BlogVerified Voting Blog Post

by Alexa Raad

A serious operational hazard recently brought forward by a whistleblower reveals a critical flaw in election readiness: mandating a brand-new federal tracking portal and rigid ballot envelope intake standards across thousands of decentralized county election offices weeks before an election violates fundamental principles of sound systems engineering. 

In large-scale IT and logistics systems, the most damaging failures rarely announce themselves with sudden, dramatic crashes. They happen quietly at the seams—where two independent databases fail to sync, an unhandled exception drops a queue of records, or an intake scanner misreads an address and halts delivery without triggering a clear alert. While national attention has focused on the constitutional tug-of-war over Executive Order 14399—culminating in a federal preliminary injunction issued by U.S. District Judge Indira Talwani and an emergency appeal to the Supreme Court—the immediate crisis is not purely legal. It is an operational hazard that would disenfranchise a significant number of voters and throw the midterms into disarray.

Building an enterprise data architecture of this scale typically requires twelve to eighteen months. Engineers need that runway to publish stable data specifications, build secure software interfaces, coordinate physical print tolerances with private vendors, and give local election staff time to run dry runs. Yet, according to an internal U.S. Postal Service (USPS) whistleblower disclosure, isolated developer teams assembled this system in a matter of weeks from shifting blueprints, culminating in an internal testing sprint of just four days on a primary sub-component. For comparison, routine administrative updates at the USPS, such as standard postal rate adjustments, generally require an eight-month development and validation cycle. As the formal whistleblower disclosure transmitted to the Senate noted:

“Other USPS IT projects currently under development, related to standard software patches or price changes, have more reasonable timelines of around eight months. These timelines reflect an established lifecycle of requirement gathering, cross-team integration, and rigorous multi-phase testing.”

Moving an untested, nation-scale tracking pipeline into live production after a four-day test window is an alarming deviation from basic quality assurance.

A single misread barcode or minor data discrepancy could quietly halt or return an entire mailing of valid ballots right as delivery deadlines expire, posing a direct threat to every average voter. Real-world mail is inherently messy: envelopes get scuffed on sorting belts, ink smudges, and registration records shift continuously. Well-tested software anticipates this friction by incorporating flexible exception handling and flagging anomalies for human review so the mail keeps moving. Instead, built through what the whistleblower called a “slapdash software development process as USPS attempted to create this complex IT system, with multiple points of ballot review, in a matter of weeks,” where “project requirements have never been sufficiently defined,” relies instead on rigid, blunt logic that turns routine sorting glitches into devastating operational failures.

These eleventh-hour requirements also run counter to standard operational discipline in election security. In election administration, strict procedural and software “change freezes” are enforced months before voting begins. They exist for a simple reason: introducing untested digital variables during an active deployment invites unforced errors. With millions of ballot envelopes already printed and states like North Carolina already mailing ballots to military, overseas, and absentee voters, forcing local jurisdictions to pivot to an unproven federal portal mid-stream creates immediate operational gridlock. Bypassing mature engineering reviews, independent third-party audits, and deliberate stress testing sets a dangerous precedent for how federal infrastructure interacts with state-administered elections.

Sound risk governance demands that we prioritize operational reliability over haste. The immediate path forward is practical: higher courts should maintain the preliminary injunction to ensure unverified software requirements do not disrupt the ongoing election cycle, while the USPS Office of Inspector General and congressional oversight committees conduct a thorough, independent audit of the platform’s development lifecycle. In the meantime, local election administrators should continue utilizing their own independent tracking and reconciliation protocols to keep ballots moving smoothly. Public trust in our elections depends on predictable, resilient systems, and true resilience cannot be built in four days.

Alexa Raad is a 25+ year tech veteran and C-suite executive in the DNS, internet infrastructure and cybersecurity industry. She is also a member of Verified Voting’s Board of Advisors and a Qualified Risk Director.