For organizations with no security team

Digital security for humans

We help nonprofits and small to mid-sized businesses build security systems, policies, and habits that actually stick—without the jargon and needless complexity.

Who we help

Come to us when…

…or any other reason you're not confident your organization is ready.

Why it matters

It usually starts with a weak password, a click on the wrong link, or a document pasted into the wrong AI tool

Security incidents are rarely a technical failure. Far more often, they involve someone doing their job.

62%

of breaches involve a person: someone clicked, was tricked, or sent the wrong thing to the wrong address1

88%

of reported breaches happen to organizations with fewer than 1,000 staff, not to big companies1

41%

of successful scams start somewhere other than email: a text, a phone call, a message1

45%

of staff put work information into AI tools their organization never approved, three times more than last year1

What these numbers describe is people making mistakes in their day to day work — which policies, processes, and training can prevent.

  1. Verizon, Data Breach Investigations Report 2026. 22,000+ confirmed breaches across 145 countries.
How we help

What we do and what changes for you

Every engagement is different, but most are built from one or more of these.

Risk assessments

You know something needs attention but not what comes first. We look at your programs, tools, and habits, then hand you an action plan: where you're strong, where you're exposed, and what to do about it, in order of priority.

What changes
  • You stop guessing: you know what to fix first, and what can wait
  • You have an expert report to put in front of your board or funder

Policy development & compliance

Whether you have no policies or policies nobody follows, we write them with you, matched to how your team actually works and to the capacity you actually have, not to an idealized standard nobody could reach.

What changes
  • Policies that fit your team, and that people actually use
  • Written answers ready when a client, insurer, or funder asks

Implementation support

We train your staff, help you find secure alternatives to the tools you're using, and stay available for the questions that come up once people start working differently.

What changes
  • Your team knows what to do without asking
  • New staff arrive into a system rather than into folklore
Working together

Two ways to start

Most of our work runs over months rather than weeks, but you don't have to commit to that on day one.

A good place to start

A short assessment

We look at your programs, tools, and habits, then hand you a report and an action plan you can act on immediately—with or without us.

It's the simplest way to find out what you're dealing with, and to see how we work before committing to anything longer.

  • Two to six weeks
  • A focused piece of work, not a months-long project
  • You keep the report and the plan either way
For lasting change

Ongoing support

Assessment, policy work, training, and hands-on help, in whatever mix your organization needs.

Habits take time to change. This is where policies get tested against real situations, staff build confidence, and new practices actually stick.

  • Three months to start, then as long as you want
  • Your team gets more capable — and less dependent on us — each month
  • Hourly or retainer, whichever suits you

Most organizations start with the assessment, though it isn't required;if you've had one done recently elsewhere, we can pick up from there. We scope every engagement to what you actually need.

Book a free consultation

Free half hour consultation. No prep needed, and no sales pitch from us.

About us

Security that people actually understand

The best security solutions are the ones people actually understand, trust, and keep using.

We're a small, focused team that believes digital security should be simple to follow and realistic to implement.

We are experts in digital security, but also in translating complex technical ideas into simple language and delivering training programs that achieve real behavioral change.

Our approach is shaped by years of delivering security programs in some of the world's most challenging environments, where getting security wrong isn't just an inconvenience: it carries life-or-death consequences. That work taught us to aim for security that just works, not security that looks perfect on paper.

How we think about security

Three principles behind every engagement.

Developing a security culture

We don't just recommend "secure" apps: those can become outdated or inadequate to address new threats. We build resilience at the organizational level: staff knowledge, skills, and adaptable processes and policies.

Security as a process

Rather than a checkbox to check once and for all, security is an ongoing journey. It requires building safe habits online, and real knowledge of what "secure" means for your specific needs and threats.

A collective effort

Our digital lives are so deeply intertwined that one person's decisions inevitably affect the digital security of their coworkers, friends, and relatives. Improving it requires working together.

Who you'll be working with

Meet the people who make up DigiSafe.

Start on your own

Free resources to get you started right now

Yours to use whether or not you ever hire us.

Security check-up

Find out where you stand, in five minutes

Answer sixteen questions and get your Digital Preparedness Level.

  • Free
  • No email required
  • We never see your answers
Take the check-up
The Privacy Hub

Build safer habits, a little at a time

A free newsletter and library of guides in the same plain language we use in our work. Sign your team up, or start reading today.

Or browse the Privacy Hub

Let's talk

Need to share something confidential? Keep the first message brief and we'll set up an encrypted channel before you share anything that matters. And we use Proton, so emailing us from a Proton account means your message is end-to-end encrypted.