Oahe Data

Digital Footprint Audit

National Congress of American Indians
Date: 2026-04-11 Entity Type: Nonprofit Audit Type: Public Index Reconnaissance

Contents

Purpose

This audit maps the publicly indexed digital footprint of the National Congress of American Indians (NCAI) across federal agency databases, grant and contract registries, certificate transparency logs, legal and regulatory records, the Wayback Machine, and the entity's own web properties.

What can anyone with a search engine learn about your organization in 30 minutes?

For a national advocacy nonprofit representing 574+ federally recognized tribes, public transparency is both a strength and a risk. The question is not whether information is available — it is whether the organization understands the full scope of what is discoverable, who else is assembling it, and what decisions it enables them to make.

Methodology

Data sources queried:

Governance & Sensitive Documents

Queries used

"National Congress of American Indians" filetype:pdf "confidential" OR "internal" OR "not for distribution"
"National Congress of American Indians" filetype:pdf "resolution" OR "charter" OR "MOU" OR "agreement"
"NCAI" filetype:pdf "resolution" OR "budget" OR "audit"
"National Congress of American Indians" site:federalregister.gov
"National Congress of American Indians" site:congress.gov
site:ncai.org intitle:"login" OR intitle:"sign in" OR inurl:portal
#DocumentHosted OnRiskNotes
1NCAI resolutions (decades of records)ncai.org, congress.gov, bia.govLOWPublished intentionally as policy advocacy tools
2Congressional testimony PDFscongress.govLOW1,242+ testimony files archived; public record
3Federal consultation documentsncai.org, fema.gov, epa.govLOWFEMA, BIA, USDA, DOE consultation responses
4NCAI Constitution (2019, 2021)ncai.orgLOWGovernance framework publicly available
5Presidential Transition Plan (2009)ncai.org (archived)LOWPolicy recommendations for incoming administration
6CMS login page (BrowserCMS v3.3.4)cms.ncai.orgMEDIUMLegacy CMS with version disclosure; enables targeted research
7TIBC budget briefing presentations (.pptx)ncai.org (archived)LOWInternal budget presentations in Wayback archive

Assessment: LOW

Summary: NCAI's governance documents are widely distributed across .gov domains, consistent with their advocacy role. No confidential or internal documents were found on third-party servers. The one elevated finding is a legacy CMS login page at cms.ncai.org running BrowserCMS v3.3.4 with version disclosure.

Wayback Machine Archive

Domain queried: ncai.org

MetricValue
Total unique pages archived~92,393
Total unique PDFs/documents archived~19,200 (18,750 PDFs + 448 docx/xlsx/pptx)
Earliest snapshot1998-05-24
Most recent snapshot2026-04-10
Hosting platform detectedTYPO3 CMS (pre-2012) → Next.js (current)

Notable archived content

#ContentTypeNotes
1Next.js _next/data/ JSON endpointsAPIFull page data extractable as raw JSON
21,242+ congressional testimony filesPDFOrganized under /attachments/Testimonial_*
3Federal consultation policy documentsPDFFEMA, BIA, USDA, DOE responses
4Policy papers and rulemaking commentsPDFWOTUS, Lifeline/Link-up reform, DOI
5Budget advocacy toolkitsDOCXEditable Word documents at root-level paths
6TIBC budget briefingsPPTXMultiple fiscal years of internal presentations
7Resolution templatesDOCXInternal workflow documents
8Complete resolution archive (1,374 pages)HTMLDecades of tribal policy positions

Assessment: LOW

Summary: NCAI has an extraordinarily deep Wayback archive spanning 28 years with nearly 19,000 unique PDFs. The corpus represents a comprehensive legislative history of tribal advocacy positions. The ~448 non-PDF documents archived at root-level paths suggest historically loose file management. No admin panels, credentials, or config files were found.

