Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

ArtOfTheHack Cybersecurity Grant Program

Five grant tiers, all delivered at no cost to the grantee.

Awards move in one direction: understand the decision, validate it in read-only shadow mode, then operate it under the organization's own policy and authority. Each tier has a defined deliverable set and defined eligibility.

What is the ArtOfTheHack cybersecurity grant program?

The ArtOfTheHack cybersecurity grant program gives approved nonprofit organizations access to cybersecurity technology and services at no cost within the award scope. Grants are funded by James Scott and administered by the Embassy Row Project. They are awards of capability, not cash transfers, and submitting an application does not guarantee approval.

Who can apply
Registered nonprofits and 501(c)(3) entities, NGOs, public policy think tanks, nonprofit research institutes, foundations, and civil society or nonprofit journalism organizations. Eligibility detail is on the eligibility page.
Who funds it
James Scott funds the grants personally. No grantee, donor, or vendor pays for the awarded scope.
Who manages it
The Embassy Row Project manages the cybersecurity grant program, including intake review, award scope, and reporting.
Is there a cost
No. There is no fee, license charge, or match requirement for services inside the awarded scope. Work outside that scope is agreed separately before it begins.
Is it a cash grant
No. A grant awards access to the KRYOS-XS Hypercube overlay and the associated cybersecurity services. Funds are not paid to the organization.
How access is deployed
Through read-scoped API connections to the systems the organization already runs, starting in read-only shadow mode. No agents are installed and no enforcement path is taken over.
Does applying guarantee approval
No. Applications are reviewed against eligibility, mission risk, and available capacity. Organizations that are not awarded are told why.
Next step
Review eligibility, then submit an application describing one consequential security decision your team currently makes without enough evidence.

Progression

Five grant tiers

Each tier is scoped against defined deliverables rather than open-ended effort, and no tier carries a cost to the organization receiving it.

Grant tier 01

Rapid Posture Review Grant

Fully funded. No cost to the grantee.

Two to four weeks

Give a small nonprofit an honest picture of its security decision surface in weeks, not quarters.

A short, remote review of where consequential security decisions are made, what evidence supports them today, who holds authority, and which workflow should be instrumented first. Delivered through document review and read-only API discovery against the systems the organization already runs.

Deliverables

  • Inventory of existing security and identity systems
  • Map of who decides and who approves security actions today
  • Evidence-quality review covering provenance, freshness, and independence
  • Adversarial red-team summary of the current architecture
  • Read-only integration design for the KRYOS-XS overlay
  • Ranked first-workflow recommendation
  • Board-readable summary in plain language

Eligibility note

Entry tier for organizations with fewer than fifty staff or no dedicated security personnel.

Precondition

Nonprofit, NGO, think tank, or nonprofit institute status and one named internal point of contact.

Grant tier 02

Foundation Overlay Grant

Fully funded. No cost to the grantee.

Eight to twelve weeks

Connect the non-intrusive overlay in read-only mode and prove its value in shadow operation.

The KRYOS-XS API overlay is attached to the organization's existing identity, endpoint, cloud, and email security systems. It evaluates real security decisions in parallel with current practice and executes nothing.

Deliverables

  • Read-only API connection to three to six existing systems
  • Historical replay against closed incidents and access requests
  • Live shadow evaluation alongside current practice
  • Governed decision records with cryptographic audit hashes
  • Dimensional geometric correlation across previously separate consoles
  • Contradiction and evidence-quality reporting
  • Advisory-mode recommendations to named internal staff

Eligibility note

Standard award for organizations running mainstream cloud identity and endpoint tooling.

Precondition

A completed Rapid Posture Review or equivalent internal documentation, plus read-only API credentials issued by the organization.

Grant tier 03

Full Overlay Grant

Fully funded. No cost to the grantee.

Twelve-month renewable award

Operate governed security decisioning in production under the organization's own policy and authority.

The validated workflow moves into approval-gated operation. Bounded automation is extended only to reversible action classes, and only after a rollback path has been demonstrated inside the grantee environment.

