YOU DON’T GET TO CERTIFY YOURSELF ANYMORE
If political authority comes from counted votes, the evidence establishing that authority must survive the authority claiming the count.
YOU DON’T GET TO CERTIFY YOURSELF ANYMORE
If political authority comes from counted votes, the evidence establishing that authority must survive the authority claiming the count.
I am done arguing about whether you should trust elections.
That is the wrong argument.
Republicans say one thing.
Democrats say another.
Election officials tell you the process is secure.
Candidates tell you it was rigged.
Television networks call races.
Courts hear specific disputes.
Fact-checkers grade claims.
Millions of citizens stare at all of them and are somehow expected to determine which authority they should trust.
I have a simpler question.
Why are we still asking anyone to trust anyone?
It is 2026.
We have cryptography.
We have digital signatures.
We have deterministic verification.
We have append-only history.
We have portable artifacts.
We have independent hashing.
We have offline verification.
We have systems capable of preserving evidence separately from the server displaying it.
And the transfer of sovereign political authority is still discussed as though the final primitive is:
Trust us. We counted it.
No.
You do not get to certify yourself anymore.
I AM NOT SAYING EVERY ELECTION WAS RIGGED
Read this carefully, because this is where people will try to escape the argument.
I am not claiming that the absence of independently verifiable evidence proves an election was manipulated.
It does not.
Lack of proof of fraud is not proof of fraud.
But the reverse matters just as much:
An institution declaring that its own process worked is not independent proof that its process worked.
Those are two completely different propositions.
I do not need to prove that every previous election was rigged to establish that the evidentiary architecture can be improved.
The institution claiming lawful authority carries the burden of establishing the count from which that authority was derived.
Not because I dislike the winner.
Not because I like the loser.
Because power requires proof.
The greater the authority being claimed, the stronger the proof should be.
And there may be no greater recurring transfer of public authority than an election.
THE GOVERNMENT ALREADY ADMITS THE PRINCIPLE
This is not some strange theory I invented in opposition to election-security experts.
The government’s own standards are walking directly toward the same conclusion.
The U.S. Election Assistance Commission’s current VVSG 2.0 framework embraces software independence: an undetected software failure should not be capable of creating an undetectable change in the election result.
Under VVSG 2.0, software-independent voting systems must either produce voter-verifiable paper records or use an approved cryptographic end-to-end verifiable protocol. (U.S. Election Assistance Commission)
Read that again.
The federal standard-setting body already recognizes the principle:
the software reporting reality cannot be the sole authority for reality.
That is the argument.
NIST describes end-to-end verifiable election systems as a way to provide the public with direct evidence about the integrity of election systems and outcomes. (NIST)
Again:
direct evidence.
Not institutional reputation.
Not a television graphic.
Not “our experts checked.”
Evidence.
The EAC unanimously adopted a policy in 2025 supporting paper-based, auditable, software-independent voting systems. (U.S. Election Assistance Commission)
And yet, as of 2026, America still does not have one national post-election auditing standard. Different states use different combinations of procedural audits, traditional audits, risk-limiting audits and other methods, while the EAC is still developing voluntary national audit standards. (U.S. Election Assistance Commission)
Even adoption of VVSG 2.0 itself is generally voluntary unless state law makes it mandatory, and jurisdictions may still operate systems certified under older VVSG standards. (U.S. Election Assistance Commission)
So we already know the destination.
We simply have not completed the architecture.
RETAINING EVIDENCE IS NOT THE SAME AS PROVING THE RESULT
Federal law already recognizes that election records matter.
For covered federal elections, 52 U.S.C. § 20701 requires election officers to preserve relevant election records and papers for twenty-two months. (U.S. Code)
Good.
Keep them.
But preservation is not the same thing as verification.
A document existing somewhere does not automatically establish:
that these are the exact original records;
that none disappeared;
that none were silently substituted;
what happened to them between custody events;
whether every accepted transition was authorized;
whether the tabulation was derived from the preserved source;
whether another independent party can reproduce the conclusion;
or whether the evidence remains verifiable when the system that created it is unavailable.
That is the difference between having records and having a proof system.
I spent years solving that distinction in another domain.
Then I realized something obvious.
The architecture does not care whether the object represents a post, an asset, ownership, money, identity or a public election event.
The law underneath it is the same:
representation must remain subordinate to source.
I ALREADY BUILT THE MISSING PRIMITIVES
This is where the conversation changes.
