Trust & Security

Proof you can audit.

Every door is verified before it's paid for, and every record is handled like evidence. Here's exactly how the verification stack works — and how we secure your data.

The verification chain

How a door becomes a verified record.

No step is optional, and no step is self-reported by the canvasser alone. Each door carries a chain of custody from arrival to payment.

1

Identity, before the first shift

Canvassers are ID-verified before they can claim work. No anonymous workers enter a campaign.

ID-Verified
2

GPS geofence on arrival

When a canvasser opens a door, their device location is checked against a geofence around the target address. The arrival GPS is captured server-side — not trusted from a manual tap.

GPS-Confirmed
3

Dwell-time check

A real conversation takes time. The server measures time-on-site; visits that are out of the geofence or implausibly brief are automatically flagged as suspect.

Server-verified
4

Proof of visit

Optional photo proof, voice notes, and structured survey responses attach to the door — captured in the field, timestamped, and tied to the verified location.

Photo · Voice · Survey
5

Hold-and-review before pay

Anomalous or out-of-geofence submissions are held automatically and withheld from payment until reviewed. Fraud is caught before it enters your data — not after you've paid for it.

No confirmation, no payment
Security & data handling

Your data is handled like evidence.

What we collect serves verification and reporting — nothing more. We don't resell voter-level data.

🔒

Encrypted in transit & at rest

Traffic is served over HTTPS; campaign records are stored on managed, access-controlled infrastructure.

🛂

Role-based access

Campaign data is scoped to its owners. Administrative surfaces are gated by server-enforced roles, not client-side checks.

📊

Aggregate-first analytics

Cross-campaign intelligence is derived from aggregate signals. Individual voter records are never sold or shared as a product.

✍️

Consent-gated capture

Signature, ID, and contact capture are consent- and jurisdiction-gated, with the field set scoped to what the engagement actually requires.

🧾

Chain of custody

Every door carries its origin: who, where, when, and the proof attached — auditable end to end.

⏱️

Retention you control

Campaign data belongs to the campaign. Retention and export are scoped to your engagement.

We don't currently claim third-party security certifications. As the platform matures, formal audits (e.g. SOC 2, accessibility conformance) will be published here with their reports — not before they're real.

Why this holds up

The proof is the mechanism.

We don't publish metrics we can't audit. What we can show you is the chain itself — every door is verified at the source, so the data you receive is trustworthy before it ever reaches your dashboard.

📍

Verified at the source

GPS geofence and dwell on every door, captured server-side — not self-reported by the canvasser.

Held before pay

Anomalous or out-of-geofence submissions are withheld automatically. Fraud never enters your data.

🧾

Auditable end to end

Every record carries its origin — who, where, when, and the proof attached.

See the verification, not just the pitch.

Walk a verified door from arrival to audited record. Then decide.

Start a campaign Talk to us