Miftah Foundation · Program 04 · in design

Shield — a free security audit for the nonprofits nobody audits.

Small nonprofits hold donor records, beneficiary data and sometimes health information on infrastructure that has never been checked by anyone. Shield checks it, writes the findings in plain English, and helps fix them. Free, and only ever with written permission.

Where this actually is

Zero audits have been delivered. No client org has signed anything and no volunteers are trained. The parent organization is not incorporated, has filed nothing with the IRS and has nothing pending, so nothing given to it is deductible on anyone's return and none is being asked for. What follows is the design and the scanner it rests on.

← Back to Miftah Foundation


The Problem

The data is sensitive. The budget for protecting it is zero.

A food bank knows the addresses of families in crisis. A clinic holds health records. A legal aid group holds immigration files. A shelter holds the location of people hiding from someone. All of it sits in a donor database, a shared drive and a website that a volunteer set up in 2019, and none of it has ever been looked at by someone whose job was to look at it.

A commercial penetration test starts in the thousands. For an organization running on grants and goodwill, that is not a line item, so the check simply never happens. The consequence lands on the people the organization exists to protect.


What It Is

An audit, a report someone non-technical can act on, and help acting on it.

An automated audit with a human reading it

Built on DIRA, an open-source scanner that already exists and works: leaked secrets, known vulnerabilities in dependencies via OSV.dev, configuration and infrastructure rules, dependency licence risk, credentials left in git history, and live TLS and security-header checks. A trained volunteer reviews everything before it reaches the client, because a raw scan output is noise, not a report.

Read about DIRA, the underlying scanner →

Plain English, prioritised, and no fear-selling

The report names what is wrong, what could happen because of it, and what to do first — written for an executive director, not for a security team that does not exist. There is nothing to buy at the end. We are not upselling a service, because there is no service to sell.

Secret scanning Dependency CVEs Config & IaC rules Licence risk Git-history leaks TLS & headers SBOM export

How It Works

Four moves, and the first one is a signature.

Authorize

The client org signs an engagement letter naming exactly which systems are in scope, who owns them, and the window. Nothing is touched before this exists.

Assess

Trained student volunteers run the audit within that scope, supervised, using read-only and non-disruptive checks.

Report

Findings are triaged, false positives removed, and written up in plain English with a prioritised remediation order.

Remediate

We follow up, help where we can, and count the engagement only when findings are actually fixed. Found is not the metric. Fixed is.


Who It's For

Named plainly.

IRS-recognized charitable organizations
Small ones, with no security staff and no budget for a commercial assessment. Charitable status is verified against the IRS and California registries before an engagement starts. (Miftah itself does not have that status — which is precisely why it can only give this away, not charge for it.)
Orgs holding data that would hurt someone if it leaked
Donor PII, beneficiary records, health information, case files. These go to the front of the queue.
Student volunteers, on the other side of it
Supervised real client work with a real scope and a real deliverable. A portfolio piece, a résumé line and a reference letter that describe something that actually happened.

The Hard Line

No written authorization, no scan. Ever.

Scanning a system you have not been given written permission to scan is a federal computer-crime problem, regardless of intent and regardless of how helpful the findings would have been. So the engagement letter comes first, always, and the scope in it is the boundary of everything that happens next.


Honest Status

What this is, and what it is not yet.

What this is

Real today

The scanner exists and works. DIRA v1.5.1 is MIT-licensed and zero-dependency, with seven scanners, SBOM output in CycloneDX and SPDX, safe auto-remediation, diff-based gating and over 200 automated tests. The technical capability behind this program is not hypothetical.

What it is not yet

Not true yet

Zero audits have been delivered. No client org has signed anything, the engagement-letter template has not been reviewed by an attorney, no volunteers are trained, no supervision structure exists, and the parent organization is not incorporated or insured. Nothing in this program can start before those are real.

Year-one targets — targets, not results

  • Target: an attorney-reviewed engagement letter template, before the first client conversation.
  • Target: a trained and supervised volunteer bench, drawn from CodeBridge graduates.
  • Target: nonprofits audited, and critical findings remediated — the count only moves when something is actually fixed.

First 100 Days

What the first hundred days would actually look like.

Counted from the day an attorney agrees to review one document. Of the four programs this is the one with the most ways to do real harm, so the first fifth of the plan is entirely paperwork and nobody touches a keyboard.

  1. Days 1–20 · the hard gate

    Get the engagement letter reviewed by an attorney

    Scope definition, system ownership, the assessment window, liability, and what happens to findings. A student drafting this from a template and calling it done is exactly the failure mode this gate exists to prevent. No client is approached before it is signed off.

  2. Days 21–35

    Recruit one supervisor and train the first three volunteers

    Written rules of engagement, read-only tooling, a documented escalation path for anything found that looks like a live breach, and a named professional who reviews every report before it leaves. Three trained people beat thirty signups.

  3. Days 36–50

    Sign the first client scope

    One small organization holding data that would hurt someone if it leaked. Verify their charitable registration, agree the systems in scope in writing, name their owner for each, and set the window. Anything not on that list stays untouched.

  4. Days 51–65

    Run the assessment, inside the lines

    Read-only and non-disruptive checks only, within the signed scope, supervised throughout. Then the unglamorous half: triage every finding, strip the false positives, and rank what is left by what could actually happen.

  5. Days 66–80

    Deliver a report an executive director can act on

    Plain English, prioritised, with nothing to buy at the end — and a walkthrough conversation rather than a PDF over the wall. The report goes to the client and to nobody else, ever.

  6. Days 81–100

    Follow up, and count only what got fixed

    Help where we can, re-check the critical findings, and record the engagement in the shared ledger with remediation as the outcome value. Findings discovered is a vanity number; findings closed is the program.


Get Involved

What would actually help.

A security professional willing to supervise student volunteers, and an attorney willing to review the engagement letter. Those two unblock everything else. If you run a small nonprofit and want to be first in the queue, say so now.

Miftah Foundation is not incorporated and has not applied for recognition of federal charitable tax exemption. No application is pending. Nothing given to it is deductible on anyone's return, and nothing is being solicited.

Two signatures unblock everything else.

Say whether you can supervise, review the engagement letter, or want your nonprofit first in the queue.