Run secure, anonymous and verifiable voting inside Decidim
Decidim Secure Elections adds anonymous, cryptographically secure voting to the Decidim your members already use. Ballots are sealed in the voter's browser, nobody can link a vote to a person, and anyone can check the result. Open source, and ready to install today.
The module Decidim recommends for votes that need real guarantees
In its 0.31 release notes, the Decidim team explained that its own elections component runs without a cryptographic layer, and that organizations needing stronger guarantees should look at the community module built on the Vocdoni protocol. That is the case for most binding votes run by cooperatives, municipalities, political parties, associations and federations, which have to satisfy national and regional regulation as well as their own statutes. Decidim Secure Elections is that module.
- Free software under AGPL-3.0
- Built for Decidim 0.33
- Maintained by Vocdoni
organizations already voting on Vocdoni infrastructure
- open source software
- e2e verifiable voting
- built for Decidim 0.33
Three guarantees Decidim cannot give a vote on its own
People propose, discuss and meet in Decidim. When a decision has to be anonymous, binding and defensible afterwards, using a voting module with cryptographic guarantees is the only solution.
Anonymity
With the Decidim Secure Elections module, each ballot is sealed in the voter's browser before it is sent. Nobody can link a vote to a person, not your administrators and not Vocdoni, and the count is produced from ballots that name nobody.
End-to-end verifiability
With the Decidim Secure Elections module, every voter gets a receipt code that proves their vote was recorded without revealing it, and anyone can recount from the published result and the export without trusting your installation.
Data protection by design
With the Decidim Secure Elections module, your Decidim stores no ballot and no census identity, and Vocdoni holds only hashed credentials that cannot be turned back into names, so a leak reveals nothing about how anyone voted.
What Decidim can guarantee, with and without Decidim Secure Elections
Decidim as it ships is built for participation, not for secret ballots: it cannot guarantee anonymity, it cannot let an outsider verify a count, and it keeps votes as personal data in your database. With the module, each of those becomes a guarantee you can point to.
The election runs on the Vocdoni voting protocol. Organizers work with it like any other Decidim component.
An administrator builds the election in minutes inside Decidim and publishes it. Votes are sealed in the member's browser, processed by the Vocdoni infrastructure, and counted where anyone can check the result. Nobody has to learn a second tool.
A census from Decidim verifications
Pull in the members who already hold a given verification in your instance, import a CSV, or add voters by hand. The census is frozen when the election is published.
Voting methods that fit the decision
Single option, multiple choice with selection limits, and one or several questions per election, built and reordered on one screen.
Results live, or sealed until the end
Per question. A sealed question cannot be counted by anyone, including us, until voting closes and the keys are published.
A second security layer when you want one
Voters identify themselves with the member fields you choose. Optionally, a one-time code by email or SMS adds a second layer before the ballot is cast.
A monitor for the electoral board
Status, turnout and per-question results as they come in, with the controls to pause, resume, end or cancel voting.
A receipt for every voter
Each vote returns a receipt code that links to the public explorer. Members can retrieve theirs later and confirm their vote was counted, without revealing it or being linked to it.
What is actually guaranteed, and who gets to know what
This is the part worth reading before anything else, and the part to forward to your data protection officer. These are not promises about our intentions. They are properties of where the code runs.
Your server never sees a ballot
Your Decidim holds one API key and performs only organiser operations: create the election, publish it, open or close a question, read the count. Votes are sealed in the voter's browser and processed by the Vocdoni infrastructure. Nothing about a vote passes through your server.
How the module delivers it
- Census check, key generation, sealing and sending the ballot all run in the browser
- No API key is ever sent to the browser
- No ballot, no choice and no voting key ever reaches your server, and no vote can be linked to a voter
Every voter can check their own vote, and reveal nothing
Each vote returns a receipt code with a link to the public explorer. It proves a vote was recorded. It does not reveal what was voted.
How the module delivers it
- Receipts can be retrieved later from the voting page, by identifying again
- Nothing is kept in a URL or a browser session
- A question sealed until the end waits for the keys to be published, and never falls back to counting in the open
The census is decided before voting opens, and by you
Voters are identified by the member fields you choose, optionally with a one-time code by email or SMS. Nothing can be added or changed once the election is published.
How the module delivers it
- Build it from the Decidim verifications members already hold, from a CSV with a template for exactly this election, or by hand
- Failed CSV rows are reported with their line and reason, and the rest still import
- Publication stops before anything reaches the network if a voter is missing a required field, and names who
Who knows what, in one line each
Data protection questions come down to who holds what. The answer is short because the design is.
How the module delivers it
- Your Decidim: the election configuration and a cached copy of the count. No census identity, no ballot.
- Vocdoni: hashed credentials that cannot be read back into names or IDs, and the sealed ballots. Never how anyone voted.
- The public network: sealed ballots and the count. No names, no readable choices, no link between a vote and a person.
Nothing rests on taking our word for it
The module is free software under AGPL-3.0-or-later, and the protocol it speaks to is public. Anyone can read the code and recount the result.
How the module delivers it
- Full source on GitHub, including the voting page shipped inside the module
- Results are queryable through Decidim's own API. Census configuration deliberately is not
- Elections already published are unaffected by an upgrade, because they live on the network
What you can hand an auditor or a challenger
The published election on the Vocdoni network, the per-question count readable independently of your instance, the CSV and JSON export with verification links, and every voter's own receipt. You can recount without trusting Vocdoni or your own installation, which is the point.
These are properties of the module and the protocol it uses. They are not a security review of your own deployment, your hosting or your census process, and they are not legal advice on whether a given vote satisfies your statutes.
For organizations on Decidim, and for the integrators who serve them
The module is free software either way. What we add is the accompaniment: the API keys for the Vocdoni infrastructure, help with the census, a rehearsal, and someone on the line the day the vote counts.
Install it on your instance, with us alongside
For cooperatives, federations, councils and associations that already run Decidim, with an IT provider or an integrator maintaining it.
- A short job for whoever already maintains your Decidim, and we accompany them
- A rehearsal election with test voters before the one that counts
- Support on voting day, and a result you can hand to anyone who asks
Offer verifiable voting to every client you serve
For the agencies and consultancies that implement and maintain Decidim for cooperatives, governments, associations and universities. You keep running the instances. We help you use the module.
- The API keys your clients' instances need to use the module with the Vocdoni infrastructure
- A named contact and an onboarding call for your team
- A rehearsal election before your client's first real vote
- Written partner terms, agreed in conversation
The things people ask before installing it
Including the ones with awkward answers.
Offer verifiable voting to your Decidim clients
If you implement or maintain Decidim for other organizations, talk with us. We accompany you through the module: the API keys for the Vocdoni infrastructure, the census, a rehearsal, and someone on the line during your client's first election.
Free software, no obligation. If your client's Decidim is not on 0.33 yet, we will tell you the realistic date.



