Miftah Foundation · Program 04 · in design

Shield — a free security audit for the nonprofits nobody audits.

Small nonprofits hold donor records, beneficiary data and sometimes health information on infrastructure that has never been checked by anyone. Shield checks it, writes the findings in plain English, and helps fix them. Free, and only ever with written permission.

← Back to Miftah Foundation


The Problem

The data is sensitive. The budget for protecting it is zero.

A food bank knows the addresses of families in crisis. A clinic holds health records. A legal aid group holds immigration files. A shelter holds the location of people hiding from someone. All of it sits in a donor database, a shared drive and a website that a volunteer set up in 2019, and none of it has ever been looked at by someone whose job was to look at it.

A commercial penetration test starts in the thousands. For an organization running on grants and goodwill, that is not a line item, so the check simply never happens. The consequence lands on the people the organization exists to protect.


What It Is

An audit, a report someone non-technical can act on, and help acting on it.

An automated audit with a human reading it

Built on DIRA, an open-source scanner that already exists and works: leaked secrets, known vulnerabilities in dependencies via OSV.dev, configuration and infrastructure rules, dependency licence risk, credentials left in git history, and live TLS and security-header checks. A trained volunteer reviews everything before it reaches the client, because a raw scan output is noise, not a report.

Read about DIRA, the underlying scanner →

Plain English, prioritised, and no fear-selling

The report names what is wrong, what could happen because of it, and what to do first — written for an executive director, not for a security team that does not exist. There is nothing to buy at the end. We are not upselling a service, because there is no service to sell.

Secret scanning Dependency CVEs Config & IaC rules Licence risk Git-history leaks TLS & headers SBOM export

How It Works

Four moves, and the first one is a signature.

STEP 1

Authorize

The client org signs an engagement letter naming exactly which systems are in scope, who owns them, and the window. Nothing is touched before this exists.

STEP 2

Assess

Trained student volunteers run the audit within that scope, supervised, using read-only and non-disruptive checks.

STEP 3

Report

Findings are triaged, false positives removed, and written up in plain English with a prioritised remediation order.

STEP 4

Remediate

We follow up, help where we can, and count the engagement only when findings are actually fixed. Found is not the metric. Fixed is.


Who It's For

Named plainly.

Registered 501(c)(3) organizations

Small ones, with no security staff and no budget for a commercial assessment. Registration is checked before an engagement starts.

Orgs holding data that would hurt someone if it leaked

Donor PII, beneficiary records, health information, case files. These go to the front of the queue.

Student volunteers, on the other side of it

Supervised real client work with a real scope and a real deliverable. A portfolio piece, a résumé line and a reference letter that describe something that actually happened.


The Hard Line

No written authorization, no scan. Ever.

Scanning a system you have not been given written permission to scan is a federal computer-crime problem, regardless of intent and regardless of how helpful the findings would have been. So the engagement letter comes first, always, and the scope in it is the boundary of everything that happens next.


Honest Status

What's real, and what isn't.

What's real

The scanner exists and works. DIRA v1.1.0 is MIT-licensed and zero-dependency, with six scanners, SBOM output in CycloneDX and SPDX, safe auto-remediation, diff-based gating and 37 passing tests. The technical capability behind this program is not hypothetical.

What isn't

Zero audits have been delivered. No client org has signed anything, the engagement-letter template has not been reviewed by an attorney, no volunteers are trained, no supervision structure exists, and the parent organization is not incorporated or insured. Nothing in this program can start before those are real.

Year-one targets (targets, not results)

  • Target: an attorney-reviewed engagement letter template, before the first client conversation.
  • Target: a trained and supervised volunteer bench, drawn from CodeBridge graduates.
  • Target: nonprofits audited, and critical findings remediated — the count only moves when something is actually fixed.

Get Involved

What would actually help.

A security professional willing to supervise student volunteers, and an attorney willing to review the engagement letter. Those two unblock everything else. If you run a small nonprofit and want to be first in the queue, say so now.

Miftah Foundation is not yet incorporated and has not applied for recognition of exemption under section 501(c)(3). No application is pending. Contributions are not tax-deductible.