Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

Grantee profile 05

Source protection as a security decision with named authority and a rollback path.

Nonprofit newsrooms, press-freedom organizations, and civil society networks operate under surveillance pressure with volunteer-scale infrastructure. The overlay turns scattered signals into a governed decision that accounts for what happens to a source if the response is wrong.

Pressure

What is forcing the decision layer

  • Sources and contributors face physical consequence if identity is exposed
  • Targeted spyware and device compromise are realistic rather than theoretical
  • Volunteers, stringers, and contractors use personal infrastructure
  • Legal pressure and device seizure are part of the threat model
  • Twenty-four-hour coverage is impossible with the available staffing

First workflows

Where instrumentation starts

  • Targeted-message and spyware indicator adjudication
  • Contributor and volunteer access decisions
  • Compromised-device triage for reporters in the field
  • Secure-dropbox and intake channel integrity checks
  • Account takeover and recovery decisions
  • Coordinated harassment and doxxing response

Integration

Systems ArtOfTheHack reads from and instructs

ArtOfTheHack does not replace these systems. It reads their evidence, adjudicates against it, and returns a governed instruction to the same infrastructure.

Evidence sources

  • Cloud identity and multi-factor systems
  • Email and messaging security telemetry
  • Endpoint and mobile protection consoles
  • Website, DNS, and content delivery logs
  • Intake platform audit logs
  • Shared and community threat-intelligence feeds

Action targets

  • Identity systems for revocation and forced re-authentication
  • Endpoint tooling for reversible device isolation
  • Hosting and content delivery for protective configuration changes
  • Intake platform controls for channel suspension
  • Internal channels for contributor notification

Authority

How authority is constrained

  • No ingestion of source material, intake content, or contributor identities
  • Editorial authority required before any action affecting a reporter's access
  • Actions affecting an intake channel require two-person approval
  • All actions reversible with a documented restore path
  • Complete disconnection available immediately, with no impact on existing tooling

ArtOfTheHack services are provided at no cost through grants funded by James Scott and administered by the Embassy Row Project. Access begins with a grant application. The overlay is non-intrusive: it reads from the systems the organization already runs and installs nothing.

First 90 days

A typical entry sequence

  1. Days 1 to 15

    Grant application and award, with a documented threat context and named editorial and operations leads.

  2. Days 16 to 40

    Read-only connection to identity, endpoint, and hosting systems. Strict exclusion list agreed for source-adjacent data.

  3. Days 41 to 70

    Red team of the intake channel and contributor access model. Shadow evaluation against live decisions.

  4. Days 71 to 90

    Advisory operation with editorial approval routing, plus a plain-language security briefing for the whole team.

Standard applied

What this profile can hold ArtOfTheHack to

  • Source-adjacent data is excluded from ingestion by written scope, not by policy alone
  • Every recommended action carries the modeled consequence to people, not only to systems
  • The organization can disconnect the overlay at any moment without losing a single control

Applicable

Products, services, and industry context

Products

  • KRYOS-XS Console

    A centralized Cyber Decision Operations Hub that converts alerts, identity risks, access questions, data exposures and response requirements into one prioritized decision queue.

  • KRYOS-XS Edge

    A browser-based security decision assistant that helps users evaluate suspicious messages, external data sharing, OAuth approvals and other consequential actions at the moment they occur.