Oahe Data

Digital Footprint Audit

American Indian Science and Engineering Society (AISES)
Date: 2026-04-11 Entity Type: Nonprofit Audit Type: Public Index Reconnaissance

Contents

Purpose

This audit maps the publicly indexed digital footprint of the American Indian Science and Engineering Society (AISES) across federal agency databases, certificate transparency logs, the Wayback Machine, IRS nonprofit filings, foundation directories, court records, and the entity's own web properties.

What can anyone with a search engine learn about your organization in 30 minutes?

For a nonprofit of AISES's scale ($19M revenue, 7,000+ members, 200+ chapters), transparency is both a strength and an exposure surface. Donors, grantors, partners, and the public can reconstruct your funding portfolio, governance documents, leadership roster, and technology infrastructure from freely available sources. This audit shows what that picture looks like.

Methodology

The following public data sources were queried:

SourcePurpose
Search enginesAdvanced operator queries (site:, filetype:, intitle:) targeting aises.org and federal agency domains
Wayback MachineCDX API queries against aises.org and www.aises.org
Certificate Transparency (crt.sh)All certificates issued to aises.org subdomains
DNS recordsA, MX, NS, TXT, CNAME lookups for aises.org
USASpending.govFederal award recipient search
HHS TAGGSHealth and Human Services grant tracking
NSF Award SearchNational Science Foundation awards
ProPublica Nonprofit ExplorerIRS Form 990 filings
GuideStar/CandidNonprofit profile and EIN verification
BBB Wise Giving AllianceAccountability standards assessment
Federal RegisterRegulatory filings and sole-source notices
Court databasesJustia, CourtListener, JudyRecords
Native mediaIndianz.com, ICT News, Native News Online

No unauthorized access was performed or attempted. All data sources are publicly accessible.

Governance & Sensitive Documents

Queries used:

"AISES" OR "American Indian Science and Engineering Society" filetype:pdf "confidential" OR "internal"
"AISES" OR "American Indian Science and Engineering Society" filetype:pdf "resolution" OR "charter" OR "MOU"
"AISES" filetype:pdf "staff list" OR "phone directory" OR "org chart"
site:aises.org intitle:"index of"
site:aises.org inurl:backup OR inurl:admin OR inurl:config
"American Indian Science and Engineering Society" site:irs.gov
"American Indian Science and Engineering Society" site:federalregister.gov
#DocumentHosted OnRiskNotes
1IHS Sole-Source Cooperative Agreementfederalregister.govLOWOfficial IHS notice naming AISES as sole-source recipient
22023 Form 990aises.orgLOWSelf-hosted tax filing — intentional transparency
32022 Form 990aises.orgLOWSelf-hosted tax filing
42021 Audited Financialsaises.orgLOWSelf-hosted audit report
5AISES Bylaws (2016)Wayback / aises.orgLOWGovernance bylaws accessible via archive
6Bylaws Change ResolutionWayback / aises.orgLOWBoard resolution on bylaws amendment process
7Quorum Definition ResolutionWayback / aises.orgLOWBoard resolution on quorum rules

Assessment: LOW

No confidential or internal documents were found indexed on any domain. MOU references are all official government press releases. AISES self-hosts its 990 filings and audited financials, reflecting intentional transparency.

Personnel & PII Exposure

#DocumentHosted OnRiskNotes
1ZoomInfo Company Profilezoominfo.comMEDIUMData broker has assembled employee directory from scraped sources
2Wiza Company Profilewiza.coMEDIUMSecond data broker aggregating employee details

Assessment: MEDIUM

No CSV, XLSX, or PDF rosters of members or employees were found indexed. However, two data broker platforms have assembled employee directories from publicly scraped sources. Staff names, titles, and inferred contact details are aggregated and commercially available.

