Contents
- Purpose
- Methodology
- Governance & Sensitive Documents
- Personnel & PII Exposure
- Financial Documents
- Wayback Machine Archive
- Certificate Transparency
- Funding & Contract Records
- Legal & Regulatory Records
- Infrastructure & Technical Surface
- Disaster & Environmental
- Media & Public Narrative
- Risk Summary
- Recommendations
- What This Means
Purpose
This audit maps the publicly indexed digital footprint of the Nez Perce Tribe across federal agency databases (BIA, IHS, EPA, HHS, DOI, DOJ, FEMA, USGS), court records, certificate transparency logs, the Wayback Machine, funding portals (USASpending, HHS TAGGS, GovTribe), and the Tribe's own web properties.
What can anyone with a search engine learn about your organization in 30 minutes?
For a federally recognized tribe, the digital footprint is shaped by government-to-government relationships that generate documents on systems you do not control. Every compact, grant, environmental filing, and court case creates a public record hosted on a federal domain. This audit reveals what that assembled picture looks like — and whether it matches what you intend to be public.
Methodology
The following data sources were queried on April 12, 2026:
- Advanced search (dorking): Targeted searches across BIA, IHS, EPA, HHS, DOI, DOJ, Congress, Federal Register, and the Tribe's own domains
- Wayback Machine CDX API: Historical archive analysis of nezperce.org, nptfisheries.org, and nezpercewildlife.org
- Certificate Transparency (crt.sh): SSL/TLS certificate analysis for all five domains
- DNS interrogation: A, MX, NS, TXT record analysis
- Funding databases: USASpending, HHS TAGGS, GovTribe, SAM.gov, HigherGov
- Legal databases: NARF/NILL, Justia, CourtListener, JudyRecords, Federal Register
- FEMA disaster records, USGS monitoring stations, EPA facility registry
- News and media: Regional news, tribal media (Indianz, ICT News, Native News Online), congressional records
Governance & Sensitive Documents
Queries: "Nez Perce Tribe" filetype:pdf "confidential" OR "internal" OR "not for distribution" "Nez Perce Tribe" filetype:pdf "resolution" OR "compact" OR "charter" OR "MOU" "Nez Perce Tribe" site:bia.gov filetype:pdf "Nez Perce Tribe" site:epa.gov filetype:pdf "Nez Perce Tribe" site:federalregister.gov
| # | Document | Hosted On | Risk | Notes |
|---|---|---|---|---|
| 1 | Tribal Government Finance Manual | nezperce.org | MEDIUM-HIGH | Full internal finance manual detailing financial controls and procedures |
| 2 | Human Resources Manual | nezperce.org | MEDIUM | Complete HR policy manual; employment policies, compensation, disciplinary procedures |
| 3 | Revised Constitution and Bylaws | nezperce.org | LOW | Governing document; standard for tribes to publish |
| 4 | Gaming Compact (2008) | bia.gov | MEDIUM | Full gaming compact with operational terms and revenue-sharing provisions |
| 5 | Gaming Compact (1995) | bia.gov | MEDIUM | Original gaming compact on BIA's public document system |
| 6 | Radon Measurement QAPP | epa.gov (FTP) | MEDIUM | Quality assurance plan on EPA FTP; includes reservation population data |
| 7 | Nez Perce Tribal Code (13 titles) | narf.org | LOW | Complete tribal code publicly indexed on NARF/NILL |
Assessment: MEDIUM
The Tribe's governance documents are appropriately self-published. The higher-risk items are the Finance Manual and HR Manual on nezperce.org, and gaming compacts on bia.gov. No documents marked "confidential" were found exposed.
Personnel & PII Exposure
| # | Finding | Hosted On | Risk | Notes |
|---|---|---|---|---|
| 1 | ZoomInfo Company Profile | zoominfo.com | MEDIUM | Third-party aggregator listing 691 employees |
| 2 | RocketReach Management Profile | rocketreach.co | MEDIUM | Third-party data broker exposing management contacts |
Assessment: MEDIUM
No spreadsheets with member enrollment or employee rosters were found indexed. Third-party data aggregators are scraping and republishing tribal employee contacts outside the Tribe's control.
Financial Documents
| # | Document | Hosted On | Risk | Notes |
|---|---|---|---|---|
| 1 | Pay Grade/Step Scale (2022) | nezperce.org | MEDIUM | Complete pay grade table with hourly rates |
| 2 | Pay Grade/Step Scale (2017) | nezperce.org | MEDIUM | Older pay scale still publicly accessible |
| 3 | Tribal Government Finance Manual | nezperce.org | MEDIUM-HIGH | Internal financial controls and procedures |
Assessment: MEDIUM-HIGH
The full Tribal Government Finance Manual and two versions of the pay grade/step scale are publicly accessible. While pay scales are common for tribal employers, the finance manual contains operational detail typically kept internal.
