Protecting the integrity of every ballot requires disciplined cybersecurity practices aligned with recognized industry standards. Skypunch maintains a comprehensive security program built on continuous monitoring, independent assessment, and adherence to established frameworks.
National Institute of Standards and Technology Special Publication 800-53
Learn more about this publication at the NIST website. Skypunch aligns its security controls with the National Institute of Standards and Technology (NIST) Special Publication 800-53, a widely adopted framework for information security and privacy controls.
Through Amazon Web Services (AWS) Security Hub, the platform continuously evaluates system architecture against applicable NIST controls. Any deviation is automatically identified for remediation. Controls are reviewed on an ongoing basis as both technology and the standard evolve.
Partnering With CISA
Skypunch participates in monthly vulnerability scanning through programs supported by the Cybersecurity and Infrastructure Security Agency (CISA), the federal agency responsible for securing critical infrastructure in the United States.
Scanning is conducted using industry-standard tools and methodologies, including controls informed by the Open Web Application Security Project (OWASP) Application Security Verification Standard.
Red Team Testing
Through its residency at Vantage Ventures, Skypunch collaborates with cybersecurity faculty and students from West Virginia University’s John Chambers College of Business and Economics and Marshall University’s Institute for Cybersecurity.
Both institutions are founding partners of the National Center of Excellence for Cybersecurity in Critical Infrastructure. Under faculty supervision, students conduct structured security exercises including:
- Vulnerability scanning
- Penetration testing
- Threat hunting
- Auditing and compliance with various industry standards (such as that published by the Open Web Application Security Project)
This structured testing model provides real-world experience for students while offering Skypunch independent assessment from cybersecurity auditors operating under academic oversight.
Code and Package Scanning
Source code is continuously scanned for security vulnerabilities and performance risks. Automated analysis tools identify insecure coding patterns and known vulnerabilities in third-party dependencies. Scans are triggered upon code updates and when new vulnerabilities are disclosed.
Amazon Web Services Certification
Skypunch infrastructure is deployed within Amazon Web Services (AWS) and managed by AWS-certified engineers. This ensures that identified security findings are remediated according to AWS best practices and architectural guidance. The same AWS-certified expertise applied in client consulting engagements is used in the design, deployment, and ongoing maintenance of the voting platform.
Summary
Security at Skypunch is not defined by a single control or certification. It is a layered, continuously monitored program designed to protect ballot integrity at every stage of the election lifecycle.