A random pick nobody can rig.
List everyone in the draw. Each person gets a private link; on it, they seal a random ticket their own browser generates. Once everyone has sealed and opened, a public randomness beacon — a number nobody could have known in advance — picks the winner. Everyone gets the same signed certificate, and anyone can re-check the draw.
One private link per person.
The link is the invitation and the only way in. Send each person their own, any way you like. If you're in the draw yourself, one of these is yours — open it to seal your ticket. We store only a hash of each link, so a lost link cannot be recovered, not even by us.
What happens next: each person opens their link and seals — the ticket is generated in their browser and never crosses the network unsealed. Everyone then comes back to the same link, in the same browser, to open. Once all tickets are open and the beacon round has published, the draw computes itself — anyone's open page triggers it, and the result is identical for everyone.