Wayback Machine Archive
| Metric | Value |
|---|---|
| Total unique pages archived | ~52,900 |
| Total unique PDFs archived | ~1,160 |
| Earliest snapshot | 1999-10-13 |
| Most recent snapshot | 2026-04-12 |
| Hosting platform | WordPress (current); legacy static HTML + CGI-BIN (pre-2018) |
Notable Archived Paths
| # | Path | Type | Notes |
|---|---|---|---|
| 1 | nezperce.org/~code/ (115 pages) | HTML | Full tribal code as individual HTML files (legacy) |
| 2 | nezperce.org/~dfrm/ (173 pages) | HTML/PDF | Fisheries annual reports 1991-2008 |
| 3 | nezperce.org/Official/PDF/infosys/BackupBrochure.pdf | IT backup procedure document — internal operational | |
| 4 | nezperce.org/cgi-bin/calendar.pl?template=login.html | HTML | Exposed CGI calendar login page |
| 5 | NPTFWC-Reg-* (45+ files) | Fish & Wildlife Commission regulations 2019-2021 |
Assessment: MEDIUM-HIGH
A massive 27-year archive. The complete tribal code, General Council resolutions, and 45+ Fish & Wildlife regulations are preserved. Legacy paths reveal internal documents not likely intended for public indexing.
Certificate Transparency
| Property | Value |
|---|---|
| Total certificates found | ~85+ |
| Issuers | Let's Encrypt, Network Solutions, GoDaddy, Amazon, cPanel, Cloudflare |
| Earliest certificate | 2018-05-03 |
| Most recent certificate | 2026-03-20 |
| Wildcard certs | Yes (*.nezperce.org — expired, not renewed) |
Subdomains Discovered
| # | Subdomain | Purpose | Notes |
|---|---|---|---|
| 1 | support.nezperce.org | Help desk / ticketing | Let's Encrypt |
| 2 | enterprise.nezperce.org | Enterprise application | Let's Encrypt |
| 3 | webland.nezperce.org | Land management system | Network Solutions |
| 4 | npt-cdms.nezperce.org | Document management (CDMS) | Network Solutions |
| 5 | flex.nezperce.org | Scheduling / HR / workforce | Network Solutions |
| 6 | librenms.nezperce.org | Network monitoring (LibreNMS) | Let's Encrypt — indicates in-house IT team |
Assessment: LOW
Mature IT operation with deliberate hosting diversification. No sensitive development/staging/VPN subdomains exposed. LibreNMS confirms in-house networking team.
Funding & Contract Records
SAM.gov Registration: UEI N6M5CKJT8G71 / CAGE 1T6Y2 / 501-750 employees / View profile
Major Funding Records
| # | Record | Amount | Agency | Notes |
|---|---|---|---|---|
| 1 | EPA Climate Pollution Reduction Grant | $37,346,490 | EPA | Residential energy, renewables, EV infrastructure |
| 2 | Indian Housing Block Grant | $21,518,872 | HUD | IHBG to Housing Authority, 2012-2033 |
| 3 | BUILD Transportation Grant | $19,134,710 | DOT | Aht'Wy Interchange on US-95 |
| 4 | EPA CPRG Second Tranche | $8,707,461 | EPA | Part of $78M to Pacific NW tribes |
| 5 | HUD Affordable Housing | $4,798,703 | HUD | 16 affordable rental units |
| 6 | America the Beautiful — Mine Restoration | $1,900,000 | DOI | Creek restoration near abandoned mine |
| 7 | HHS Tobacco Prevention | $845,664 | HHS | Keep Tobacco Sacred program |
| 8 | DOJ Tribal Victim Services | $543,066 | DOJ | Culturally-appropriate victim services |
Subsidiary Entities Discovered
| # | Entity | Relationship | Source |
|---|---|---|---|
| 1 | Nez Perce Tribal Housing Authority | Housing authority | SAM.gov |
| 2 | Nez Perce Tribal Enterprises | Enterprise arm — casinos, golf, hot springs | nezperce.org |
| 3 | Nimiipuu Health | IHS Self-Governance health — two clinics | nimiipuuhealth.org |
| 4 | Nimiipuu Energy | Tribal energy company — solar, est. 2022 | nezperce.org |
| 5 | Appaloosa Express | Transit service | nezperce.org |
| 6 | Nez Perce Soil & Water Conservation District | Conservation | SAM.gov |
| 7 | Water Resources Division | Government division | nptwaterresources.org |
| 8 | Dept. of Fisheries Resources Management | Government division | BPA/nezperce.org |
Assessment: HIGH
The Tribe has a large, fully reconstructable federal funding footprint exceeding $100M across 10+ agencies with 8+ subsidiary entities. The BIA 638 contracts and IHS Self-Governance Compact represent significant recurring annual transfers.