Deliverables

  • Production overlay tenancy under the grant
  • Connectors for the grantee environment
  • Policy and authority configuration written by the grantee
  • Approval routing aligned to existing internal governance
  • Digital twin of the environment for response simulation
  • Monte Carlo scenario ranges attached to consequential decisions
  • Action gateway with enforced reversibility checks
  • Staff training and outcome calibration

Eligibility note

Awarded to organizations that completed shadow evaluation and have a named internal decision authority.

Precondition

A completed Foundation Overlay Grant with measured shadow results.

Grant tier 04

High-Risk Mission Grant

Fully funded. No cost to the grantee.

Twelve to thirty-six months

Support organizations facing nation-state targeting, transnational repression, or physical risk to staff and sources.

A hardened award profile for human rights organizations, investigative research institutes, and NGOs operating in hostile environments, where the identity of a source or a field worker is the asset an adversary is trying to reach.

Deliverables

  • Dedicated private tenancy or grantee-controlled deployment
  • Grantee-held encryption keys
  • Strict data minimization with no beneficiary or source data ingestion
  • Extended adversarial red teaming against targeted-threat scenarios
  • Travel, field-device, and off-network decision playbooks
  • Segregated model environments and extended audit retention
  • Priority response coverage

Eligibility note

Reserved for documented elevated-threat missions. Reviewed case by case by the Embassy Row Project.

Precondition

Documented threat context and a named security or operations lead.

Grant tier 05

Coalition and Sector Grant

Fully funded. No cost to member organizations.

Annual, renewable

Extend one award across a network of allied nonprofits that share adversaries and infrastructure.

Funders, associations, and umbrella bodies can sponsor a shared overlay across their grantee network, so a threat observed at one organization improves the decision quality available to the others without sharing any organization's underlying data.

Deliverables

  • Shared threat and decision-pattern layer across member organizations
  • Per-organization tenancy isolation with no cross-tenant data access
  • Sector-level red teaming and exposure prioritization
  • Coordinated incident adjudication across member organizations
  • Aggregate reporting for the sponsoring body with no member data disclosure
  • Shared staff training and onboarding for member organizations

Eligibility note

Sponsored through a single award to the coalition, association, or funder network.

Precondition

A sponsoring nonprofit body and at least three eligible member organizations.

Every tier is delivered at no cost to the grantee. Grants are funded by James Scott and administered by the Embassy Row Project. Award decisions depend on eligibility, mission risk, and available grant capacity, and nothing is owed by the organization at any stage.

Variables

What determines an award

Two organizations with the same headcount can receive very different awards. These are the variables the review weighs.

  • Nonprofit, NGO, think tank, or nonprofit institute status
  • Mission risk and adversary profile
  • Populations, sources, or researchers placed at risk by a breach
  • Number and type of existing security systems available for read-only connection
  • Presence of any internal security or IT staffing
  • Number of decision workflows in scope
  • Jurisdictions of operation and data-residency constraints
  • Named internal authority for approving security actions
  • Coalition or single-organization award
  • Available grant capacity in the current funding cycle

Discipline

What we decline to fund

  • No grantee is ever invoiced, upsold, or moved to a paid tier
  • No grantee data is sold, brokered, licensed, or used to train models for other parties
  • Awards are declined where the work would not materially reduce risk to the mission
  • Awards are declined where the applicant is not a nonprofit, NGO, think tank, or nonprofit institute
  • Work outside cybersecurity is out of scope and is referred elsewhere

Awards are annual and renewable. Decision processing, read-only connectors, sector policy packs, dedicated deployment, and managed assurance are all covered inside the grant. The organization is never invoiced for the overlay, its connectors, or its usage.

What the grant covers

Everything Required to Run Governed Cybersecurity Decisions

Grant-funded access is not software alone. It covers assessment, deployment, configuration, training, reporting and continued capacity building.

