Check us.
Don’t trust us.
This petition goes to the U.S. Department of Energy. A signature roll is only worth something if it can survive being examined, so here is exactly how it is built, including the parts we can’t claim.
A signature doesn’t count until you click a link in your email
Anyone can type someone else’s name into a form. Idaho’s voter rolls are public, so a person wanting to discredit this could submit hundreds of real names without consent, then tip off a reporter.
That’s why a signature does not exist, is not counted, and never appears publicly until someone clicks a confirmation link sent to their own inbox. It is the single most important control here, and it is why the public number is always lower than the number of submissions.
The public count only ever shows confirmed signatures
Both numbers are above, side by side, permanently. A planted or abandoned entry can never reach the figure anyone screenshots.
One person, one signature, including the clever versions
Email addresses are reduced to a canonical form before being checked, so you+1@gmail.com, you+2@gmail.com and y.o.u@gmail.com are all recognised as the same person. Without that, email confirmation alone wouldn’t stop anyone signing fifty times from one inbox.
The roll is append-only, and published daily as a fingerprint
The obvious question about any petition is whether the people running it added names later. Signatures are stored append-only, and each day the confirmed set is hashed together with the previous day’s hash and published.
That makes the roll tamper-evident: anyone can verify afterwards that the list delivered contains exactly the signatures that existed on each earlier day, in order, with nothing inserted.
Here is the chain so far. Each day’s hash covers that day’s confirmations and the previous day’s hash, so altering anything in the past changes every hash after it.
Built automatically at 07:10 UTC each day, inside the database. Not by a person, and not by anything we could forget to run. Days with no confirmations still get a link, so a gap in the chain is itself evidence.
What we check, and what we deliberately don’t
Every submission passes an invisible bot check, a hidden field no person can see, a minimum time-on-form, and rate limits. IP addresses are stored only as a one-way cryptographic hash, never in readable form.
We do not require a phone number, a driver’s licence, or a street address. A petition that demands identity papers collects fewer signatures and deserves to.
What we do not claim
This is the part most campaigns leave out. We ask for a ZIP code and check it against the county you select, which catches typos and careless fabrication. It is not proof of residency. Anyone anywhere can look up a valid Idaho ZIP.
So we will never describe these as “verified Idaho residents.” What we can say is precisely this: each signer confirmed an email address and provided an Idaho ZIP code consistent with the county they selected. If we later match the roll against Idaho’s public voter file, we’ll publish that number separately and say exactly what it means.
Signatures from outside Idaho are welcome, and are counted separately. The number on the front page is Idaho residents only.
Found a problem with any of this? Tell us. A page about being checkable should be the easiest one to correct.