Receiz does not begin by asking a server what happened.
It begins with the artifact.
The implemented Receiz proof law says verification begins from the artifact, manifest, proof bundle, verified append or admitted local register—not from a database row, interface, server response or model memory.
A sealed artifact carries its own integrity relationship, signature, claim, provenance and payload binding.
The saved bytes can be independently hashed.
The enclosing artifact can be verified before its payload is trusted.
History is not rewritten.
New truth is appended.
A different application can verify the same underlying object without the application that created it becoming the authority.
And production verification explicitly requires a local verifier and zero network calls during verification.
The offline verifier goes further:
artifact truth does not require the server, database, session or marketplace to answer first.
That matters enormously.
Because if an election result is ultimately true only because a particular server says it is true, then the server has accidentally become sovereign.
It should not be.
The evidence should outrank the machine reporting the evidence.
That is Receiz.
NOW APPLY THE LAW TO ELECTIONS
Do not misunderstand what I am proposing.
You cannot simply attach someone’s identity to their vote.
That would destroy the secret ballot.
Election systems must preserve ballot secrecy, and existing federal voting-system principles specifically reject creating a link between an identifiable voter and that voter’s selections. (NIST)
So a proof-native election requires separation of concerns.
PROVE ELIGIBILITY.
Establish that a lawful voter was entitled to receive exactly the ballot available to them.
PROVE CONSUMPTION.
Establish that the eligibility right resulted in no more than the lawful number of accepted ballots.
DO NOT LINK IDENTITY TO CHOICE.
Once eligibility is established, the ballot-choice record must not reveal which identifiable person cast it.
SEAL THE CAST RECORD.
The accepted ballot representation must have independently verifiable integrity.
PRESERVE EVERY LAWFUL TRANSITION.
Creation.
Issuance.
Cast.
Custody.
Transfer.
Tabulation.
Reconciliation.
Audit.
Certification.
Not mutable database history.
Authenticated append-only evidence.
DETECT DIVERGENCE.
Two incompatible histories cannot silently become one accepted history because a database administrator decided which row wins.
Conflict must become visible.
VERIFY WITHOUT THE SERVER.
A competent independent verifier should be able to examine the relevant public or authorized evidence without asking the election vendor’s production database to tell it whether that evidence is valid.
REPRODUCE THE RESULT.
The certification should be a projection derived from the evidence.
Not the other way around.
That is the architecture.
THE BALLOT IS SOURCE. THE RESULT PAGE IS A PROJECTION.
This one distinction changes everything.
Today people stare at election-result webpages.
Candidate A: 51.2%.
Candidate B: 48.1%.
99% reporting.
Called.
Certified.
Those are representations.
They are not the underlying event.
They are projections from ballots, cast-vote records, custody processes, tabulations, reconciliations and audits.
So the proper hierarchy is:
SOURCE
Ballots and valid election evidence.
↓
PROOF
Integrity, custody, accepted transitions, reconciliation and audit.
↓
DERIVED STATE
Tabulation.
↓
PROJECTION
The result shown on television, a website or an official certification document.
The projection cannot outrank its source.
That rule is so obvious everywhere else that it is astonishing we debate it here.
If the website disagrees with the evidence, rebuild the website.
If the database disagrees with the evidence, rebuild the database.
If the tabulation disagrees with the evidence, rerun the tabulation.
You do not modify the source to protect the projection.
THE STATE DOES NOT GET A SPECIAL EXEMPTION FROM PROOF
This is where I refuse the old argument completely.
If I tell you I own something, prove it.
If a bank says I owe money, show the ledger.
If a company claims revenue, show the books.
If a scientist reports a result, show the experiment.
If a cryptographic system claims an object is authentic, verify the signature.
But somehow when an institution claims the lawful authority to govern hundreds of millions of people, people become offended by the question:
Can I verify the evidence?
Why would sovereignty receive a lower evidentiary standard than an asset?
Why would political power require less provenance than a digital file?
Why should the most consequential collective decision we make depend more heavily on institutional trust than systems handling far less consequential facts?
It should not.
“WE AUDITED IT” IS NOT THE FINAL STANDARD EITHER
Audits matter.
Risk-limiting audits are especially important because they use voter-verifiable records and statistical methods to provide assurance about reported outcomes. (NIST)
But even an audit is still an operation performed over evidence.
So the next question remains:
What proves the audit?
Which records were sampled?
From what source set?
Who possessed them?
