Shield — a free security audit for the nonprofits nobody audits.
Small nonprofits hold donor records, beneficiary data and sometimes health information on infrastructure that has never been checked by anyone. Shield checks it, writes the findings in plain English, and helps fix them. Free, and only ever with written permission.
The Problem
The data is sensitive. The budget for protecting it is zero.
A food bank knows the addresses of families in crisis. A clinic holds health records. A legal aid group holds immigration files. A shelter holds the location of people hiding from someone. All of it sits in a donor database, a shared drive and a website that a volunteer set up in 2019, and none of it has ever been looked at by someone whose job was to look at it.
A commercial penetration test starts in the thousands. For an organization running on grants and goodwill, that is not a line item, so the check simply never happens. The consequence lands on the people the organization exists to protect.
What It Is
An audit, a report someone non-technical can act on, and help acting on it.
An automated audit with a human reading it
Built on DIRA, an open-source scanner that already exists and works: leaked secrets, known vulnerabilities in dependencies via OSV.dev, configuration and infrastructure rules, dependency licence risk, credentials left in git history, and live TLS and security-header checks. A trained volunteer reviews everything before it reaches the client, because a raw scan output is noise, not a report.
Plain English, prioritised, and no fear-selling
The report names what is wrong, what could happen because of it, and what to do first — written for an executive director, not for a security team that does not exist. There is nothing to buy at the end. We are not upselling a service, because there is no service to sell.
How It Works
Four moves, and the first one is a signature.
Authorize
The client org signs an engagement letter naming exactly which systems are in scope, who owns them, and the window. Nothing is touched before this exists.
Assess
Trained student volunteers run the audit within that scope, supervised, using read-only and non-disruptive checks.
Report
Findings are triaged, false positives removed, and written up in plain English with a prioritised remediation order.
Remediate
We follow up, help where we can, and count the engagement only when findings are actually fixed. Found is not the metric. Fixed is.
Who It's For
Named plainly.
Registered 501(c)(3) organizations
Small ones, with no security staff and no budget for a commercial assessment. Registration is checked before an engagement starts.
Orgs holding data that would hurt someone if it leaked
Donor PII, beneficiary records, health information, case files. These go to the front of the queue.
Student volunteers, on the other side of it
Supervised real client work with a real scope and a real deliverable. A portfolio piece, a résumé line and a reference letter that describe something that actually happened.
The Hard Line
No written authorization, no scan. Ever.
Scanning a system you have not been given written permission to scan is a federal computer-crime problem, regardless of intent and regardless of how helpful the findings would have been. So the engagement letter comes first, always, and the scope in it is the boundary of everything that happens next.
Miftah Foundation performs security assessments only under written authorization from the system owner, strictly within the scope defined in the signed engagement letter. Assessments are point-in-time and best-effort; they do not guarantee the absence of vulnerabilities and do not constitute a compliance certification.
- Scope is a boundary, not a suggestion. If a system is not named in the signed letter, it is not touched, even when it is obviously connected to one that is.
- Third-party systems need their own owner's permission. A client cannot authorize a scan of a vendor's platform. If the vendor is in scope, the vendor signs too.
- Read-only and non-disruptive by default. No exploitation, no data extraction, no load testing, nothing that could take a working system down.
- Findings go to the client, and nowhere else. No public disclosure, no case study with the org named, no report shared without their written consent.
- Not a compliance certification. A Shield report does not make anyone HIPAA, SOC 2 or PCI compliant and will never be presented as if it does.
- Point in time. A clean report describes the day it was run. It is not a guarantee about tomorrow, and it never claims to be.
- Volunteers are trained and supervised before they touch a client system, and a supervisor reviews every report before it is delivered.
Honest Status
What's real, and what isn't.
What's real
The scanner exists and works. DIRA v1.1.0 is MIT-licensed and zero-dependency, with six scanners, SBOM output in CycloneDX and SPDX, safe auto-remediation, diff-based gating and 37 passing tests. The technical capability behind this program is not hypothetical.
What isn't
Zero audits have been delivered. No client org has signed anything, the engagement-letter template has not been reviewed by an attorney, no volunteers are trained, no supervision structure exists, and the parent organization is not incorporated or insured. Nothing in this program can start before those are real.
Year-one targets (targets, not results)
- Target: an attorney-reviewed engagement letter template, before the first client conversation.
- Target: a trained and supervised volunteer bench, drawn from CodeBridge graduates.
- Target: nonprofits audited, and critical findings remediated — the count only moves when something is actually fixed.
Get Involved
What would actually help.
A security professional willing to supervise student volunteers, and an attorney willing to review the engagement letter. Those two unblock everything else. If you run a small nonprofit and want to be first in the queue, say so now.
Miftah Foundation is not yet incorporated and has not applied for recognition of exemption under section 501(c)(3). No application is pending. Contributions are not tax-deductible.