Operation Encrypt · Born Between 2 Generals

Evidence for every stepa ballot takes.

Operation Encrypt is a mail-ballot custody evidence service. It records what happened to the envelope — who held it, when, under whose signature — and it is engineered so that record survives the arrival of quantum computing. It never sees how anyone voted.

Custody · envelope, never the vote
Privacy · hard wall at separation
Quantum · hybrid post-quantum signatures
Authority · paper and officials
The presentation film

Welcome, future innovators of elections
and protectors of the Constitution.

Just over three minutes, start to finish, with on-screen captions throughout: sign-up and verification, ballot issuance, the mail stream, receipt and acceptance, the privacy wall, the count, and the twenty-year archive — with the quantum readiness process running the whole way through, and a closing sequence showing all seven stages converging into one chain of evidence.

Runtime 3:13 · Narrated and captioned · Born Between 2 Generals, Election Command Scenes are illustrative reconstructions, not footage of a live election.
Stage I · Enrollment

It begins beforea single ballot moves.

A voter opens the app and verifies who they are — once, cleanly, with the county as the authority. What comes back is a credential, not a dossier. Post-quantum signatures protect that enrollment from the very first second.

OnceVerified in the app
CountyRemains the authority
CredentialNot a dossier
Stated out loud

What this is — and what it is not.

Every claim below is a boundary we hold ourselves to. Election officials should be able to check us against it.

What Operation Encrypt does

  • Issues a custody token bound to the ballot envelope
  • Records induction, transit, arrival, and acceptance as signed events
  • Writes those events to an append-only ledger with inclusion and consistency proofs
  • Enforces dual control and a shuffle attestation at separation
  • Publishes a sealed, sorted-token commitment officials and observers can verify
  • Preserves an evidence archive designed to be checkable for twenty years

What it does not do

  • It does not mark a ballot
  • It does not tabulate votes
  • It does not decide voter eligibility — officials do
  • It does not replace the county's certified voting system
  • It does not link an envelope token to a vote token; that join does not exist
  • It is not an EAC-certified voting system and is not offered as one
The system records. It does not decide. Paper remains authoritative, and human election officials remain the authority on every judgment call.
The lifecycle

Seven stages. One unbroken chain of evidence.

Quantum-resistant protection is applied at each stage where custody evidence is signed, transported, or stored.

I

Verify

A voter proves identity once, in the app. What the system keeps is a credential, not a dossier — and it is signed with post-quantum protection from the first second.

Hybrid PQ signature
A voter completing identity verification in the app
II

Issue

The county issues the ballot. Operation Encrypt binds a custody token to the envelope — never to the vote — and writes the issuance to an append-only ledger.

Append-only ledger
A ballot envelope scanned under a laser line
III

Transit

Induction into the mail stream, movement, arrival. Each scan becomes a sealed event, carried over quantum-safe key exchange so the record cannot be quietly rewritten in transit.

Quantum-safe transport
Ballot envelopes moving along a postal sorting conveyor
IV

Receive

Receipt, signature review, acceptance. Human officials make the call; the service records the decision, the time, and the signer. The system records — it does not decide.

Officials decide
Election officials conducting signature review
V

Separate

The hard privacy boundary. Two separation officers under dual control, a shuffle attestation, and a sealed sorted-token commitment. No key, no token, no join, no back door — protected with quantum-resistant signatures.

Dual control · shuffle attestation
Two officials breaking a seal under dual control
VI

Count

Ballots are cast and counted on the county's certified system. Paper stays authoritative. Operation Encrypt contributes inclusion and consistency proofs and witness counter-signatures around the process.

Inclusion & consistency proofs
Ballot stacks beside a certified scanner with observers present
VII

Audit

Evidence is exported and archived so an auditor arriving years later finds proofs already waiting — signed with conservative post-quantum algorithms chosen for a twenty-year horizon.

20-year archive
An archive corridor of sealed evidence boxes
Stage III · The mail stream

Induction. Transit.Arrival.

Every scan becomes a sealed, timestamped event, carried over quantum-safe key exchange — so a recording made today cannot be broken open a decade from now. The envelope moves. The vote is never in the record.

SealedEvery scan event
ML-KEM-768Hybrid key exchange
Append-onlyNo quiet rewrites
The privacy wall

The join does not exist.

The strongest guarantee in Operation Encrypt is an absence. At separation, the envelope token and the vote token are severed. There is no key that reconnects them, no lookup table held in reserve, no administrative override.

What replaces the link is proof: two separation officers acting under dual control, a shuffle attestation showing the order was destroyed, and a sealed commitment to the sorted set of tokens that anyone can later check without learning a single vote.

A stream of particles meeting a wall of light
Stage V · Separation

The joindoes not exist.

