Methodology
The pipeline, the standing rules, and where we refuse.
Method is what makes a figure reviewable by someone who does not trust us. Each stage names the artifact it leaves behind, each rule holds in every engagement, and each refusal carries a code that can be looked up.
The pipeline
Five stages, each leaving an artifact
| Stage | What happens | Evidence artifact |
|---|---|---|
Capture | Tally sheets are captured and hashed at the moment of capture, with the capturing role recorded rather than an individual. | Capture set, with the image hash per artifact |
Verify | Each sheet is read against that country's acta format and human-confirmed; automated extraction never stands alone. | Verification record per station, with its proving basis |
Aggregate | Verified records only are aggregated, with a stated interval and a finite-population correction on the sampled frame. | Aggregation report, with the interval log and method note |
Reconcile | Verified figures are compared line by line with a hashed snapshot of the official record; nothing is dropped. | Reconciliation report, with the full N/A log |
Preserve | Parts are frozen, hashed, chained to a root, and archived, with a delivery hash recorded in the custody record. A correction is a new artifact, never an edit. | erm_evidence/1 bundle, with its manifest and delivery hash |
Standing rules
Rules that hold in every engagement
Provenance on every number
No figure is published without its source, or without an N/A that carries a reason. A blank and a zero are both refused.
Attribution discipline
A figure is attributed to the record it came from, never to Veridian's judgment. We report what a record says, and name the record.
No win-calls
We do not publish, imply, or confirm an outcome before certification, and we do not confirm one on request afterwards.
Aggregate-only
The smallest unit we publish is an aggregate unit. Individual-level data is not collected, not stored, and not accepted from a client.
Human accountability
A named role answers for every verification and every refusal. No figure and no denial is attributed to a system alone.
Rehearsed reachability
Official-source reachability is rehearsed against the real endpoint before the contest. Availability is never assumed on the day.
Confidence intervals
A number without a band is not a finding
- Never a point estimate without a band. A bare percentage is published as a refusal, not as a result.
- The interval is withheld, with a stated reason, when the sample is coverage-based rather than probability-based. A band computed on a non-probability sample is arithmetic, not inference.
- Identical bands across strata are a refusal, not a result. A degenerate or uniform band means the computation failed, and the reason code is published in its place.
Published, probability sample
95 % interval, finite-population correction applied · verified records, 1,412 of 1,480 stations
Withheld, coverage-based sample
interval withheld · non_probability_sample
No interval is published for this frame, and no point estimate is published in its place.
Refusal rules
Refusal rules, and the code each one publishes
A refusal is a finding. It names what is withheld, the reason code it rests on, and the log entry that records it. Codes are stable across engagements and across languages.
| Reason code | What is withheld, and why |
|---|---|
non_probability_sample | The frame is coverage-based, not a probability sample. No interval is published, and no point estimate is published in its place. |
coverage_below_threshold | Verified coverage for the unit is below the protocol threshold. No figure is published for that unit; it publishes as N/A with this code. |
official_snapshot_absent | No official-record snapshot could be fetched and hashed. Reconciliation is not attempted, and no delta is published. |
degenerate_band | The interval computation returned a zero-width or uniform band. The band is withheld and the failure is published in its place. |
unreadable_tally | The tally sheet cannot be read to the standard by a human confirmer. The station publishes as N/A with this code, never as a zero. |
Capability status
Production-proven and simulation-proven, kept apart
The qualifier column is the wording we use everywhere, verbatim. If a capability is simulation-proven, that phrase travels with it into every deck, proposal, and report.
| Capability | Status | Verbatim qualifier |
|---|---|---|
| Tally-sheet verification, human-confirmed | Production-proven | “Run at national scale in a certified contest.” |
| Independent aggregation with stated intervals | Engine capability — accuracy not claimed | “Intervals were withheld in engagement #1 (non-probability sample); no published interval has yet resolved.” |
| Reconciliation against the official record | Production-proven | “Run at national scale in a certified contest.” |
| Automated tally-sheet extraction | Simulation-proven | “A three-tally-sheet live demonstration, plus a pipeline designed for national scale. It has not run live at national scale.” |
| Tamper detection on the evidence bundle | Simulation-proven | “Three constructed tamper cases, detected on every CI run against a synthetic bundle.” |
| Content-credential chain | Simulation-proven | “C2PA-ready: structured for C2PA assertions, and not certified by any C2PA authority.” |
Request an engagement
Tell us the contest, the date, and the artifact you need. We reply with scope, refusal conditions, and a price against the published floor.