Financial Documents

#DocumentHosted OnRiskNotes
1ProPublica Nonprofit Explorerpropublica.orgLOWComplete 990 filing history; FY2024 revenue $18.97M
2Instrumentl 990 Reportinstrumentl.comLOW990 timeline with 14 active grant programs
3Cause IQ Profilecauseiq.comLOW69 employees; NTEE classification; financial summary
4USASpending Recipient Profileusaspending.govLOWFederal award recipient; UEI: XUE5YPEN3UZ9

Financial Trajectory (from 990 filings)

YearRevenueExpensesNet Assets
2024$18,970,849$13,288,390$9,259,281
2023$12,004,535$11,220,136$3,489,435
2022$9,273,961$9,794,112$2,595,016
2021$8,766,660$6,776,814$3,221,834
2020$5,717,062$5,696,593$1,210,975
2019$5,674,585$5,817,558$1,265,912
2018$5,010,011$4,700,230$1,505,583
2017$4,246,049$4,132,365$1,278,065
2016$3,262,638$3,259,135$1,152,059
2015$2,972,122$3,030,113$1,132,211

Assessment: LOW

Exemplary financial transparency. 990 filings from 2009–2024 are self-hosted and independently available through multiple nonprofit databases. Revenue has grown 6.6x from $2.9M to $19.0M over nine years. Material weakness in internal controls identified in recent audits.

Wayback Machine Archive

MetricValue
Total unique pages archived75,800+
Total unique PDFs archived~1,220
Earliest snapshot1998-12-12
Most recent snapshot2026-04-10
Platform historyColdFusion (2000s) → Joomla (~2008) → Drupal (~2012) → WordPress (current)

Notable archived content

#ContentTypeNotes
1990 Tax Filings (2009–2023)PDFComplete 14-year run across both CMS eras
2Audited Financial Statements (2009–2023)PDFFull decade+ of independent audit history
3Annual Reports (2005–2021)PDFOrganizational narrative and program data
4Board Governance DocumentsPDFBylaws, resolutions, tribal chapter code of conduct
5Drupal CHANGELOG.txtConfigRevealed exact CMS version during Drupal era
6Drupal install.phpConfigInstaller script was publicly accessible
7Gallery2 Photo Gallery (~928 pages)ApplicationRetired photo gallery with extensive archive
8ColdFusion Member Login PortalLoginLegacy member authentication from 2005 era
9Winds of Change Media KitPDFMagazine advertising rates and readership data
10Historical Scholarship Applications (2003–2006)PDFArchived application forms from early programs

Assessment: MEDIUM-HIGH

Exceptionally large Wayback footprint spanning 27 years. Four platform migrations are documented. The archive preserves the complete financial record, governance documents, and artifacts from retired platforms including CMS configuration files. The archive represents a deep historical record of the organization's digital evolution.

Certificate Transparency

PropertyValue
Total certificates found17
Certificate issuersLet's Encrypt (R12, R13, E7), GeoTrust, Google Trust Services, Amazon RSA
Earliest certificate2025-03-06
Most recent certificate2026-04-01
Wildcard certificatesNo
Renewal pattern90-day automated (Let's Encrypt) + commercial CAs for specific services

Subdomains discovered (20)

#SubdomainPurposeCertificate Issuer
1www.aises.orgMain websiteLet's Encrypt E7
2conference.aises.orgNational conference siteLet's Encrypt R13
3events.aises.orgEvent management (Aventri)Amazon RSA
4give.aises.orgDonation portal (Classy.org)Google Trust Services
5opportunities.aises.orgJob/scholarship boardLet's Encrypt R13
6resumes.aises.orgResume portalLet's Encrypt R12
7fairs.aises.orgCareer fairsLet's Encrypt R13
8forms.aises.orgWeb formsLet's Encrypt R12
9info.aises.orgMarketing (Pardot)Let's Encrypt R13
10nativelinks.aises.orgResource directoryLet's Encrypt R13
11photos.aises.orgPhoto gallery (Azure)GeoTrust
12secure.aises.orgMember portalLet's Encrypt R13
13woc.aises.orgWinds of Change magazineLet's Encrypt R13
14nfc.aises.orgConference (alt)Let's Encrypt R12
15old.aises.orgLegacy siteLet's Encrypt R12
16www.conference.aises.orgConference redirectLet's Encrypt R13
172021.aises.org2021 conference archiveLet's Encrypt R13
182022.aises.org2022 conference archiveLet's Encrypt R12
192023.aises.org2023 conference archiveLet's Encrypt R13
202025.aises.org2025 conference siteLet's Encrypt R12