Certificate Transparency

Domain analyzed: ncai.org

PropertyValue
Total certificates found8
Certificate issuersLet's Encrypt (R11, R12, R13, E8), Google Trust Services (WE1)
Earliest certificate2025-07-27
Most recent certificate2026-03-25
Wildcard certs?No
Renewal pattern90-day automated

Subdomains discovered via SANs

#SubdomainCert IssuerPurposeNotes
1ncai.orgLet's Encrypt R12Apex domain
2www.ncai.orgLet's Encrypt R12Main websiteVercel/Next.js
3updates.ncai.orgGoogle Trust Services WE1Email marketingHubSpot
4members.ncai.orgGoogle Trust Services WE1Membership portalHubSpot
5give.ncai.orgGoogle Trust Services WE1DonationsClassy.org
6auth.ncai.orgLet's Encrypt R13Authentication/SSOAuth0 (Okta)
7blog.ncai.orgLet's Encrypt E8BlogWordPress.com
8archive.ncai.orgLet's Encrypt R11Legacy contentCertificate expired Oct 2025

Assessment: LOW

Summary: NCAI operates a well-structured subdomain architecture with purpose-specific services. The expired certificate on archive.ncai.org indicates either intentional decommission or neglect. No wildcard certificates mean the full subdomain surface is visible in CT logs.

Funding & Contract Records

Queries used

site:usaspending.gov "National Congress of American Indians"
"National Congress of American Indians" 990 site:propublica.org/nonprofits
"National Congress of American Indians" site:candid.org
"National Congress of American Indians" site:govtribe.com

USASpending Profile: NCAI operates under two legal entities — NCAI Fund (501(c)(3), primary recent grant recipient) and NCAI of the United States and Alaska Inc (501(c)(4), historical recipient).

IRS 990 Financial Profile (501(c)(3) Fund)

YearRevenueExpensesNet Assets
2024$13,169,834$12,211,613$11,637,859
2023$9,076,259$10,188,135$14,640,346
2022$9,744,341$10,964,197$18,110,882
2021$10,230,979$11,765,633$22,096,750
2020$15,297,152$11,789,026$19,757,171

Source: ProPublica Nonprofit Explorer

Top Federal Awards

#AwardAmountAgencyProgram
1Tribal Victim Assistance Micro-Grant$13,000,000DOJVOCA
2T.R.A.I.L. Diabetes Prevention$8,408,708HHS/IHSDiabetes
3NARCH V Research Centers$2,375,958HHS/IHSResearch
4Native American Mentoring$2,353,583DOJYouth
5Strengthening Tribal Nations$1,179,226DOI/BIACapacity

Total federal awards on USASpending (2007–present): ~$46.9 million (25 grants + 17 contracts)

Foundation Funding

FoundationAmountProgram
W.K. Kellogg Foundation$26,000,000+Partnership for Tribal Governance
Ford Foundation4 grants since 2006Civic Engagement
Lumina Foundation$200,000Tribal Civics Education
Google.orgUndisclosedCenter for Tribal Digital Sovereignty
Northwest Area Foundation$300,000Strengthening Tribal Economies
Robert Wood Johnson Foundation~$300,000Leadership for Healthy Communities

Subsidiary Entities

EntityTypeEINRelationship
NCAI Fund501(c)(3)53-6017907Education/programmatic arm
NCAI501(c)(4)53-0210846Advocacy/membership org
NCAI Foundation501(c)(3)New (2023)Philanthropic arm
NCAI Policy Research CenterProgramUnder FundResearch division

Charity Navigator: 2 of 4 stars (63% overall score)

Assessment: LOW

Summary: NCAI's entire funding portfolio — $46.9M federal + $26M+ Kellogg Foundation — is publicly reconstructable. The dual 501(c)(3)/501(c)(4) structure is standard. The 501(c)(3) has run operating deficits in 3 of 4 recent years, and the 2-star Charity Navigator rating is worth noting.

Queries used

"National Congress of American Indians" site:law.justia.com
"National Congress of American Indians" amicus OR "amicus curiae"
"National Congress of American Indians" site:federalregister.gov
"National Congress of American Indians" site:congress.gov testimony

Legal Advocacy (Tribal Supreme Court Project)

NCAI operates the Tribal Supreme Court Project (est. 2001, joint with NARF), coordinating amicus strategy across 250+ tribal leaders, attorneys, and professors.

