Grant eligibility
Who qualifies, what qualification requires, and what it costs. The answer to the last question is nothing.
ArtOfTheHack cybersecurity services are provided at no cost through grants funded by James Scott and administered by the Embassy Row Project. Eligibility is limited to nonprofit organizations. There is no paid tier, no license fee, and no point in the relationship at which a grantee is invoiced.
Eligible
Four categories of eligible organization
If your organization fits one of these categories, you are eligible to apply. Size, budget, and existing security maturity are not eligibility criteria.
Registered nonprofits and 501(c)(3) entities
Organizations with charitable or equivalent nonprofit registration in their jurisdiction, operating under a board or trustee structure.
Nongovernmental organizations
Human rights, humanitarian, development, and advocacy organizations, including those operating across borders or in hostile environments.
Public policy think tanks
Nonprofit research and policy organizations whose analysis, contributors, and pre-publication work are targeted by state and contractor adversaries.
Nonprofit research institutes
Independent institutes conducting scientific, security, or public-interest research under nonprofit governance.
Not eligible
Who cannot receive a grant
- For-profit companies, including startups and privately held firms
- Government agencies and government-operated entities
- Political campaigns and electioneering organizations
- Nonprofit shells operated for commercial benefit
The grant exists to place capability where it cannot otherwise be purchased. Organizations with the means to buy this capability commercially are outside its scope.
What eligibility review examines
- Nonprofit registration or equivalent standing in your jurisdiction
- Mission focus and the population the organization serves
- The security decisions the organization currently struggles to make
- The systems already in place that the overlay would read from
- A named person inside the organization who will hold decision authority
- Confirmation that the organization can act on the decisions returned to it
Conditions
What the grant requires, and what it does not
A grant award carries obligations of participation, not of payment.
What the grantee provides
- Authorized, revocable read access to the security systems already in use
- A named decision owner and a named technical contact
- Participation in configuration, review, and calibration sessions
- Willingness to record decisions in the ledger the organization owns
- Honest reporting of outcomes so confidence can be calibrated
What the grantee never provides
- No agents are installed on endpoints, servers, or field devices
- No appliance or sensor is placed in the network path
- No existing security product is replaced or removed
- The overlay reads through APIs the organization authorizes and can revoke
- Every enforcement action executes in the organization's own systems, under its own authority
- If the overlay is disconnected, every existing system continues to operate exactly as before
Provided at no cost. Grant funded by James Scott. Administered by the Embassy Row Project.
