Shield — a free security audit for the nonprofits nobody audits.
Small nonprofits hold donor records, beneficiary data and sometimes health information on infrastructure that has never been checked by anyone. Shield checks it, writes the findings in plain English, and helps fix them. Free, and only ever with written permission.
Where this actually is
Zero audits have been delivered. No client org has signed anything and no volunteers are trained. The parent organization is not incorporated, has filed nothing with the IRS and has nothing pending, so nothing given to it is deductible on anyone's return and none is being asked for. What follows is the design and the scanner it rests on.
The data is sensitive. The budget for protecting it is zero.
A food bank knows the addresses of families in crisis. A clinic holds health records. A legal aid group holds immigration files. A shelter holds the location of people hiding from someone. All of it sits in a donor database, a shared drive and a website that a volunteer set up in 2019, and none of it has ever been looked at by someone whose job was to look at it.
A commercial penetration test starts in the thousands. For an organization running on grants and goodwill, that is not a line item, so the check simply never happens. The consequence lands on the people the organization exists to protect.
What It Is
An audit, a report someone non-technical can act on, and help acting on it.
An automated audit with a human reading it
Built on DIRA, an open-source scanner that already exists and works: leaked secrets, known vulnerabilities in dependencies via OSV.dev, configuration and infrastructure rules, dependency licence risk, credentials left in git history, and live TLS and security-header checks. A trained volunteer reviews everything before it reaches the client, because a raw scan output is noise, not a report.
The report names what is wrong, what could happen because of it, and what to do first — written for an executive director, not for a security team that does not exist. There is nothing to buy at the end. We are not upselling a service, because there is no service to sell.
The client org signs an engagement letter naming exactly which systems are in scope, who owns them, and the window. Nothing is touched before this exists.
Assess
Trained student volunteers run the audit within that scope, supervised, using read-only and non-disruptive checks.
Report
Findings are triaged, false positives removed, and written up in plain English with a prioritised remediation order.
Remediate
We follow up, help where we can, and count the engagement only when findings are actually fixed. Found is not the metric. Fixed is.
Who It's For
Named plainly.
IRS-recognized charitable organizations
Small ones, with no security staff and no budget for a commercial assessment. Charitable status is verified against the IRS and California registries before an engagement starts. (Miftah itself does not have that status — which is precisely why it can only give this away, not charge for it.)
Orgs holding data that would hurt someone if it leaked
Donor PII, beneficiary records, health information, case files. These go to the front of the queue.
Student volunteers, on the other side of it
Supervised real client work with a real scope and a real deliverable. A portfolio piece, a résumé line and a reference letter that describe something that actually happened.
The Hard Line
No written authorization, no scan. Ever.
Scanning a system you have not been given written permission to scan is a federal computer-crime problem, regardless of intent and regardless of how helpful the findings would have been. So the engagement letter comes first, always, and the scope in it is the boundary of everything that happens next.
Miftah Foundation performs security assessments only under written authorization from the system owner, strictly within the scope defined in the signed engagement letter. Assessments are point-in-time and best-effort; they do not guarantee the absence of vulnerabilities and do not constitute a compliance certification.
Scope is a boundary, not a suggestion. If a system is not named in the signed letter, it is not touched, even when it is obviously connected to one that is.
Third-party systems need their own owner's permission. A client cannot authorize a scan of a vendor's platform. If the vendor is in scope, the vendor signs too.
Read-only and non-disruptive by default. No exploitation, no data extraction, no load testing, nothing that could take a working system down.
Findings go to the client, and nowhere else. No public disclosure, no case study with the org named, no report shared without their written consent.
Not a compliance certification. A Shield report does not make anyone HIPAA, SOC 2 or PCI compliant and will never be presented as if it does.
Point in time. A clean report describes the day it was run. It is not a guarantee about tomorrow, and it never claims to be.
Volunteers are trained and supervised before they touch a client system, and a supervisor reviews every report before it is delivered.
Honest Status
What this is, and what it is not yet.
What this is
Real today
The scanner exists and works. DIRA v1.5.1 is MIT-licensed and zero-dependency, with seven scanners, SBOM output in CycloneDX and SPDX, safe auto-remediation, diff-based gating and over 200 automated tests. The technical capability behind this program is not hypothetical.
What it is not yet
Not true yet
Zero audits have been delivered. No client org has signed anything, the engagement-letter template has not been reviewed by an attorney, no volunteers are trained, no supervision structure exists, and the parent organization is not incorporated or insured. Nothing in this program can start before those are real.
Year-one targets — targets, not results
Target: an attorney-reviewed engagement letter template, before the first client conversation.
Target: a trained and supervised volunteer bench, drawn from CodeBridge graduates.
Target: nonprofits audited, and critical findings remediated — the count only moves when something is actually fixed.
First 100 Days
What the first hundred days would actually look like.
Counted from the day an attorney agrees to review one document. Of the four programs this is the one with the most ways to do real harm, so the first fifth of the plan is entirely paperwork and nobody touches a keyboard.
Days 1–20 · the hard gate
Get the engagement letter reviewed by an attorney
Scope definition, system ownership, the assessment window, liability, and what happens to findings. A student drafting this from a template and calling it done is exactly the failure mode this gate exists to prevent. No client is approached before it is signed off.
Days 21–35
Recruit one supervisor and train the first three volunteers
Written rules of engagement, read-only tooling, a documented escalation path for anything found that looks like a live breach, and a named professional who reviews every report before it leaves. Three trained people beat thirty signups.
Days 36–50
Sign the first client scope
One small organization holding data that would hurt someone if it leaked. Verify their charitable registration, agree the systems in scope in writing, name their owner for each, and set the window. Anything not on that list stays untouched.
Days 51–65
Run the assessment, inside the lines
Read-only and non-disruptive checks only, within the signed scope, supervised throughout. Then the unglamorous half: triage every finding, strip the false positives, and rank what is left by what could actually happen.
Days 66–80
Deliver a report an executive director can act on
Plain English, prioritised, with nothing to buy at the end — and a walkthrough conversation rather than a PDF over the wall. The report goes to the client and to nobody else, ever.
Days 81–100
Follow up, and count only what got fixed
Help where we can, re-check the critical findings, and record the engagement in the shared ledger with remediation as the outcome value. Findings discovered is a vanity number; findings closed is the program.
Get Involved
What would actually help.
A security professional willing to supervise student volunteers, and an attorney willing to review the engagement letter. Those two unblock everything else. If you run a small nonprofit and want to be first in the queue, say so now.
Miftah Foundation is not incorporated and has not applied for recognition of federal charitable tax exemption. No application is pending. Nothing given to it is deductible on anyone's return, and nothing is being solicited.
Two signatures unblock everything else.
Say whether you can supervise, review the engagement letter, or want your nonprofit first in the queue.