Two officers under dual control. A shuffle attestation showing the order was destroyed. A sealed commitment to the sorted set of tokens that anyone can check later without learning a single vote. The wall holds for as long as the record exists.

Dual controlTwo officers, always
No keyNothing reconnects it
No overrideNot even for us
The quantum readiness process

Built for the machine that hasn't arrived yet.

Custody evidence has to remain checkable long after the election is over. That means the signatures, the transport, and the archive have to outlive today's cryptography. Our readiness program applies post-quantum protection at every point in the lifecycle where evidence is signed, moved, or stored.

A crystalline lattice structure
Where it appliesApproach
Custody event signatures Hybrid signing — a classical signature paired with ML-DSA-65, so the evidence stands if either scheme is broken.
Transport between components Hybrid key establishment using ML-KEM-768 together with X25519.
Long-horizon archive Stateless hash-based signatures (SLH-DSA) chosen for conservatism over a twenty-year verification window.
Data at rest AES-256 symmetric encryption, which remains appropriate under current post-quantum guidance.
Legacy parameter gate Gate PQ-0: no group parameters below 3072-bit p / 256-bit q anywhere in the program.
An honest limit. Homomorphic tallying and verifiable decryption remain classical in this design. We label that plainly rather than implying end-to-end quantum resistance where it does not yet exist. Post-quantum protection here covers custody evidence signatures, transport, and archive.
Stage VII · The archive

Built to outlivethe machines that will one day try to break it.

Custody records are kept for decades, which makes them an ideal target for an adversary willing to capture traffic now and decrypt it later. The archive is signed with stateless hash-based signatures chosen for conservatism, not speed.

SLH-DSAHash-based archive signing
20 yearsVerification window
Harvest-nowThe threat we design against
The encryption specification

Every artifact says which cryptography made it.

The readiness program is written down, not implied. Each signed record carries a cryptographic suite identifier, so a verifier years from now can tell exactly how it was produced — and refuse anything it does not recognise rather than quietly waving it through.

bb2g-suite-2026.1

Ed25519 with SHA-256. Retained so historical records stay verifiable.

Legacy · verify only
bb2g-suite-2026.2

Ed25519 and ML-DSA-65 with SHA-256. Hybrid: both signatures must verify or the artifact fails.

Current signing default
bb2g-suite-2027.1

ML-DSA-65 with SHA-384, post-quantum only, for when the classical half is no longer worth carrying.

Planned
bb2g-archive-2026.1

SLH-DSA-128s with SHA-256, for records that must remain checkable over a twenty-year horizon.

Archive

The gates a build has to pass

Why now

NIST approved the first post-quantum standards — FIPS 203, 204 and 205 — in August 2024. A June 2026 Executive Order, Securing the Nation Against Advanced Cryptographic Attacks, sets deadlines of end-2030 for post-quantum key establishment and end-2031 for signatures. CISA, NSA and NIST direct organisations to begin with a cryptographic inventory. Election custody evidence, retained for decades, is exactly the category that cannot wait.

What we deliberately did not do

We did not select FIPS 206 / FN-DSA, which is still in development. We did not claim post-quantum protection for the homomorphic tally, which remains classical. And we did not remove the classical signature — hybrid signing is the hedge against a young algorithm failing.

Status. The quantum readiness document is a specification held under BB2G design authority. It is not a certification, not an EAC-certified system, and not a claim that any component has been formally evaluated. Where it is implemented, it protects custody evidence signatures, transport and archive — not the tally.
One system

Seven stages.One chain of evidence.

Enrollment, issuance, transit, receipt, the separation wall, the count and the archive were designed as one system, not seven tools that happen to sit near each other. Post-quantum protection runs through every point where evidence is signed, moved or stored — converging into a single record that follows a ballot from the moment a voter signs up to the moment it is cast and counted.

We have run that full path end to end with the quantum protections switched on. The chain held. This is not a diagram — it is a tested path.

7 → 1Stages into one chain
End to endSignup through count
TestedWith quantum on
The pilot model

One county first. Beside the existing system, never in front of it.

We do not ask a jurisdiction to change how it runs an election. We ask for permission to observe and record alongside it, then hand over evidence the office can check independently.

01 — Shadow

Runs in parallel

The pilot operates beside existing systems with no authority over any outcome. Nothing in the certified path changes.

02 — Scoped

A defined slice

A single county, a defined mail-ballot population, and an agreed set of custody events — not an enterprise rollout.

03 — Checkable

Evidence you can verify

Exports are structured for independent review, with the export format aligned to NIST SP 1500-101 election data conventions.

For jurisdiction decision-makers

Start with one county. Then a nation.

We are seeking a jurisdiction willing to host a shadow pilot — no authority transferred, no certified system displaced, and a full evidence package at the end that your office owns. If that is a conversation worth having, we will bring the technical detail, the boundaries in writing, and the people who built it.