Terms of Use
Last updated 6 August 2026
Important status notice: The Machine Assurance Institute ("MAI," "we," "us," "our") is a newly formed nonprofit corporation. Our application for recognition of exemption under Section 501(c)(3) of the Internal Revenue Code (IRS Form 1023) is currently in drafting and has not yet been filed or determined. Until we receive an IRS determination letter, contributions to MAI may not be tax-deductible as charitable contributions. Do not rely on deductibility until we publish confirmation that a favorable determination letter has been issued. We intend to seek retroactive reinstatement of deductibility to the effective date of incorporation if eligible, but no assurance of that outcome can be given.
Last updated: 6 August 2026
Acceptance
By submitting the MAI intake form, you agree to these Terms of Use. If you do not agree, do not submit the form.
Eligibility
You must be at least 18 years of age to submit the form. By submitting, you represent that you are at least 18.
Accuracy of Information
You represent that all information you provide is accurate and complete to the best of your knowledge. You will promptly update us if material information changes.
No Offer of Employment; No Contract
Submitting the form is not an application for employment and creates no employment relationship, contract, or promise of any benefit between you and MAI. MAI is a volunteer-driven nonprofit; any volunteer engagement is separate and subject to a separate agreement if one is offered.
No Guarantee of Acceptance
MAI has no obligation to accept, respond to, or act on any submission. We may decline or discontinue engagement at any time, with or without cause.
Nonpartisan Use
MAI is strictly nonpartisan. The "Open Source the Vote Initiative" exists to improve election-system security for the public benefit, not to advance any political party, candidate, or partisan outcome. You agree that you will not use MAI's form, communications, research, or community for partisan political purposes, including campaigning for or against any candidate, party, or ballot measure.
Intellectual Property and Contribution Licensing Intent
MAI's research outputs are intended to be published as open source under permissive or copyleft licenses (for example, Apache 2.0, MIT, or GPLv3) chosen by MAI. If you contribute code, documentation, data, or other creative work to an MAI project, you agree that:
- You retain ownership of your contributions, but grant MAI and the public a license under the terms of the applicable project license.
- You have the right to grant that license.
- Your contributions are your original work or properly licensed material you are authorized to contribute.
- You will not contribute material that is subject to a confidentiality agreement, employment restriction, or third-party right that would prevent open-source publication.
MAI may require a separate Contributor License Agreement for significant contributions.
Responsible Disclosure
If you identify a security vulnerability in an election system, follow coordinated vulnerability disclosure practices:
- Report vulnerabilities to the system's vendor and to the appropriate election official before any public disclosure.
- Do not exploit, exfiltrate data, or access systems beyond what is necessary to confirm the vulnerability.
- Allow reasonable time for remediation before public disclosure.
- MAI may publish de-identified technical findings after remediation, consistent with public-safety norms.
Prohibition on Classified or Export-Controlled Information
You must not submit, upload, or share:
- Classified information (U.S. or foreign).
- Export-controlled technical data (including ITAR, EAR, or equivalent controls) unless you are authorized to do so and the data is appropriate for public open-source release.
- Confidential or proprietary information belonging to an employer or third party that you are not authorized to disclose.
- Personal information of third parties.
No Unauthorized Testing of Live Election Systems
You must not use MAI's form, resources, or community to conduct, plan, or coordinate unauthorized testing, scanning, probing, or intrusion of live election systems, voter registration systems, election-night reporting systems, or any production government infrastructure. Security research must be conducted only on systems you own, systems you are authorized to test, or systems made available for research through legitimate programs (e.g., vendor-sanctioned test environments, bug bounty scopes, or government-authorized ranges).
Code of Conduct
All participants must abide by the MAI Code of Conduct (Section 5 below). Violations may result in removal from MAI programs and communities.
No Warranty
MAI's websites, forms, and research are provided "as is" and "as available," without warranties of any kind, express or implied, including merchantability, fitness for a particular purpose, or non-infringement.
Limitation of Liability
To the maximum extent permitted by law, MAI and its officers, directors, employees, volunteers, and agents are not liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of profits or data, arising from your use of MAI's websites, forms, programs, or research, or your participation in any MAI activity.
Governing Law
These Terms are governed by the laws of the State in which the Machine Assurance Institute is organized, without regard to conflict-of-laws principles. You consent to the exclusive jurisdiction of the state and federal courts of that State for any dispute, except that MAI may seek injunctive relief in any court of competent jurisdiction.