Initial cybersecurity assessment

A review of the systems the organization runs, the people who use them and the risks that matter most to its mission.

Google Workspace connection

An authorized, least-privilege connection to the organization's Workspace tenant as the first evidence source.

KRYOS-XS Edge deployment

Rollout of the browser-based decision assistant across the work surfaces the organization approves.

KRYOS-XS Console configuration

Setup of the decision queue, ownership, priorities and reporting for the organization's structure.

Policy setup

Translation of the organization's written rules into the policy checks the platform applies.

Administrator and user training

Practical training for the people who will operate the Console and the staff who will see Edge verdicts.

Decision reporting

Reporting drawn from the real decision history for boards, funders and auditors.

Pilot measurement

Measurement of what changed during the pilot period, stated honestly, including what did not change.

Ongoing capacity building

Continued support so the organization builds its own decision capability rather than a dependency.

Grant funding is provided by James Scott and administered through the Embassy Row Project. ArtOfTheHack manages cybersecurity assessment, deployment and technical support.

Applying

What the application asks for, and what follows it

Nothing in the application requires access to your systems, and no technical connection exists until an award is made and your administrators authorize it.

Information requested

  • Organization legal name, website, nonprofit type, and country of operation
  • A contact name, role, and organization email address
  • Approximate number of people who would use the deployment
  • One consequential security decision your team currently makes without enough evidence
  • The systems you already run, such as Google Workspace, identity, or endpoint tooling
  • Any deployment or data-residency requirements your board or funders impose

After you submit

  • Acknowledgement that the application was received, with a named point of contact
  • Eligibility review against nonprofit status, mission risk, and current program capacity
  • A scoping conversation to confirm the first workflow, the systems involved, and the authorization required
  • An award decision with the tier and scope stated in writing, or a declined decision with the reason given
  • For awarded organizations, read-only shadow-mode deployment before any action capability is discussed

How your information is handled

  • Application information is used only to assess eligibility and scope an award
  • It is not sold, not used for advertising, and not shared outside the review and delivery teams
  • No access to your systems is requested or possible during the application stage
  • You can ask for your application to be deleted at any point before or after a decision

Delivery boundary

What Grant-Funded Access Includes and Excludes

Grant-funded access delivers an API-only intelligence layer over the systems your organization already runs. Your organization keeps ownership of those systems and can revoke the scoped credentials at any time.

Supported

What ArtOfTheHack uses

  • Approved work surfaces and authorized APIs
  • Inline decision support at the moment of action
  • Cross-source correlation of available evidence
  • Explainable recommendations with confidence and uncertainty
  • Approval-gated action in the organization's own systems
  • Complete decision logging in the KRYOS Decision Ledger
  • Outcome verification and board-ready reporting

Excluded

What ArtOfTheHack never uses

  • Replacement of existing security products
  • Unrelated personal browsing collection
  • Endpoint agents, appliances or packet capture
  • Independent malware detection
  • Hidden or unsupported data access
  • Autonomous consequential action
  • Claims a connected system cannot evidence

KRYOS does not claim evidence that a connected system cannot provide. When data is incomplete, the platform identifies the limitation and requests the appropriate human or technical input.

OEM and embedded

Structure for coalition sponsors and technology partners

Funders, associations, and mission-aligned technology partners can extend an award across a network through the following components.

Grant application

The organization submits an application describing its mission, nonprofit status, existing systems, and primary security concern.

Eligibility review

The Embassy Row Project confirms nonprofit status and reviews mission risk against current grant capacity.

Award and scope letter

The award names the grant tier, the systems in scope, the data that will and will not be read, and the duration.

Read-only connection

The organization issues read-only API credentials for the systems it selects. No agent is installed and no enforcement path changes.

Advisory operation

The overlay recommends. Named staff inside the organization decide. Nothing is executed automatically.

Renewal or exit

The grantee can renew, reduce scope, or disconnect at any time. On disconnection every existing system continues to operate unchanged and the audit record is exported to the grantee.