Assessment: LOW

Well-managed automated certificate renewal. Subdomain inventory maps cleanly to known AISES programs. No wildcard certificates, no shadow IT indicators.

Infrastructure & Technical Surface

DNS Configuration

RecordValueSignificance
A192.0.78.213Automattic (WordPress.com managed hosting)
MXaises-org.mail.protection.outlook.comMicrosoft 365 email
NSns9.worldnic.com, ns10.worldnic.comNetwork Solutions (legacy registrar DNS)
TXT (SPF)7 includes (Outlook, Pardot, Informz, Neon, Aventri, WPCloud, Google)Complex email sender landscape

Infrastructure Profile

PropertyValue
Hosting platformWordPress.com (Automattic managed)
Domain type.org
Email providerMicrosoft 365
CDN/ProxyAutomattic a8c-cdn
DNS providerNetwork Solutions (legacy)
Marketing automationSalesforce Pardot
Hosting providers (total)6 distinct across subdomains
Security headersPartial (HSTS only; no CSP, X-Frame-Options, X-Content-Type-Options)

Assessment: MEDIUM-HIGH

Sprawling infrastructure with 6 distinct hosting providers across 20 subdomains. Main site is well-hosted on WordPress.com, but legacy subdomains sit on budget shared hosting. Network Solutions nameservers indicate legacy DNS. SPF record with 7 includes approaches DNS lookup limits. Year-specific conference subdomains accumulate without retirement.

Funding & Contracts

#RecordSourceAmountAgency
1USASpending Recipient Profileusaspending.govMultiple awardsMultiple
2HHS TAGGS Cumulative Awardstaggs.hhs.gov~$2,955,039NIH, IHS, ACF
3NSF Lighting the Pathway (Phase I & II)nsf.gov~$3,000,000NSF
4NSF/Kapor CS for Native Girlsnsf.gov$1,400,000NSF
5IHS Sole-Source Cooperative AgreementIHS~$745,000IHS
6ProPublica 990 Filingspropublica.org$18.97M (2024 rev)IRS

Revenue breakdown (2024): 93.5% contributions/grants ($17.7M), 5.6% program services ($1.05M), 1.2% investment income.

Assessment: LOW

Confirmed USASpending recipient profile. Substantial federal funding from NSF, HHS (NIH, IHS, ACF), DOE, and NASA. Revenue growth of 6.6x over nine years. Funding portfolio is largely reconstructable from public sources.

Litigation: Zero cases found across Justia, CourtListener, and JudyRecords. No lawsuits as plaintiff or defendant.

Regulatory Filings

#FilingSourceNotes
1IHS Sole-Source Cooperative AgreementFederal Register5-year sole-source award for AI/AN STEM workforce
2BIA Conference Promotionbia.govOfficial federal agency participation
3NIST Conference Participationnist.govFederal recruitment at AISES events

Governance Flags

#FindingSourceSeverity
1BBB Wise Giving Alliance: Does NOT meet standardsBBB/Give.orgMEDIUM
2Material weakness in internal controls (FY2024 audit)ProPublica / 990MEDIUM

Assessment: CLEAN

Exceptionally clean legal profile. Zero litigation. BBB accountability flags and audit findings are governance matters, not legal exposure.

Disaster & Environmental

Assessment: CLEAN

No FEMA declarations, EPA enforcement, or environmental monitoring records. AISES is a STEM education nonprofit, not a jurisdictional entity. Relevant environmental programming includes the Indigenous Knowledge Research Program (USDA partnership) and Environmental Science Associates scholarships.

