAMP

Cloud authorization for state and local government

Path selection in progress

NIST SP 800-53 Rev. 5

Control catalog, Moderate baseline

Mapped

Independent penetration test

Adversarial validation by a third party

Scheduled

EI-ISAC

Sector threat intelligence and coordination

Membership planned

52 U.S.C. §20701

22-month federal retention of election records

Policy engine in development

FedRAMP is deliberately absent from this table. It authorizes cloud services sold to federal agencies and is not the applicable framework for county or state election infrastructure. Vendors citing it in this context are generally reusing federal proposal language.

4.3 The retention and privacy tension

Append-only systems retain by default. Public records law and privacy statutes may require redaction or deletion. These obligations genuinely conflict, and the resolution is architectural rather than procedural: the custody record — which contains no voter-identifying information after extraction — is retained and anchored, while personal data is held separately under its own governance and can be redacted without breaking any proof. Any jurisdiction evaluating a custody vendor should require a specific answer to this question.

5. Implementation State

Stated precisely, because vendors in this sector routinely describe roadmaps as if they were products.

Built and tested: the event log core — append-only storage with a relational backend, event signing, Merkle anchoring, role-based access control, managed key integration, offline scanner synchronization for facilities without connectivity, and envelope encryption for data at rest. The production entrypoint is designed to refuse to start rather than silently fall back to in-process keys, which is a deliberate choice to make misconfiguration loud rather than invisible.

In progress: 22-month retention policy engine, hardware security module vendor selection, SOC 2 Type II, StateRAMP path, third-party penetration test.

Not yet done: deployment in a live federal election. We are seeking two pilot jurisdictions for the 2027 cycle and will say so plainly rather than implying operational history we do not have.

6. Economics

Priced as recurring infrastructure rather than as a capital project, on a per-registered-voter annual subscription.

Included

Track

$0.20 – $0.30

Postal data ingestion, voter notifications, status portal, standard reporting

Custody

$0.40 – $0.55

Adds append-only event log, signed custody events, chain-of-custody reporting

Proof

$0.60 – $0.75

Adds external anchoring, per-ballot inclusion proofs, public verifier, audit support

A 150,000-voter county at the Custody tier is approximately $75,000 annually. A 2.5-million-voter jurisdiction at the Proof tier is approximately $1.75 million. Typical funding sources are HAVA funds, state election security grants, and county general fund.

7. What We Are Asking For

Two pilot jurisdictions for the 2027 cycle, at discounted pricing, in exchange for three things: permission to name the jurisdiction publicly, a written reference, and a joint presentation at a professional association conference.

We are looking for a customer who will let us be examined. A product whose entire premise is that claims should be checkable rather than trusted cannot reasonably ask to be adopted on trust. The right first customer is one who will subject this to scrutiny and publish what they find.

Kristen Hall, Founder · Born Between 2 Generals LLC · bornbetween2generals.com

This paper describes system properties and guarantees. It does not disclose cryptographic construction, key ceremony procedures, or implementation internals. Technical due diligence materials are available to evaluating jurisdictions under NDA.

Tables

§6 — Economics

TierPer voter / yrIncluded
Track$0.20 – $0.30IMb ingestion, voter notifications, status portal, standard reporting
Custody$0.40 – $0.55Above, plus append-only event log, signed custody events, chain-of-custody reporting
Proof$0.60 – $0.75Above, plus Merkle anchoring, per-ballot inclusion proofs, public verifier, adversarial audit support

Run this rate card against your own registered-voter count →

§4.2 — The compliance stack that applies

FrameworkWhat it coversStatus
SOC 2 Type IIOperating effectiveness of security controls over timeReadiness assessment underway
StateRAMPCloud authorization for state and local governmentPath selection in progress
NIST SP 800-53 Rev. 5Control catalog, Moderate baselineMapped
Independent penetration testAdversarial validation by a third partyScheduled
EI-ISACSector threat intelligence and coordinationMembership planned
52 U.S.C. §2070122-month federal retention of election recordsPolicy engine in development