How can I know/trust that? These things are proposed a lot, and they all tend to fail around ease of use, properly establishing anonymity, and trust into their implementation.
A guess you trust this system the same way you trust people from not looking in the urn after you put the envelop in. Or not altering the count when they open it.
Do you have an example of failure like you said ?