Changes to Terms
We may update these Terms. Material changes will be posted with an updated "Last updated" date. Continued use of the form after changes constitutes acceptance.
SMS CONSENT
For one-time-passcode verification only.
By checking the SMS consent box and providing your mobile phone number, you expressly consent to receive a one-time automated SMS message from the Machine Assurance Institute (or its service provider, Twilio, Inc.) at the mobile number you provided, containing a verification code to confirm your number. No marketing messages will be sent.
Message frequency: You will receive a maximum of one (1) message per verification attempt. Re-verification will trigger one additional message per attempt.
Message and data rates may apply. Check with your mobile carrier for details.
To cancel: Reply STOP to any message to opt out of future SMS messages. Reply HELP for support. Opting out may prevent you from completing verification.
Carrier disclaimer: The Machine Assurance Institute is not responsible for delayed or undelivered messages. Mobile carriers are not liable for delayed or undelivered messages. Message delivery is not guaranteed. Standard message and data rates charged by your carrier may apply.
Carriers supported: Messages are delivered through Twilio to major U.S. wireless carriers. We do not guarantee delivery to all carriers or all geographic areas.
This consent is not a condition of any purchase or service. You may revoke consent at any time by replying STOP or by emailing vote@aisecurityfoundation.org.
EMAIL CONSENT
Transactional verification email (required): By submitting the form, you consent to receive a one-time automated verification email containing a code to confirm your email address. This message is required to complete submission and is not marketing.
Ongoing program updates (optional): By checking the program-updates box, you separately opt in to receive periodic non-marketing emails from MAI about the Open Source the Vote Initiative, including research announcements, volunteer opportunities, and event invitations. You may unsubscribe at any time using the link in any such email or by emailing vote@aisecurityfoundation.org. Unsubscribing does not affect transactional messages necessary to complete a submission you have initiated.
PUBLIC ACKNOWLEDGEMENT CONSENT
By checking the public-acknowledgement box, you consent to the Machine Assurance Institute publicly acknowledging your name, employer, role, and/or contribution in MAI publications, websites, social media, press materials, and event materials, in perpetuity, unless you notify us in writing to opt out. You may opt out at any time by emailing vote@aisecurityfoundation.org; opt-out applies prospectively only.
CODE OF CONDUCT
The Machine Assurance Institute is committed to fostering an open, welcoming, and nonpartisan community dedicated to election-system security for the public benefit. We pledge to make participation in our initiative a harassment-free experience for everyone, regardless of age, body size, visible or invisible disability, ethnicity, sex characteristics, gender identity and expression, level of experience, education, socio-economic status, nationality, personal appearance, race, religion, or sexual identity and orientation.
We expect all participants—volunteers, donors, vendors, researchers, and staff—to act professionally and respectfully. Examples of unacceptable behavior include: the use of sexualized language or imagery; unwelcome sexual attention or advances; trolling, insulting, or derogatory comments; personal or political attacks; harassment of any kind; publishing others' private information without consent; and any conduct that could reasonably be considered inappropriate in a professional setting.
Participants asked to stop unacceptable behavior are expected to comply immediately. MAI may remove, ban, or decline further engagement with anyone who engages in unacceptable behavior, at our sole discretion and without notice. This Code is not exhaustive; MAI may address conduct not explicitly listed here that undermines the community's safety or mission.
To report concerns, email vote@aisecurityfoundation.org. Reports are handled confidentially to the extent possible. This Code applies in all MAI spaces and in public spaces when an individual is representing MAI or its community.
EXPORT CONTROL AND LEGAL SAFE HARBOR
Security research into election systems serves the public interest and is generally protected under U.S. law when conducted lawfully, in good faith, and without unauthorized access to production systems. However, technical information about vulnerabilities, exploits, or defensive measures may be subject to U.S. export controls, including the Export Administration Regulations (EAR) and the International Traffic in Arms Regulations (ITAR), as well as analogous laws in other jurisdictions. MAI's research is intended for public, open-source release and is structured to avoid controlled technical data. Contributors are solely responsible for ensuring that any information they submit is not classified, export-controlled, or otherwise restricted from public disclosure, and that they have all necessary rights and authorizations to contribute it. MAI does not provide legal advice; contributors with questions about export control, authorization, or legal exposure should consult qualified counsel before submitting. Nothing in this document constitutes a representation that any particular contribution is lawful to publish, transmit, or export in any jurisdiction.
Machine Assurance Institute · vote@aisecurityfoundation.org