Legal & Regulatory Records
Legal Code Exposure
| # | Resource | Source | Scope |
|---|---|---|---|
| 1 | Nez Perce Tribal Code | narf.org | 13 titles — complete legal framework |
| 2 | Constitution & Bylaws | narf.org | 9 articles + bylaws |
| 3 | Tribal Court Opinions | NICS | Appellate decisions |
Significant Litigation
| # | Case | Type | Notes |
|---|---|---|---|
| 1 | NPT v. Perpetua Resources | Federal (CWA) | Settled $5M — water quality fund |
| 2 | NPT v. USFS (Stibnite, 2025) | Federal (NEPA) | Active — challenging gold project approval |
| 3 | County of Lewis v. NPT | 9th Circuit | Landmark tribal sovereignty case |
Major Settlements
| # | Settlement | Value | Notes |
|---|---|---|---|
| 1 | Snake River Basin Water Rights | ~$193M | $83M cash + 11,000 acres BLM land + salmon conservation |
| 2 | Portland Harbor NRD | $33.2M | Multi-trustee natural resource damages |
| 3 | Perpetua Resources CWA | $5M | Water quality enhancement fund |
Assessment: MEDIUM-HIGH
Complete 13-title tribal code publicly indexed. Strategically coherent litigation record — aggressive treaty and environmental enforcement. The Tribe functions as a sophisticated co-regulator with delegated Clean Air Act authority.
Infrastructure & Technical Surface
DNS Configuration
| Record | Domain | Value | Significance |
|---|---|---|---|
| A | nezperce.org | 104.42.73.26 | Microsoft Azure |
| A | nptfisheries.org | 52.38.38.234 | Amazon AWS |
| A | nezpercewildlife.org | 198.185.159.144 | Squarespace |
| A | nezpercegis.org | 67.109.224.220 | Self-hosted (Verizon Business) |
| MX | nezperce.org | *.mail.protection.outlook.com | Microsoft 365 |
| NS | nezperce.org | dns1/dns2.nezperce.org | Self-hosted authoritative DNS |
| TXT | nezperce.org | SPF + iphmx.com | Proofpoint email security gateway |
Infrastructure Profile
| Property | Value |
|---|---|
| Primary hosting | Azure (main), AWS (fisheries), Squarespace (wildlife/tourism) |
| On-premises | Verizon Business IP block — DNS, GIS, mail relay |
| Web server | Nginx + PHP 8.2.30 on Plesk |
| Domain type | .org x4, .com x1 (no .gov) |
| Microsoft 365 + Proofpoint gateway | |
| Self-hosted DNS | Yes — 3 of 5 domains |
| Subdomains | 20+ discovered |
| Security headers | Partial (HSTS on main, CSP on fisheries, gaps on Squarespace) |
Assessment: MEDIUM-HIGH
Sophisticated hybrid infrastructure with self-hosted DNS, LibreNMS monitoring, and enterprise email security. Server technology headers are exposed. No .gov domain despite eligibility.
Disaster & Environmental
FEMA Declarations
| # | Declaration | Date | Type | Notes |
|---|---|---|---|---|
| 1 | FEMA-4443-DR | 2019-06-12 | Storms, flooding, landslides | Tribe explicitly designated |
| 2 | FEMA-4534-DR | 2020 | COVID-19 pandemic | Statewide |
| 3 | FMAG — Texas Fire | 2024-07 | Wildfire | Latah/Nez Perce counties |
| 4 | FMAG — Gwen Fire | 2024-07 | Wildfire | Burned across Reservation; $985K HMGP |
| 5 | DR-4878 | 2026-04-11 | Straight-line winds | Nez Perce County designated |
Environmental Monitoring
| # | Station | Agency | Type |
|---|---|---|---|
| 1 | Clear Creek nr MF Clearwater | USGS | Water — sediment, turbidity |
| 2 | Clearwater River at Spalding | USGS | Water — gage height, streamflow |
| 3 | Lapwai Creek near Lapwai | USGS | Water — gage height, streamflow |
| 4 | 18 Lower Lapwai Creek sites | NPT/EPA | CWA Section 106 water quality |
EPA Records
| # | Record | Notes |
|---|---|---|
| 1 | Brownfields/CERCLA Response Program | 114-acre Blue North Mill site (asbestos) |
| 2 | Underground Storage Tank Program | 18 regulated facilities — 2nd largest in EPA Region 10 |
| 3 | Delegated Burn Permit Authority | EPA delegation to Tribe |
Assessment: MEDIUM-HIGH
Substantial disaster history with multiple FEMA declarations and FMAGs. Among the most robust environmental monitoring footprints in EPA Region 10 — dozens of sites, active Brownfields program, 18 UST facilities.
