Operation Encrypt is a mail-ballot custody evidence service. It records what happened to the envelope — who held it, when, under whose signature — and it is engineered so that record survives the arrival of quantum computing. It never sees how anyone voted.
Just over three minutes, start to finish, with on-screen captions throughout: sign-up and verification, ballot issuance, the mail stream, receipt and acceptance, the privacy wall, the count, and the twenty-year archive — with the quantum readiness process running the whole way through, and a closing sequence showing all seven stages converging into one chain of evidence.
A voter opens the app and verifies who they are — once, cleanly, with the county as the authority. What comes back is a credential, not a dossier. Post-quantum signatures protect that enrollment from the very first second.
Every claim below is a boundary we hold ourselves to. Election officials should be able to check us against it.
Quantum-resistant protection is applied at each stage where custody evidence is signed, transported, or stored.
A voter proves identity once, in the app. What the system keeps is a credential, not a dossier — and it is signed with post-quantum protection from the first second.
Hybrid PQ signature
The county issues the ballot. Operation Encrypt binds a custody token to the envelope — never to the vote — and writes the issuance to an append-only ledger.
Append-only ledger
Induction into the mail stream, movement, arrival. Each scan becomes a sealed event, carried over quantum-safe key exchange so the record cannot be quietly rewritten in transit.
Quantum-safe transport
Receipt, signature review, acceptance. Human officials make the call; the service records the decision, the time, and the signer. The system records — it does not decide.
Officials decide
The hard privacy boundary. Two separation officers under dual control, a shuffle attestation, and a sealed sorted-token commitment. No key, no token, no join, no back door — protected with quantum-resistant signatures.
Dual control · shuffle attestation
Ballots are cast and counted on the county's certified system. Paper stays authoritative. Operation Encrypt contributes inclusion and consistency proofs and witness counter-signatures around the process.
Inclusion & consistency proofs
Evidence is exported and archived so an auditor arriving years later finds proofs already waiting — signed with conservative post-quantum algorithms chosen for a twenty-year horizon.
20-year archive
Every scan becomes a sealed, timestamped event, carried over quantum-safe key exchange — so a recording made today cannot be broken open a decade from now. The envelope moves. The vote is never in the record.
The strongest guarantee in Operation Encrypt is an absence. At separation, the envelope token and the vote token are severed. There is no key that reconnects them, no lookup table held in reserve, no administrative override.
What replaces the link is proof: two separation officers acting under dual control, a shuffle attestation showing the order was destroyed, and a sealed commitment to the sorted set of tokens that anyone can later check without learning a single vote.

Two officers under dual control. A shuffle attestation showing the order was destroyed. A sealed commitment to the sorted set of tokens that anyone can check later without learning a single vote. The wall holds for as long as the record exists.
Custody evidence has to remain checkable long after the election is over. That means the signatures, the transport, and the archive have to outlive today's cryptography. Our readiness program applies post-quantum protection at every point in the lifecycle where evidence is signed, moved, or stored.

| Where it applies | Approach |
|---|---|
| Custody event signatures | Hybrid signing — a classical signature paired with ML-DSA-65, so the evidence stands if either scheme is broken. |
| Transport between components | Hybrid key establishment using ML-KEM-768 together with X25519. |
| Long-horizon archive | Stateless hash-based signatures (SLH-DSA) chosen for conservatism over a twenty-year verification window. |
| Data at rest | AES-256 symmetric encryption, which remains appropriate under current post-quantum guidance. |
| Legacy parameter gate | Gate PQ-0: no group parameters below 3072-bit p / 256-bit q anywhere in the program. |
Custody records are kept for decades, which makes them an ideal target for an adversary willing to capture traffic now and decrypt it later. The archive is signed with stateless hash-based signatures chosen for conservatism, not speed.
The readiness program is written down, not implied. Each signed record carries a cryptographic suite identifier, so a verifier years from now can tell exactly how it was produced — and refuse anything it does not recognise rather than quietly waving it through.
bb2g-suite-2026.1
Ed25519 with SHA-256. Retained so historical records stay verifiable.
Legacy · verify onlybb2g-suite-2026.2
Ed25519 and ML-DSA-65 with SHA-256. Hybrid: both signatures must verify or the artifact fails.
Current signing defaultbb2g-suite-2027.1
ML-DSA-65 with SHA-384, post-quantum only, for when the classical half is no longer worth carrying.
Plannedbb2g-archive-2026.1
SLH-DSA-128s with SHA-256, for records that must remain checkable over a twenty-year horizon.
ArchiveNIST approved the first post-quantum standards — FIPS 203, 204 and 205 — in August 2024. A June 2026 Executive Order, Securing the Nation Against Advanced Cryptographic Attacks, sets deadlines of end-2030 for post-quantum key establishment and end-2031 for signatures. CISA, NSA and NIST direct organisations to begin with a cryptographic inventory. Election custody evidence, retained for decades, is exactly the category that cannot wait.
We did not select FIPS 206 / FN-DSA, which is still in development. We did not claim post-quantum protection for the homomorphic tally, which remains classical. And we did not remove the classical signature — hybrid signing is the hedge against a young algorithm failing.
Enrollment, issuance, transit, receipt, the separation wall, the count and the archive were designed as one system, not seven tools that happen to sit near each other. Post-quantum protection runs through every point where evidence is signed, moved or stored — converging into a single record that follows a ballot from the moment a voter signs up to the moment it is cast and counted.
We have run that full path end to end with the quantum protections switched on. The chain held. This is not a diagram — it is a tested path.
We do not ask a jurisdiction to change how it runs an election. We ask for permission to observe and record alongside it, then hand over evidence the office can check independently.
The pilot operates beside existing systems with no authority over any outcome. Nothing in the certified path changes.
A single county, a defined mail-ballot population, and an agreed set of custody events — not an enterprise rollout.
Exports are structured for independent review, with the export format aligned to NIST SP 1500-101 election data conventions.

We are seeking a jurisdiction willing to host a shadow pilot — no authority transferred, no certified system displaced, and a full evidence package at the end that your office owns. If that is a conversation worth having, we will bring the technical detail, the boundaries in writing, and the people who built it.