Contents
- Purpose
- Methodology
- Governance & Sensitive Documents
- Personnel & PII Exposure
- Financial Documents
- Wayback Machine Archive
- Certificate Transparency
- Funding & Contract Records
- Legal & Regulatory Records
- Infrastructure & Technical Surface
- Disaster & Environmental
- Media & Public Narrative
- Risk Summary
- Recommendations
- What This Means
Purpose
This audit maps the publicly indexed digital footprint of Four Bands Community Fund across federal agency databases (CDFI Fund, EDA, USDA, FEMA, EPA), nonprofit transparency portals (ProPublica, Charity Navigator, GuideStar), certificate transparency logs, the Wayback Machine, and the entity's own web properties.
What can anyone with a search engine learn about your organization in 30 minutes?
For a Native CDFI managing $53M+ in cumulative lending, leading a $45M federal coalition, and holding seats on the Federal Reserve Board and USDA Equity Commission, the answer to that question has implications for donor confidence, regulatory relationships, and the communities you serve. This audit identifies what is exposed, where it lives, and what it reveals when assembled.
Methodology
The following public data sources were queried using only standard search tools and publicly accessible APIs. No unauthorized access was performed or attempted.
- Advanced search operators — Targeted searches across federal agency domains (cdfifund.gov, eda.gov, rd.usda.gov, epa.gov, fema.gov, federalregister.gov), nonprofit data portals, and the entity's own domain
- Wayback Machine CDX API — Historical page and document archival analysis for fourbands.org
- Certificate Transparency (crt.sh) — SSL/TLS certificate issuance history and subdomain discovery
- DNS interrogation — A, MX, NS, TXT, CNAME records for domain infrastructure mapping
- FEMA, USGS, EPA databases — Disaster declarations, environmental monitoring, and regulatory records
- News and media search — Coverage across tribal media, philanthropy publications, congressional records, and local outlets
Governance & Sensitive Documents
| # | Document | Hosted On | Risk | Notes |
|---|---|---|---|---|
| 1 | EDA Build Back Better Concept Proposal Narrative | eda.gov | MEDIUM | Full strategic proposal revealing partnership plans, priorities, and coalition structure for $45M award |
| 2 | CDFI Fund Case Statement | cdfifund.gov | LOW | Hosted as a model example for other Native CDFIs — intentional publication by the funder |
| 3 | CDFI Fund Impact Story: Thinking Local | cdfifund.gov | LOW | Feature profile on business growth support programs |
| 4 | CDFI Fund Impact Story: Making Waves | cdfifund.gov | LOW | Financial literacy program featured |
Assessment: LOW
No confidential, internal, or restricted documents were found indexed on any domain. The EDA concept proposal is the most substantive third-party-hosted document. The CDFI Fund documents are positive and intentional.
Personnel & PII Exposure
No results. Zero employee rosters, phone directories, org charts, or member lists found in any file format.
Assessment: CLEAN
Financial Documents
| # | Document | Hosted On | Risk | Notes |
|---|---|---|---|---|
| 1 | ProPublica Nonprofit Explorer — Full 990 filings | propublica.org | LOW | All Form 990 filings from 2001 to present. Revenue ~$6M FY2022, executive compensation $139K |
| 2 | Charity Navigator — 4-Star Rating (95%) | charitynavigator.org | LOW | Top-tier nonprofit rating with financial breakdown |
| 3 | GuideStar/Candid Profile | guidestar.org | LOW | Organizational transparency profile |
| 4 | Cause IQ Financial Trends | causeiq.com | LOW | Multi-year financial trend data |
Assessment: LOW
Financial exposure is entirely through legally required nonprofit transparency channels. The 4-star Charity Navigator rating and modest executive compensation are positive signals.