What was the pre-audit state?
What changed?
What discrepancy was found?
What procedure resolved it?
What was the resulting state?
Was the exact evidence retained?
Can another permitted observer reproduce the conclusion?
This is not paranoia.
This is engineering.
Every important operation should leave evidence sufficient to establish what happened.
STOP ASKING PEOPLE TO TRUST DEMOCRACY
That sentence has always bothered me.
Trust democracy.
Why?
Democracy should be designed so that I need to trust it less.
That is the entire point of checks and balances.
We do not tell one branch of government:
“We trust you. Police yourself.”
We divide authority precisely because concentrated trust is dangerous.
The same principle belongs inside election architecture.
Do not tell the citizen:
Trust the machine.
Do not tell the citizen:
Trust the vendor.
Do not tell the citizen:
Trust the county.
Do not tell the citizen:
Trust the secretary of state.
Do not tell the citizen:
Trust your party.
Do not tell the citizen:
Trust the court.
Give every appropriate verifier enough independent evidence that the important claims do not depend on any one of them being trusted.
That is stronger democracy.
Not weaker democracy.
AND NO, THE VOTER SHOULD NOT RECEIVE PROOF OF WHO THEY VOTED FOR
Proof without privacy would create another disaster.
A voter must not walk away with a transferable receipt that proves to an employer, spouse, political machine or vote buyer exactly whom they selected.
Older NIST/EAC testing requirements make this principle explicit: a voting system should not issue a receipt capable of proving how a voter voted. (NIST)
So the objective is not:
Here is cryptographic evidence that BJ voted for Candidate X.
Absolutely not.
It is:
Here is sufficient evidence to establish that an eligible voting right was lawfully exercised, that an accepted ballot entered the election state, that accepted ballots were not silently mutated, added or removed, and that the published aggregate result was correctly derived—without linking a specific human identity to a specific ballot choice.
That is a real engineering problem.
It is also solvable enough that the EAC now has an explicit process for evaluating cryptographic end-to-end voting protocols. (U.S. Election Assistance Commission)
The question is no longer whether verification belongs in elections.
The government already conceded that.
The question is how far we are willing to take it.
HERE IS MY STANDARD
I am putting it in public now.
No election system should be considered proof-native unless it can establish, at minimum:
Eligibility integrity — only lawful voting rights enter the process.
Ballot secrecy — voter identity cannot be reconstructed from ballot selections.
Cast integrity — accepted ballot evidence cannot be silently altered.
Exclusivity — the system detects duplicate, conflicting or otherwise unlawful state transitions.
Append-only custody — material history is preserved rather than overwritten.
Independent verification — evidence can be checked independently of the authority making the claim.
Offline survivability — verification does not disappear because a vendor, API, database or network disappears.
Deterministic reconciliation — conflicting histories are exposed and resolved according to public rules.
Reproducible tabulation — the reported result can be derived again from the accepted evidence.
Auditable certification — certification itself produces evidence establishing what was certified and from which state.
Open verifier law — the verification rules are inspectable enough that independent implementations can test the same evidence.
No authority by assertion — no server, database, user interface, vendor, model, official or institution becomes truth merely by claiming it is authoritative.
That is the bar.
Meet it.
Or explain why sovereign power deserves something weaker.
DO YOU HAVE TO USE RECEIZ?
Now I will remove the easiest technical escape hatch myself.
Under current American law, an election does not become legally invalid merely because it did not use Receiz.
Congress has not written:
“Thou shalt use BJ Klock’s protocol.”
I am not pretending it has.
That would be a stupid argument.
My argument is more dangerous than that.
The architecture now exists.
The primitives now exist.
The distinction between source and projection is demonstrable.
Offline verification is demonstrable.
Portable proof is demonstrable.
Append-only continuity is demonstrable.
Artifact-derived authority is demonstrable.
So from this point forward, the question changes.
You do not necessarily have to use my company.
You do not necessarily have to use my interface.
You do not necessarily even have to use my implementation.
But if you reject the properties I have demonstrated, you now owe the public an explanation for why.
Build an equivalent.
Improve mine.
Fork the ideas.
Standardize the invariants.
Attack the protocol.
Try to break it.
Make something stronger.
Good.
That is how civilization progresses.
What you no longer get to do is use a weaker trust architecture and behave as though no stronger proof model exists.
THIS IS NOT A VENDOR PITCH
I would actually distrust the architecture if the argument were:
Everyone must trust Receiz now.
