Forum OnlineForum Online
    About ForumSign in
    Sign in

    Security & Privacy

    Enterprise-grade security architecture protecting your identity and votes

    100% Open Source & Verifiable

    Forum is built on transparency. Every line of code, every smart contract, and every cryptographic proof is open source and publicly auditable. We believe trust comes from verification, not promises.

    View Source Code on GitHubAudit Smart Contracts
    Continuous Review
    Community-driven code review
    Public Audits
    All security audits published
    Verifiable Builds
    Reproducible from source

    Security at a Glance

    100%
    Open Source
    256-bit
    Encryption
    Zero
    Data Breaches
    Public
    Audit Reports

    Core Security Principles

    Device-Only Processing

    All sensitive data processing happens exclusively on your device. Passport photos, biometric templates, and personal information never leave your phone.

    Local NFC chip reading
    On-device biometric processing
    Client-side zero-knowledge proof generation

    Zero-Knowledge Architecture

    Prove your eligibility to vote without revealing any personal information. Advanced cryptographic circuits ensure complete anonymity.

    Groth16 proof verification
    Merkle-based eligibility checks
    Nullifier-based anonymous voting

    Cryptographic Security

    Encryption Standards

    AES-256 for data at rest • TLS 1.3 for data in transit • ECDSA for digital signatures • SHA-256 hashing for Merkle eligibility trees

    Key Management

    Hardware security modules • Secure key derivation (BIP-32) • Multi-signature wallets • Regular key rotation

    Zero-Knowledge Proofs

    Groth16 proof verification • Trusted setup verification • Merkle eligibility proofs • Per-post nullifiers to prevent duplicate anonymous votes

    Infrastructure Security

    Blockchain Security

    Ethereum Layer 2 deployment • Immutable smart contracts • Consensus mechanism protection • MEV protection

    Network Security

    DDoS protection • Rate limiting • Geographic distribution • CDN security

    Operational Security

    24/7 monitoring • Incident response team • Regular security audits • Penetration testing

    Privacy Protection

    Data Minimization

    Only necessary data collected • Automatic data purging • Pseudonymization techniques • Privacy by design

    Anonymous Voting

    Vote-identity unlinkability • Mixing networks • Temporal decorrelation • Metadata protection

    Threat Model & Mitigations

    Potential Threats

    Sybil Attacks

    Malicious actors creating multiple fake identities

    Vote Buying

    External parties attempting to purchase votes

    Coercion

    Forcing voters to vote in specific ways

    State Attacks

    Government surveillance or intervention

    Our Mitigations

    Eligibility and Nullifier Checks

    Merkle eligibility proofs and per-post nullifiers reduce fake or duplicate voting without exposing voter identity

    Anonymous Receipt System

    No way to prove how you voted to third parties

    Zero-Knowledge Privacy

    Impossible to link votes to specific individuals

    Decentralized Architecture

    No central point of failure or control

    Verify Everything

    Don't trust, verify. All our code is open for inspection, from the mobile app to smart contracts. Check our implementations, review our cryptography, and validate our security claims yourself.

    Mobile App Source CodeZero-Knowledge CircuitsSmart Contracts

    Community Verified

    Our growing community of developers and security researchers continuously review our code. Join our contributors who help make Forum more secure every day. Every commit is reviewed, every change is tracked, and every security concern is addressed transparently on GitHub.

    Security Contact

    Found a security issue? Please report it responsibly according to the repository security policy.

    Preferred: GitHub Security Advisories
    Do not open a public GitHub issue for vulnerabilities
    Fallback: contact maintainers privately with reproduction steps and impact
    Forum OnlineForum

    Forum voting platform built on Ethereum Layer 2

    Download on the App StoreGet it on Google Play

    Platform

    • About Forum
    • Testnet Guide
    • Security

    Resources

    • Documentation
    • Whitepaper
    • Download App
    • Community
    • FORUM Token
    • Programs

    Legal

    • Cookie Policy
    • Mirrors

    © 2026 Forum Protocol. Built on Ethereum Layer 2. All rights reserved.

    Built for modern democracy
    v1.0.7