Security

Security starts with explicit boundaries and honest status.

The M1 Project marketing site accepts text-only inquiries. It does not connect to source repositories, development computers, or agent runtimes. The proposed product will require a separate pilot agreement and technical review before those capabilities are enabled.

01

Marketing site scope

Access and contact submissions are stored in the Site’s private managed database. They are not exposed through a public listing endpoint. We collect no payment data, credentials, source code, or uploaded files through this site.

02

Proposed product controls

Pilot design includes scoped repository connections, per-agent secrets, connected-computer status, execution timeouts, concurrency limits, isolated worktrees, visible traces, and human acceptance. These are proposed controls, not security certifications.

03

Report a vulnerability

Use the privacy and security request option on our contact form. Include a concise description, affected URL, reproducible steps, and impact. Do not include live credentials, personal data, or destructive proof. We make no unverified response-time promise.

Pre-release · No instant signup or payment

See whether M1 Project fits your team’s operating model.

Request a walkthrough