No.
That would recreate the exact problem I am attacking.
Receiz itself cannot be sovereign over the evidence.
That is the point.
The verifier must be independently implementable.
The artifact must carry enough evidence to survive my server.
The truth must survive my company.
The election must survive its vendor.
The record must survive its database.
The proof must survive the person asking you to believe it.
Otherwise we changed brands without changing architecture.
I did not build a new authority.
I built a way to reduce how much authority has to be trusted.
THEN CERTIFICATION BECOMES WHAT IT ALWAYS SHOULD HAVE BEEN
Imagine election night under the correct architecture.
Nobody needs to scream:
TRUST THE RESULTS.
Nobody needs to scream:
THE RESULTS ARE FAKE.
The system says:
Here is the accepted evidence set.
Here are its integrity commitments.
Here is the custody history.
Here are the reconciliations.
Here are the detected divergences.
Here is how each was resolved.
Here is the audit evidence.
Here is the deterministic derivation of the aggregate.
Here is the certification artifact.
Here is the verifier.
Run it yourself.
That is a completely different civilization.
The political argument does not disappear.
It moves to where it belongs:
the evidence.
Someone alleging manipulation must identify the broken proof boundary.
Someone defending the result can point to the exact evidence establishing that boundary held.
Now both sides have somewhere objective to stand.
THAT IS WHAT “LAWFUL” SHOULD MEAN
We have allowed “lawful” to collapse into:
the authorized institution followed its authorized procedure.
That is necessary.
It is not enough for the future.
When the procedure determines who gets sovereign authority, lawful should increasingly mean something stronger:
The authorized rules were followed, the underlying evidence was preserved, material transitions were accountable, ballot secrecy remained intact, and the resulting claim can survive independent verification.
Procedure plus proof.
Authority plus accountability.
Power plus evidence.
Because otherwise we create the strangest circular argument imaginable:
We know the government was lawfully selected because the government-certified process says the government was lawfully selected.
That is exactly the kind of circular authority modern cryptographic systems were invented to reduce.
I BUILT THE VERIFIER BEFORE I ASKED YOU TO BELIEVE ME
This may be the part I care about most.
I did not write an essay saying servers should not be trusted and stop there.
I built objects that survive the server.
I did not say digital history should be immutable and stop there.
I built append-based continuity.
I did not say proof should be portable and stop there.
I made the artifact portable.
I did not say verification should work independently and stop there.
I built the offline verifier.
That verifier’s governing law explicitly says offline proof is not a fallback mode and that artifact truth outranks server, database, session and UI state.
So now I am applying exactly the same standard upward.
If I should have to prove the history of an object I created,
the state should have to prove the history of the authority it claims.
Not because government is uniquely evil.
Because government is uniquely powerful.
And responsibility should scale with authority.
THE NEXT ELECTION SHOULD COME WITH PROOF
Not another slogan.
Not another blue map.
Not another red map.
Not another official telling half the country to shut up and trust them.
Not another candidate declaring fraud without identifying a provable failure.
Not another citizen expected to choose between two competing authorities.
Give us the evidence architecture.
Give us independent verification.
Give us ballot secrecy.
Give us append-only custody.
Give us reproducible tabulation.
Give us visible divergence.
Give us auditable reconciliation.
Give us proof that survives the machine that created it.
Then certify the election.
And when somebody says it was rigged?
Excellent.
Show us the broken invariant.
When somebody says it was secure?
Excellent.
Show us the proof that the invariant held.
Same standard.
Same evidence.
Same reality.
No privileged narrator.
YOU WANTED DEMOCRATIC LEGITIMACY.
NOW PROVE IT.
I am not asking America to trust me.
I am asking America to stop designing its most important systems around trust that can be replaced by proof.
The technology has moved.
The standards are moving.
The government’s own election agencies are already speaking the language of software independence, voter-verifiable evidence, auditing and end-to-end verification. (U.S. Election Assistance Commission)
I simply followed the principle farther.
The server is not the truth.
The database is not the truth.
The interface is not the truth.
The certification is not the truth.
They are representations of a truth that must remain independently provable beneath them.
I built my systems around that law.
Now apply the law where it matters most.
Because once a civilization possesses the ability to make authority verifiable, continuing to demand trust is no longer a technological necessity.
It is a choice.
And anyone asking for power should be prepared to explain why they made it.
You do not get to certify yourself anymore.
Bring the proof.