Wayback Machine Archive
| Metric | Value |
|---|---|
| Total unique pages archived | 4,869 |
| Total unique PDFs/documents archived | 156+ |
| Earliest snapshot | 2002-06-20 |
| Most recent snapshot | 2026-04-07 |
| Hosting platform detected | WordPress (migrated from static HTML circa 2017) |
Notable Archived Documents
| # | URL | Type | Notes |
|---|---|---|---|
| 1 | 2006 Audited Financial Statements | Full audited financials — sensitive | |
| 2 | 2009 Audit | Full audit — sensitive | |
| 3 | Vogel Congressional Testimony (Jan 2022) | Senate Banking Committee testimony | |
| 4 | Banking Testimony (Nov 2011) | Financial services testimony | |
| 5 | CRA Testimony — Fiddler (2010) | Community Reinvestment Act testimony | |
| 6 | Restoring Self-Determination | Policy/advocacy paper | |
| 7 | Customer Intake Packet (Fillable) | Fillable loan intake form with field structure | |
| 8 | Investor Loan Application | DOC | Word format — may contain document metadata |
Additional archived content: 30+ individual entrepreneur profiles (personal names and business details of CRST community members), Making Waves financial literacy materials, Chamber of Commerce materials, job postings, legacy static HTML pages from 2002.
Assessment: MEDIUM-HIGH
The Wayback Machine preserves a 24-year corpus with the most significant items being audited financial statements and individual entrepreneur profiles. WordPress plugins include revslider and js_composer, which have had significant historical vulnerabilities.
Certificate Transparency
| Property | Value |
|---|---|
| Total certificates found | 22 |
| Certificate issuer(s) | Go Daddy Secure Certificate Authority - G2 |
| Earliest certificate | 2017-06-09 |
| Most recent certificate | 2026-02-24 |
| Wildcard certs? | No |
| Renewal pattern | Mixed — apex annual, pay subdomain ~90-day rotation |
Subdomains Discovered
| # | Subdomain | First Seen | Notes |
|---|---|---|---|
| 1 | fourbands.org / www.fourbands.org | 2017-06-09 | Primary site, annual renewal |
| 2 | pay.fourbands.org | 2025-05-05 | Payment portal, 90-day cert rotation — likely PCI-DSS compliant |
| 3 | point.fourbands.org | 2021-10-08 | DNS no longer resolves — may be decommissioned |
Assessment: LOW
Three subdomains, all through GoDaddy, with no wildcard certificates and no evidence of shadow IT.
Funding & Contract Records
| # | Record | Source | Amount | Agency / Funder | Notes |
|---|---|---|---|---|---|
| 1 | Build Back Better Regional Challenge | EDA | ~$45M (coalition) | U.S. Commerce / EDA | Lead/fiscal sponsor of 9-CDFI coalition |
| 2 | CDFI Fund NACA Awards (11 awards) | CDFI Fund | $4.6M+ cumulative | U.S. Treasury | Since 2001 |
| 3 | CDFI Fund ERP Award | CDFI Fund | $1.5M | U.S. Treasury | Equitable Recovery Program |
| 4 | USDA Native American Relending Pilot | USDA Rural Dev. | $3M (2022) | USDA | Section 502 mortgage relending |
| 5 | Bush Foundation grants | Bush Foundation | Undisclosed | Private | Including Bush Prize for Community Innovation (2013) |
| 6 | Northwest Area Foundation | NWAF | Undisclosed | Private | Long-term partner |
| 7 | Robert Wood Johnson Foundation | RWJF | Undisclosed | Private | 2024 coalition research |
| 8 | Yield Giving (MacKenzie Scott) | Yield Giving | Undisclosed | Private | Gift recipient |
| 9 | Trust for Civic Life | Trust for Civic Life | Undisclosed | Private | Current grantee |
| 10 | FHLB Des Moines / Sunrise Banks (2026) | FHLB | Share of $122,500 | Federal/Banking | March 2026 matching grant |
Assessment: LOW
The funding portfolio is fully reconstructable from public sources. The organization operates as a single 501(c)(3) with no hidden subsidiary structures.
