Our mission is to look after the financial best interests of the up-and-coming, so we build tools that make investing, saving and earning money easy. Because growing wealth shouldn’t just be for the few. We promise our more than 3,000,000 customers serious security. Thank you for helping us stand by that promise by exposing our vulnerabilities, so that anyone can have a chance at a brighter future.
Our Acorns Security Analysts are committed to helping our researchers be successful in our program! We are determined to work with you to understand and attempt to resolve the issue quickly (confirming the report within 2 days of submission).
For the initial prioritization/rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.
This program follows Bugcrowd’s standard disclosure terms.
For any testing issues (such as broken credentials, inaccessible application, or Bugcrowd Ninja email problems), please email support@bugcrowd.com. We will address your issue as soon as possible.
This program does not offer financial or point-based rewards for P5 — Informational findings. Learn more about Bugcrowd’s VRT.
Scope Type | Scope Name |
---|---|
android_application | Acorns for Android |
api | https://graphql.acorns.com |
ios_application | Acorns for iOS |
web_application | https://app.acorns.com |
web_application | https://signup.acorns.com/ |
web_application | https://client.acorns.com |
web_application | https://help.acorns.com |
On this program you get up to 3500 $ for the most critical vulnerability.
FireBounty © 2015-2024