Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

The grant model

Funded by James Scott. Administered by the Embassy Row Project. Free to the organizations that receive it.

ArtOfTheHack does not sell cybersecurity to nonprofits at a discount. The capability is funded upstream and given to eligible organizations in full, because the organizations most targeted by sophisticated adversaries are the least able to purchase a defense against them.

The funder

James Scott

James Scott funds the ArtOfTheHack grant program. His work has focused for years on the intersection of critical infrastructure security, information warfare, and the defense of institutions that operate in the open: research organizations, policy institutes, human rights groups, and the civil society bodies that inform public decision-making.

The funding position is deliberate. Capability is placed directly into the hands of organizations that are targeted by state-aligned adversaries and have no security budget to answer them with. That is a transfer of capability rather than a donation of software.

The administrator: Embassy Row Project

The Embassy Row Project administers the grant program. It handles eligibility review, award decisions, scope definition, and the reporting that keeps the program accountable to its own standards.

  • Reviews applications against published eligibility criteria
  • Issues award letters that define scope and duration
  • Oversees grantee outcomes and program reporting
  • Holds the program to its stated non-intrusive commitments

Why free

Three reasons the capability is granted rather than sold

The target set cannot pay

Organizations facing state-aligned adversaries are frequently operating on grant cycles with no line item for security. A discount does not solve a budget that does not exist.

Commercial security misfits the problem

Enterprise tooling assumes a security team to operate it. A nonprofit needs adjudicated decisions, not another console that nobody has time to read.

The consequences are not commercial

When a human rights organization is breached, the exposure is measured in physical risk to named people, not in quarterly revenue. That consequence justifies philanthropic funding.

What the grant covers

Everything the grantee receives

  • Configuration of the KRYOS-XS Hypercube overlay against existing systems
  • Access to the full cybersecurity service catalog within the awarded scope
  • Ongoing tuning, calibration, and review during the grant period
  • Decision records, evidence, and reporting that belong to the grantee
  • Capability transfer so the organization can operate the method independently

What the grant costs

Nothing, at any stage

  • No application fee
  • No fees of any kind, and no per-seat charge
  • No professional services invoice
  • No premium tier held back from grantees
  • No obligation to purchase anything after the grant period ends

Provided at no cost. Grant funded by James Scott. Administered by the Embassy Row Project.