
M1
Earn 3.10% APY with high-yield cash accounts. Automate investing, borrow at low rates, and maximize everyday finances. Join M1 today.
External Program
Submit bugs directly to this organization


Earn 3.10% APY with high-yield cash accounts. Automate investing, borrow at low rates, and maximize everyday finances. Join M1 today.
External Program
Submit bugs directly to this organization
M1 Finance welcomes independent researchers who wish to report potential security vulnerabilities. Before submitting any findings, please read the following guidelines and terms.
Reporting of potential security vulnerabilities are limited to the following:
To learn more about security at M1 Finance please visit M1 Security Recommendations.
To get support with an M1 product please visit our Help Center.
In order to help us understand and mitigate the potential vulnerability as quickly as possible, please follow these guidelines when creating a clear report. For submittal instructions, please see the "Submit" section below.
Please include the following information:
Due to legal constraints, all researchers must meet the following criteria if they wish to be eligible for a reward:
M1 reserves the right to change any restrictions or eligibility requirements at any time.
Rewards are scaled based on the severity of the finding and the quality of the report. M1 will not grant a reward if the researcher publicly discloses the issue before complete resolution or a specified disclosure date (each as solely determined by M1).
To deliver a reward we will need your ACH information and W-9. Be prepared to provide this information after the finding has been verified.
All payments will be made in U.S. dollars (USD) and will comply with local laws, regulations and ethics rules. You are responsible for the tax consequences of any bounty you receive, as determined by the laws of your locality.
Please submit all bug reports to [email protected].
A member of our team will review your findings and work with you to resolve the issue, if applicable. We will aim to reach out to you as soon as possible and work to create a vulnerability disclosure timeline within 180 days.