Skip to content
Use case 079

Electronic Voting Machines

A deployment concept for electoral commissions, voting-system vendors, auditors and election security teams.

Proposed deployment · Compatibility assessment required
Government, Public Safety and Defence

Why this environment matters

For electronic voting machines, the system captures and records voter selections at polling locations. The risk extends beyond a conventional endpoint: malicious software, unauthorised configuration or hidden persistence could alter records or undermine confidence in the result. A NØNOS deployment concept would treat every software component, data source and device interface as separately authorised rather than assuming that anything running on the host should be broadly trusted.

The security challenge

Public-sector systems hold authoritative records and powers that affect identity, liberty, property, emergency response and national security. Endpoint compromise can therefore create consequences far beyond data loss. For this system, the primary attack path is that malicious software, unauthorised configuration or hidden persistence could alter records or undermine confidence in the result. Conventional general-purpose hosts often place parsers, management tools, network services and privileged drivers in one broad trust domain, allowing a flaw in a low-value feature to reach a high-consequence function.

How the capsule model could help

NØNOS could be placed at the operator, gateway, edge or application-compute layer and configured to use signed, inspectable vote-capture capsules, strict device capabilities and resettable known-good election images with independent audit outputs. The most relevant controls are purpose-bound data access, attestation for privileged actions, controlled removable media and disposable trusted sessions. This would make privileges explicit: a service that reads a sensor, displays data or contacts a cloud API would not automatically be able to issue a physical command or use a signing key.

Separate address spaces and capability checks can limit cross-process reach. They cannot stop harmful use of legitimate permissions, prove AI decisions correct or substitute for domain-specific safety controls.

Deployment requirements

Government deployment would require formal accreditation, identity and records integration, accessibility testing, procurement assurance and controls appropriate to the information classification and public function.

Current public-beta limitations, hardware support and application availability must be assessed before any pilot. Neither this use case nor an industry source establishes NONOS certification or a current customer deployment.

Who could buy or integrate it?

  • Election authorities procuring voting equipment through formal tenders
  • Voting-system manufacturers selecting the embedded execution platform
  • Election service contractors integrating deployment and maintenance for jurisdictions

Industry examples: Election Systems & Software, Hart InterCivic. Organisations shown illustrate the industry. No NONOS customer, partner or endorsement relationship is implied.

Market opportunity

Market benchmarks and device scenarios.

Published industry benchmark
US$45 million

US HAVA election security appropriation

United States and US territories · 2026 · annual budget appropriation

FY2026 federal funding appropriated for state and territorial election administration and security. Budget authority, not actual annual outlays, vendor sales, or total election spending. Excludes state matching funds.

Modelled global devices
500K–6M

Candidate OS endpoints

Hypothetical planning range · 2025

Low confidence: planning assumptions. Hardware compatibility, procurement and adoption have not been validated.

Illustrative annual licensing
$10M–$600M

USD / year at full model coverage

Device scenario × assumed US$20–$100 per device / year.

Not a revenue forecast, announced price or measured serviceable market.

Device calculation

Hypothetical global planning range, 2025 scenario: assume 500,000–2,000,000 polling locations hypothetically within electronic-voting jurisdictions × 1–3 candidate OS endpoints per site/asset = 500,000–6,000,000 endpoints. Counting unit: dedicated voting or ballot-verification computers; excludes paper-only locations. Site and asset counts, and devices per site, are planning assumptions. The installed base has not been measured. Coverage is limited to the defined equipped subset; includes all candidate endpoints within that assumed subset. Hardware eligibility, certification, adoption and achievable NØNOS share are unverified; overlaps other cases.

Election Security Grant ↗

Market context only; separate from device and site population estimates. Original monetary-market scope and geography are preserved in benchmark. This source does not establish the assumed worldwide site count or endpoint density.

How to interpret the figures

Adjacent or broader commercial market benchmark; not the NØNOS OS market, licensable-device count or revenue forecast.

Modelled candidate endpoints multiplied by an assumed annual USD price per endpoint. Pricing is a planning assumption, not a vendor quote. This illustrates the full scenario range, not revenue or total addressable market. It excludes adoption timing, procurement, certification, support costs, channel economics and achievable market share. Use cases can overlap, so their totals do not represent unique devices.

Research from 2026. Publisher estimates have not been independently audited.

Read the full methodology

Explore NONOS

Choose your
NONOS experience.

Discover the platform for your organisation or explore the software.

You can reopen this chooser from the footer at any time.