← All gaps
🔌 Physical & network security

Chain-of-custody nobody can see

Voting equipment should have a clear, public record of who touched it and when. When those custody records aren't open, someone can get unauthorized access — and it can go unnoticed for a long time.

Explainer video coming soon

A 60-second, plain-language walkthrough of this gap.

What actually happened

On January 7, 2021, in Coffee County, Georgia, outsiders were given access to the county's voting equipment and copied — in the words of those involved — virtually every component of the system, including ballot images and voting-equipment software, which later spread online. It was not caught in real time; it surfaced months later through litigation, and criminal charges followed. A public, tamper-evident custody record is what makes that kind of access impossible to hide.

Where it stands today

The gap is current: many jurisdictions still don't publish chain-of-custody records, so access has to be discovered after the fact rather than seen as it happens. The figure above reflects today's law.

A record of every hand

A voting machine passes through many hands — storage, transport, setup, maintenance. A chain of custody is the record of who had access and when. When that record is public and tamper-evident, an unexpected access is obvious. When it isn't, the access can simply go unseen.

What it looks like when it breaks

In Coffee County, Georgia, on January 7, 2021, outsiders were given access to the county's voting equipment and copied virtually every component — ballot images, equipment software — which later spread online. It wasn't caught as it happened; it surfaced months later through litigation, and criminal charges followed.

How TrustVoting closes it

Custody and device-event records are signed and published, so every access to a machine is logged and publicly visible. An unauthorized touch shows up right away — not months later in a lawsuit.

How TrustVoting closes it

TrustVoting signs and publishes custody and device-event records, so every access to a machine is logged and publicly visible — an unauthorized touch shows up immediately, not months later.