#CaseCourtOutcomeNotes
1Haaland v. Brackeen (ICWA)SCOTUSUpheld 7-221 briefs, 497 Tribal Nations
2Becerra v. San Carlos ApacheSCOTUSWonTribal contract support costs
3United States v. CooleySCOTUSUnanimousTribal law enforcement authority
4Michigan v. Bay MillsSCOTUSUpheldTribal sovereign immunity
5Apache Stronghold / Oak Flat9th CircuitPendingRFRA sacred site protection
6Landor v. Louisiana DOCSCOTUS (2025)PendingRLUIPA religious liberty

Litigation (NCAI as defendant)

#CaseTypeStatus
1Desiderio v. NCAIEmployment (D.C. Superior)Former CEO sued for $5M; no public resolution
2Dossett v. NCAIDefamation (Federal)Dismissed
3NAGA v. NCAIConspiracy (D. North Dakota)Dismissed with prejudice, Jan 2024

Regulatory Filings

#FilingSourceTopic
1FCC 2.5 GHz Tribal Priority WindowFederal RegisterTribal broadband spectrum
2NTIA National Spectrum StrategyNTIASpectrum access
3DOT Tribal Transportation Self-GovernanceDOTNegotiated rulemaking
4BIA Federal Acknowledgment (25 CFR Part 83)Federal RegisterTribal recognition reform

Assessment: CLEAN

Summary: NCAI's legal footprint reflects its role as the premier tribal advocacy organization: an extraordinarily active amicus program spanning landmark SCOTUS cases, deep regulatory engagement, and regular congressional testimony. The three lawsuits where NCAI was a defendant are internal governance or nuisance litigation, not indicators of misconduct.

Infrastructure & Technical Surface

Domain analyzed: ncai.org

DNS Configuration

RecordValueSignificance
A76.76.21.21Hosting: Vercel
MXaspmx.l.google.comEmail: Google Workspace
NSns55/ns56.worldnic.comDNS: Network Solutions (legacy)
TXT (SPF)v=spf1 include:_spf.google.com ~allSPF configured; soft-fail
TXT (DMARC)v=DMARC1; p=noneMonitor only — spoofed emails NOT rejected

Infrastructure Profile

PropertyValue
Hosting platformVercel (Next.js)
Domain type.org
Email providerGoogle Workspace
CDN/ProxyVercel Edge (main), HubSpot (members/updates), Cloudflare (auth/give)
Subdomains7 active
Security headersPartial — HSTS present; missing CSP, X-Frame-Options, X-Content-Type-Options
FrameworkNext.js (x-powered-by header exposed)

Subdomain Inventory

#SubdomainPlatformPurpose
1www.ncai.orgVercel/Next.jsMain website
2updates.ncai.orgHubSpotEmail marketing
3members.ncai.orgHubSpotMembership portal
4give.ncai.orgClassy.org (GoFundMe)Donations
5auth.ncai.orgAuth0 (Okta)Authentication/SSO
6blog.ncai.orgWordPress.comBlog
7archive.ncai.orgAWS EC2Legacy content (cert expired)

Assessment: MEDIUM-HIGH

Summary: NCAI operates a modern, well-segmented infrastructure with professional vendor selection. Three gaps are worth flagging: (1) DMARC is set to p=none, meaning spoofed @ncai.org emails are not rejected; (2) security headers (CSP, X-Frame-Options, X-Content-Type-Options) are absent; (3) archive.ncai.org has an expired certificate.

Disaster & Environmental

Assessment: N/A (National Advocacy Organization)

NCAI is not a facility-based entity. Its disaster/environmental relevance is as the leading national tribal advocacy voice:

#ActivitySource
1Drove Stafford Act amendments for direct tribal disaster declarationsncai.org
2FEMA Administrator presented Tribal Strategy at NCAI 80th Conventionfema.gov
3Administered tribal disaster preparedness grantsitema.org
4EPA environmental partnership spanning 50+ yearsepa.gov
5Active policy portfolios: climate, green energy, water/air qualityncai.org

Summary: NCAI's disaster/environmental profile is advocacy-facing. They are FEMA's primary tribal government interlocutor and the organization that achieved tribal parity with states on presidential disaster declarations.

