Row-level security
Row-level access controls remain enabled on every customer-owned or exposed table. Policies combine authenticated access with ownership and scope predicates; UI visibility is never the sole control.
Security and trust
Votegrain uses defence in depth: authenticated server flows, database row-level access controls, explicit grants, constraints, security-reviewed database procedures, application validation and independent permission tests. The product describes what it does today, not a certification or a promise beyond the current implementation.
Row-level access controls remain enabled on every customer-owned or exposed table. Policies combine authenticated access with ownership and scope predicates; UI visibility is never the sole control.
Ballot writes occur through approved database procedures only. Duplicate and write-once integrity is database-enforced, while ordinary roles cannot read ballot rows.
Anonymous small cells and small group audiences are suppressed. Results and exports expose aggregates rather than voter identity.
The released result remains deterministic and authoritative. Governed analysis cannot replace it or change the result when model output is unavailable.
Customer-owned child records carry organisation and scope boundaries with composite same-organisation foreign keys. Cross-organisation references are rejected at database write boundaries, and service-role credentials remain server-only.
Tenant Owner, Organisation Admin, Initiative Editor, Analyst, Voter and Read-only Invitee are distinct target grants. The application offers affordances, but database policies and procedures decide effective access.
Anonymous ballot identity is retained only for eligibility and duplicate protection. Named ballot identity access is denied to baseline roles, and reporting crosses the boundary only through released, source-verified and suppressed aggregates.
Result surfaces and exports expose aggregates, never voter identity. Participation metadata cannot substitute for eligibility or turnout.
Groups are not segment, export, confidence, risk or AI dimensions. A group scope does not create an analysis segment.
Model calls occur server-side with allow-listed inputs and strict output validation. AI never guides voter choice, and unavailable model output is reported honestly rather than fabricated.
AI features require their own permission and policy checks, with a platform stop switch. A failure leaves the released deterministic result untouched.
Explore how AI is used and our example decision standards.