What We Do

The Work in Detail

SpaceBoat volunteers contribute professional information technology and cybersecurity expertise to organizations that could not otherwise obtain it. You don't need to know which of these you need before getting in touch. Working that out is part of the help.

Direct Technical Assistance

Hands-on help with the systems an organization already depends on: accounts and access, backups, devices, email, and the everyday infrastructure that fails quietly until it fails badly.

In practice, it's ordinary work. Moving the organization onto email at its own domain instead of a founder's personal account, fixing the domain records that send your newsletter to everyone's spam folder, getting files off a departed volunteer's laptop, and finding out who actually owns your domain name so it can be put back in the organization's hands.

This is routine work for someone who does it professionally. For a team of four with no technical staff and a waiting list, it can sit undone for years.

Security Assessment and Remediation Guidance

A plain assessment of where an organization is exposed, written in ordinary language, with a prioritized plan that a staff member without technical training can actually carry out.

We look at the things that get organizations like yours hurt: accounts without multifactor authentication, shared passwords, backups nobody has ever restored from, records of the people you serve sitting somewhere they shouldn't, and what happens to access when someone leaves.

What you get back is a short list in priority order with the reasoning attached, rather than a 100-page report. Your board can see what you fixed and what you chose to defer.

What we learn about your weaknesses stays with us. Confidentiality is one of our stated values, and every volunteer is bound to it.

Education and Training

Practical instruction for staff, volunteers, and boards, so that capability stays with the organization after we leave.

That covers recognizing a phishing attempt, using a shared password manager without hating it, and knowing what to do first when something looks wrong. For boards, we run sessions on what the organization is responsible for and what a reasonable technology budget looks like.

We write things down as we go, so the next person inherits notes rather than a mystery: what you have, where it lives, who has access, what it costs, and when it renews.

Incident Response

Help when something has already gone wrong: a compromised account, a lost or stolen device, a suspected breach. We work the problem with you and help you decide what to do next.

The first hour matters, and it is the hour in which a small organization is least equipped to think clearly. We help you work out what actually happened and how far it reached, lock down what still needs locking down, and get back the accounts and access that were taken.

We also help with what comes after: what you are obliged to tell the people whose information was involved, what to tell your board, and what to change so the same thing does not happen twice.

If you think something is wrong right now, email us and say so plainly. You do not need to be certain, and it is better to ask early than to wait until you are sure.

Our Objectives

The Point of the Work

  • Improve the technical infrastructure of the organizations we serve, so that staff time returns to mission work instead of troubleshooting.
  • Reduce the risk that a security incident disrupts an organization's operations or exposes the people it serves.
  • Give organizations without in-house technical staff a knowledgeable and trustworthy place to bring a problem.
  • Build durable capacity through education, so that organizations depend less on outside help over time.
  • Help organizations respond and recover when a security incident does occur, so that the harm is contained and normal operations resume quickly.

Not Sure Which One?

That's Still Worth an Email

Describe what's happening in your own words, and we'll work out what it actually is.