Media & Public Narrative

Queries used

"National Congress of American Indians" news 2025 2026
"National Congress of American Indians" site:indianz.com
"National Congress of American Indians" site:ictnews.org
"NCAI" site:nativenewsonline.net
"National Congress of American Indians" president OR "executive director" 2025 2026

Recent Coverage (2025–2026)

#ArticleDatePublicationKey Points
1Emergency Resolutions on Immigration Enforcement2026-02Native News OnlineDHS tribal consultation, tribal ID recognition
2Macarro: Tribes 'will never back down'2026-02ICT2026 State of Indian Nations address
382nd Convention brings 2,500 to Seattle2025-11Native News Online~100 resolutions passed by consensus
4Oglala Sioux Tribe leaves NCAI2025-11ICTCited structural bias toward self-governance tribes
5Condemns mascot reinstatement push2025-07NCAI75-year institutional opposition
6Condemns boarding school funding cuts2025-05NCAICalled rescission "a betrayal"
7Condemns federal layoffs hitting tribal programs2025-02NCAIIHS, BIA, BIE RIFs

Leadership (2025–2027 Executive Committee)

NameRoleAffiliation
Mark MacarroPresidentPechanga Band of Luiseno Indians
Brian Weeden1st Vice PresidentMashpee Wampanoag Tribe
Christie ModlinRecording SecretaryIowa Tribe of Oklahoma
Ashley CornforthTreasurerShakopee Mdewakanton Sioux Community
Larry Wright Jr.Executive DirectorPonca Tribe of Nebraska

Assessment: CLEAN

Summary: NCAI is in an extremely active advocacy posture, publishing major policy statements roughly monthly and directly confronting the Trump administration on multiple fronts. The Oglala Sioux Tribe's November 2025 withdrawal is the one notable friction point but is not indicative of organizational instability.

Risk Summary

CategoryAssessment
Governance & DocumentsLOW
Wayback ArchiveLOW
Certificate TransparencyLOW
Funding & ContractsLOW
Legal & RegulatoryCLEAN
InfrastructureMEDIUM-HIGH
Disaster & EnvironmentalN/A
Media & NarrativeCLEAN
Overall Footprint Assessment: EXTENSIVE

NCAI has one of the deepest publicly indexed footprints of any nonprofit in Indian Country — 28 years of archived documents, $73M+ in traceable funding, 14+ SCOTUS amicus briefs, and active engagement across every major federal agency. This is consistent with their role as the premier inter-tribal advocacy organization. The footprint is overwhelmingly intentional and well-managed, with infrastructure being the primary area where posture gaps exist.

Recommendations

Immediate Actions

  1. Set DMARC to p=quarantine then p=reject — Currently p=none allows spoofed @ncai.org emails to be delivered. For an organization that communicates with 574+ tribal governments, email spoofing is a significant phishing vector.
  2. Decommission or renew archive.ncai.org — Expired certificate since October 2025; either formally decommission the subdomain or renew the cert.
  3. Restrict cms.ncai.org — Legacy BrowserCMS v3.3.4 login page is indexed; restrict to IP allowlist or VPN.
  4. Add security headers — Content-Security-Policy, X-Frame-Options, and X-Content-Type-Options are absent from the main site.
  5. Remove x-powered-by header — Exposing "Next.js" provides unnecessary fingerprinting information.

Ongoing Monitoring

  1. Certificate transparency monitoring — Set up alerts for new certificates issued to *.ncai.org to detect unauthorized subdomain creation.
  2. Wayback archive review — The 448 non-PDF documents (.docx, .pptx) archived at root-level paths should be reviewed for sensitive internal content.
  3. USASpending and 990 monitoring — Monitor for new filings that reveal program changes or financial shifts.

Strategic Considerations

  1. Next.js data endpoints — The _next/data/ JSON endpoints in Wayback allow bulk extraction of site content. Consider whether this data exposure is intentional.
  2. Dual-entity structure transparency — The 501(c)(3)/501(c)(4) split is fully traceable across ProPublica, Charity Navigator, and USASpending.
  3. Foundation dependency visibility — The $26M+ Kellogg relationship and 2-star Charity Navigator rating are prominently indexed and will be among the first things discovered by potential donors, partners, or critics.

What This Means

Donor and grant transparency means your funding portfolio, tax filings, and program outcomes are publicly assembled in ways that shape how funders and the public perceive your organization. For NCAI specifically, the 28-year archived document corpus, $73M+ in traceable funding, and comprehensive litigation record create an extraordinarily detailed picture of the organization's priorities, positions, and financial health — available to anyone with a search engine. The infrastructure gaps (DMARC, expired certificates, missing security headers) are the one area where the organization's technical posture does not match the sophistication of its policy work.