Legal & Regulatory Records
Legal Entity Registration
| # | Resource | Source | Notes |
|---|---|---|---|
| 1 | ProPublica — EIN 46-0456528 | IRS / ProPublica | 501(c)(3), NTEE code S30, incorporated 2000 |
| 2 | GovTribe Vendor Profile | SAM.gov | Registered federal vendor |
| 3 | SD Dakota At Home Listing | South Dakota | State social services directory |
Litigation: None found. Zero cases across Justia, CourtListener, JudyRecords, and general web search.
Regulatory: Active CDFI certification with "Policy Plus" distinction. Case statement hosted by CDFI Fund as exemplar. Compliant with federal Single Audit requirements.
Assessment: CLEAN
An exceptionally clean legal and regulatory profile. Zero litigation, 95% Charity Navigator score, and model CDFI status.
Infrastructure & Technical Surface
DNS Configuration
| Record | Value | Significance |
|---|---|---|
| A | 198.12.235.156 | GoDaddy shared hosting |
| MX | fourbands-org.mail.protection.outlook.com | Microsoft 365 for email |
| NS | ns41.domaincontrol.com, ns42.domaincontrol.com | GoDaddy DNS |
| TXT (SPF) | v=spf1 include:spf.protection.outlook.com include:spf.mandrillapp.com include:_spf.salesforce.com -all | Hard fail SPF — authorizes Outlook, Mandrill, Salesforce |
Infrastructure Profile
| Property | Value |
|---|---|
| Hosting platform | GoDaddy shared hosting (Apache) |
| CMS | WordPress 6.8.1 |
| PHP version | 7.4.33 (EOL since November 2022) |
| Email provider | Microsoft 365 (Exchange Online) |
| CRM | Salesforce |
| Transactional email | Mandrill (Mailchimp) |
| CDN/Proxy | None |
| Security headers | None (missing HSTS, X-Frame-Options, CSP) |
Assessment: MEDIUM
The organization invests in business-tier SaaS (M365, Salesforce) but runs WordPress on end-of-life PHP with no security headers or CDN layer.
Disaster & Environmental
FEMA Declarations Affecting Service Area
| # | Declaration | Date | Type | Notes |
|---|---|---|---|---|
| 1 | FEMA-4842-DR | 2024-11-01 | Severe storms, straight-line winds, flooding | Tribal declaration; SBA disaster loans triggered |
| 2 | EM-3536 | 2020-03-13 | COVID-19 Pandemic | Emergency assistance through May 2023 |
| 3 | FEMA-4440-DR-SD | 2019-06-07 | Severe winter storm, flooding | Dewey & Ziebach Counties designated |
| 4 | FEMA-4186-DR-SD | 2014 | Severe storms, tornadoes, flooding | Both counties designated for Public Assistance |
| 5 | FEMA-2337 | 2009 | Severe storms, flooding | Both counties among 14 declared |
EPA Records
| # | Record | Notes |
|---|---|---|
| 1 | Cheyenne River Basin Superfund Site | Mercury and heavy metals from Black Hills mining |
| 2 | Landfill Fire Superfund actions | On-reservation removal actions |
| 3 | Eagle Butte Wastewater NPDES Permit | Three waste stabilization ponds, 67.4 acres |
| 4 | Air Quality Monitoring ($406K) | PM2.5, trace metals, mercury vapor monitoring |
Assessment: MEDIUM-HIGH
The Cheyenne River Sioux Reservation has recurring disaster exposure and environmental challenges that directly affect Four Bands' borrowers and service area.
