Pro bono · Mission support

Security work for the people who show up.

Tengu Labs donates a share of every year to nonprofits, volunteer search and rescue teams, fire departments, EMS agencies, and small law enforcement departments. No invoice. No upsell. No bait for a paid engagement later.

Volunteer fire Search & rescue EMS 501(c)(3) Small & rural PD Emergency management Combination departments K9 teams Volunteer fire Search & rescue EMS 501(c)(3) Small & rural PD Emergency management Combination departments K9 teams

The agencies with the most at stake have the least support.

A volunteer fire department runs CAD integrations, a records management system, and a mutual-aid radio network. A SAR team carries member PII, deployment records, mapping data, and a drone fleet. A rural police department holds criminal justice information under federal policy. None of them have a security engineer, and most cannot justify one against an operating budget that is already stretched. The exposure is real and the resourcing is not. That gap is worth closing.

Scoped tight. Delivered as something usable.

01

Security architecture review

An assessment of your current environment with a prioritized, budget-aware roadmap. Written so a board or a chief can read it, with a technical appendix for whoever actually maintains the systems.

02

Threat modeling

Structured analysis of a system or process using STRIDE, PASTA, and MITRE ATT&CK. Where the risk actually sits, ranked by exploitability and impact, with concrete mitigations attached.

03

AI tool risk assessment

Your agency is being sold AI transcription, report drafting, video analytics, and chat assistants. Evaluated against MITRE ATLAS — what the vendor does with your data, what the failure modes are, and what to require in the contract.

04

Attack surface review

What is exposed to the internet, what is unpatched, which credentials are already in breach corpora, and what to fix first. Findings ordered by what an actual adversary would reach for.

05

Policy and IR planning

Written security policy and an incident response plan sized to your organization. Documents you will open during an incident — not a ninety-page template that dies in a shared drive.

06

Grant and compliance support

Help articulating the security and technology sections of grant applications, and mapping what you already do to the frameworks funders, auditors, and insurers ask about.

SAR Log — built for a K9 team, at no cost to them.

Search and rescue teams have to document deployments, training hours, and K9 certification progress. Most do it in spiral notebooks, group texts, and a spreadsheet living on one person's laptop. When a team needs to prove readiness for a grant, an audit, or a court proceeding, the records often are not there.

// sarlogs.com · production since April 2026

Deployment & training documentation
Multi-dog handler support
Cross-user access controls
Append-only audit trail
Canonical source-type taxonomy

// stack
compute  · AWS Lambda
storage  · DynamoDB
auth     · Amazon Cognito
delivery · CloudFront

designed, built, funded, and maintained pro bono
$ _

This is not charity from a distance. Tengu Labs is run by a former police officer with twenty years in cybersecurity who currently serves as Treasurer, Technical Director, and Drone Pilot for a 501(c)(3) K9 search and rescue organization.

That means the callout at 0300 is a familiar thing, not an abstraction. So is the board meeting where the annual technology budget is a rounding error, and the grant deadline where nobody on the team can write the security narrative the funder is asking for.

Tools get built for those conditions because those are the conditions being operated in.

Certifications
CISSP · CEH
Prior service
Sworn law enforcement officer
Current volunteer role
Treasurer · Technical Director · Drone Pilot, 501(c)(3) K9 SAR
Frameworks
NIST CSF · NIST 800-53 · MITRE ATT&CK · MITRE ATLAS · CJIS-aware
Who qualifies
501(c)(3) nonprofits Volunteer & combination fire Search & rescue teams EMS agencies Small & rural law enforcement Emergency management

Close to this list but not exactly on it? Ask anyway.

Being straight about this saves everyone time.

01 / Availability

A small number of engagements per quarter.

This is donated capacity from a working practitioner, not a staffed program. There may be a wait. Most work is remote; in-person is possible in the Chicago metro area.

02 / Shape

Defined deliverable, defined end.

Every engagement has a stated scope and a finish line. That is what makes it possible to say yes to the next organization. This is not an open-ended retainer or a standing advisory seat.

03 / Not a SOC

No monitoring, no on-call response.

There is no 24/7 monitoring, no security operations center, and no incident response hotline behind this. If you are in an active incident right now, contact your cyber insurance carrier, your state fusion center, and CISA at report@cisa.gov.

04 / Paperwork

A written agreement, even at zero cost.

Engagements are covered by a short agreement defining scope, confidentiality, and liability. That protects your organization as much as it protects this one. Agencies with procurement, gift-acceptance, or CJIS personnel-screening requirements: those processes are welcome, not an obstacle.

Tell me what you're trying to protect.

A paragraph is enough — your organization, what you run, and what is worrying you. If it's a fit, we'll schedule thirty minutes to scope it.