Media & Public Narrative
Recent Coverage
| # | Article | Date | Key Points |
|---|---|---|---|
| 1 | Tribe warns Congress of hatchery crisis | 2025-07 | FWS cut Kooskia hatchery 33% |
| 2 | Fighting to protect salmon | 2025-08 | Trump withdrew from Columbia Basin Agreement |
| 3 | ICE sovereignty guidance | 2026-01 | Tribal Police will not assist ICE detentions |
| 4 | $37.3M EPA climate grant | 2024-07 | Largest single tribal climate grant |
Leadership Identified
| # | Name | Role |
|---|---|---|
| 1 | Shannon F. Wheeler | Chairman, NPTEC (term through 2028) |
| 2 | Ashton Picard | Vice-Chairman, NPTEC |
| 3 | Rachel P. Edwards | Secretary, NPTEC |
| 4 | Anthony Johnson | Interim Manager, Planning & Economic Development |
Assessment: CLEAN
Strong, well-organized public narrative centered on treaty rights, salmon restoration, and sovereignty. No scandals, no financial distress, no leadership disputes. Transparent governance with full General Council minutes published.
Risk Summary
Category Scorecard
| Category | Assessment | Key Finding |
|---|---|---|
| Governance & Documents | MEDIUM | Finance manual and gaming compacts publicly accessible |
| Personnel & PII | MEDIUM | Third-party aggregators scraping employee data |
| Financial Documents | MEDIUM-HIGH | Internal finance manual and pay scales indexed |
| Wayback Archive | MEDIUM-HIGH | 52,900+ pages; complete tribal code and legacy internal docs |
| Certificate Transparency | LOW | Mature IT posture; no sensitive subdomains exposed |
| Funding & Contracts | HIGH | $100M+ reconstructable; 8+ subsidiaries discovered |
| Legal & Regulatory | MEDIUM-HIGH | Complete 13-title code; $193M settlement; active litigation |
| Infrastructure | MEDIUM-HIGH | Self-hosted DNS; PHP version disclosed; no .gov domain |
| Disaster & Environmental | MEDIUM-HIGH | Multiple FEMA declarations; 18 UST facilities |
| Media & Narrative | CLEAN | Strong positive narrative; transparent governance |
The Nez Perce Tribe has one of the most substantial digital footprints of any tribal government — a reflection of its deep engagement with federal agencies, sophisticated IT infrastructure, and transparent governance practices. This is not inherently negative; much of it reflects good governance. The question is whether all of it is intentional.
Recommendations
Immediate Actions
- Review the Finance Manual PDF — The Tribal Government Finance Manual details internal financial controls. Consider whether this should be behind authentication.
- Submit data broker opt-outs — ZoomInfo and RocketReach are republishing management contact details. Both offer removal processes.
- Remove server technology headers — The main site discloses PHP 8.2.30 and PleskLin. Configure nginx to suppress X-Powered-By.
Ongoing Monitoring
- WordPress upload directory — Sensitive PDFs uploaded through WordPress are discoverable by path enumeration. Consider access-controlling sensitive documents.
- Certificate renewal — Monitor that individual subdomain certs remain current after the wildcard expiration.
- Third-party data aggregation — Set quarterly checks on data broker services to prevent re-accumulation of employee data.
Strategic Considerations
- Consider .gov domain adoption — Tribal governments are eligible through CISA. A .gov domain increases authority and trust.
- Self-hosted DNS resilience — Running authoritative DNS on-premises is a significant decision. Ensure redundancy and failover.
- Audit intentionality — With 52,900+ pages archived, establish periodic reviews of what should be public vs. member-only.
What This Means
Data sovereignty is not only about what data you collect. It is about knowing where your data already lives, who else can find it, and what decisions it enables them to make.
The Nez Perce Tribe's digital footprint is a product of three decades of active federal engagement — treaty enforcement, environmental co-regulation, and economic development. Much of this exposure is the cost of doing business with the federal government. But some of it — the finance manual, the pay scales, the predictable WordPress upload paths — may not be intentional. And third-party data aggregators are assembling employee profiles from public sources without tribal consent.
Understanding this footprint is the first step toward managing it deliberately.