Media & Public Narrative
Key Coverage
| # | Article | Date | Publication | Key Points |
|---|---|---|---|---|
| 1 | Matching grants for SD nonprofits | 2026-03 | DRGNews | FHLB Des Moines grants |
| 2 | 25th Anniversary celebration | 2025 | Lakota Times | Employment rose from 49.2% to 51.3% on reservation |
| 3 | Data transforms Indigenous finance | 2024-08 | Sweet Grass Consulting | Data sovereignty presentation at Housing Summit |
| 4 | Rewriting the rules | 2022 | ImpactAlpha | $5.5M annual lending, 1% delinquency, 57% female business owners |
| 5 | $45M coalition award | 2022-09 | U.S. Commerce Dept | Largest single investment in Native CDFI industry |
Leadership
| # | Name | Role | Notes |
|---|---|---|---|
| 1 | Lakota Vogel | Executive Director (since 2015) | Federal Reserve Bank of Minneapolis Board. USDA Equity Commission. Senate Banking Committee testimony. |
| 2 | Stewart Sarkozy-Banoczy | Founder / Board Vice Chair | Founding ED (1999-2002). Now CEO of World Ocean Council. |
| 3 | Tanya Fiddler | Former ED / Co-founder | First Executive Director of Native CDFI Network. |
Assessment: CLEAN
Uniformly positive public narrative. Exceptional institutional credibility through executive director's board appointments and congressional testimony.
Risk Summary
Scorecard
| Category | Assessment | Key Finding |
|---|---|---|
| Governance & Documents | LOW | One strategic document on EDA servers |
| Personnel & PII | CLEAN | No PII exposure detected |
| Financial Documents | LOW | Standard nonprofit transparency through 990 filings |
| Wayback Archive | MEDIUM-HIGH | 156+ PDFs including audited financials and entrepreneur profiles |
| Certificate Transparency | LOW | 3 subdomains, narrow surface, no shadow IT |
| Funding & Contracts | LOW | Fully reconstructable portfolio; no hidden structures |
| Legal & Regulatory | CLEAN | Zero litigation; model CDFI status |
| Infrastructure | MEDIUM | PHP 7.4.33 EOL; no security headers |
| Disaster & Environmental | MEDIUM-HIGH | 5+ FEMA declarations; Superfund exposure |
| Media & Narrative | CLEAN | Universally positive; exceptional leadership credibility |
Recommendations
Immediate Actions
- Upgrade PHP to a supported version. PHP 7.4.33 has been end-of-life since November 2022. Upgrade to PHP 8.2+ or migrate to managed WordPress hosting.
- Add security headers. Configure HSTS, X-Frame-Options, X-Content-Type-Options, and Content-Security-Policy.
- Audit WordPress plugins. Ensure revslider, js_composer, and all 16 detected plugins are current. Remove unused plugins.
- Resolve orphaned subdomain.
point.fourbands.orghas certificate history but no DNS resolution. - Review Wayback Machine exposure. Consider whether the 2006/2009 audited financial statements warrant a takedown request.
Ongoing Monitoring
- Set up Google Alerts for "Four Bands Community Fund" to track new third-party indexing.
- Periodically audit wp-content/uploads/ for unintentionally public documents.
- Monitor certificate transparency logs for unexpected certificate issuance.
Strategic Considerations
- Consider a CDN layer. Cloudflare (free tier) adds DDoS protection and security headers with zero migration.
- Domain authority. Consider whether a .nsn.gov domain would better reflect institutional standing.
- Entrepreneur profiles. The 30+ archived PDFs naming community members represent a data stewardship consideration.
What This Means
Donor and grant transparency means your funding portfolio, tax filings, and program outcomes are publicly assembled in ways that shape how funders and the public perceive your organization. For Four Bands Community Fund, this transparency is overwhelmingly a strength — a 4-star Charity Navigator rating, a model case statement hosted by your federal regulator, Senate testimony, and a Federal Reserve board appointment all tell a story of institutional excellence. The areas requiring attention are technical (an aging web platform) and historical (archived documents from an earlier era of the organization's web presence). Neither undermines the strong public narrative — but both are worth addressing to match the organization's infrastructure to its institutional standing.