Media & Public Narrative

Key Coverage

#ArticleDatePublicationKey Points
1National conference brings together Native scientists2025-10MPR News2025 conference in Minneapolis; thousands of attendees
2Native student program shuts down due to DEI orders2025-03Indianz.comAdjacent programs affected by anti-DEI executive orders
3ACS partner conferences community2026-01Chemical & Engineering NewsAISES highlighted as key ACS partner conference

Leadership Identified

#NameRoleSource
1Sarah EchoHawk (Pawnee)CEO/President since 2013AISES
2Michael Laverdure (Turtle Mountain Chippewa)Board Chair EmeritusAISES
3Lillian Sparks Robinson (Rosebud Sioux)Board Member (2025–2028)AISES
4Fawn Sanchez (Shoshone-Bannock)Board Member (2025–2028)AISES

Assessment: CLEAN

Overwhelmingly positive public narrative. $8.7M cumulative scholarships to 4,924 students. Emerging risk from anti-DEI executive orders affecting adjacent programs.

Risk Summary

Scorecard

CategoryAssessmentKey Finding
Governance & DocumentsLOWSelf-hosted financials, no confidential docs indexed
Personnel & PIIMEDIUMData broker profiles aggregate staff details
Financial DocumentsLOWExemplary transparency; complete 990 history
Wayback ArchiveMEDIUM-HIGH75,800+ pages, retired CMS config files
Certificate TransparencyLOW20 subdomains, well-managed, no shadow IT
InfrastructureMEDIUM-HIGH6 hosting providers, fragmented, minimal headers
Funding & ContractsLOWUSASpending profile confirmed; 5 federal agencies
Legal & RegulatoryCLEANZero litigation; BBB accountability flags
Disaster & EnvironmentalCLEANNo jurisdictional exposure
Media & NarrativeCLEANPositive coverage; DEI policy risk
Overall Footprint Assessment: SIGNIFICANT

AISES operates one of the more extensive digital footprints among Indigenous-serving nonprofits. Online since 1998, four CMS platform migrations, 20 subdomains across 6 hosting providers, and a complete public financial record spanning 14+ years. The footprint reflects organizational maturity more than security deficiency — but the infrastructure fragmentation and archive depth mean the information surface is larger than typical for an organization of this size.

Recommendations

Immediate Actions

1. Data broker cleanup — Submit removal requests to ZoomInfo and Wiza to reduce staff PII aggregation. Repeat annually.

2. Security header hardening — Add Content-Security-Policy, X-Frame-Options, and X-Content-Type-Options headers to the main site and all subdomains.

3. BBB disclosure completion — Respond to the 3 outstanding BBB Wise Giving Alliance information requests.

Ongoing Monitoring

1. Certificate transparency alerts — Subscribe to crt.sh alerts for aises.org to detect unauthorized certificate issuance.

2. Wayback monitoring — Periodically review new archived content for sensitive documents.

3. Subdomain inventory — Audit year-specific conference subdomains (2021–2023); decommission if no longer needed.

Strategic Considerations

1. Infrastructure consolidation — Consolidate legacy subdomains (HostGator, DreamHost) onto the Automattic platform.

2. DNS modernization — Migrate from Network Solutions to a modern DNS provider (Cloudflare, AWS Route 53).

3. SPF simplification — The 7-include SPF record approaches the DNS lookup limit. Audit and remove unused senders.

What This Means

Donor and grant transparency means your funding portfolio, tax filings, and program outcomes are publicly assembled in ways that shape how funders and the public perceive your organization. For AISES, this transparency is largely intentional and well-managed — your 990s, audited financials, and annual reports are self-hosted and clearly communicated. The areas where the footprint exceeds intentional disclosure are the infrastructure fragmentation (6 hosting providers make the technical surface harder to defend) and the depth of the Wayback archive (27 years of digital history, including retired CMS artifacts). These are not urgent risks but represent the accumulated surface area of an organization that has been a digital pioneer since 1998.