Security and vulnerability disclosure
Effective 2026-07-24
Report a vulnerability
Email security@glp1.healthcare. We aim to acknowledge within 3 business days. We do not operate a paid bug bounty, but we will credit you publicly if you would like that, and we will always tell you what we did about it.
What this site is, from a security standpoint
The attack surface here is unusually small, and that is deliberate. GLP-1 Healthcare is a statically generated site with no user accounts, no login, no database of readers, no payment processing, and no forms that submit to us. There is no reader data to breach because we do not collect any — see our Privacy Policy.
The interactive tools — the provider match quiz, the cost pathway tool, and the glossary search — run entirely in your browser. Your answers are never transmitted to us.
In scope
- The
glp1.healthcaredomain and its subdomains. - Cross-site scripting, content injection, or anything that could alter the clinical information a reader sees. On a health site, content integrity is the primary security concern — a modified dose figure is more dangerous here than most data leaks.
- Subdomain takeover, DNS misconfiguration, or exposed infrastructure.
- Missing or misconfigured security headers with a demonstrable impact.
- Anything that would let a third party track readers, which would break our privacy commitments.
Out of scope
- Findings against Vercel Inc., our hosting provider — report those to them directly.
- Third-party sites we link to, including provider and manufacturer websites.
- Denial of service, volumetric testing, or anything degrading availability for readers.
- Social engineering, phishing, or physical attacks against anyone involved.
- Automated scanner output with no demonstrated impact, missing headers with no exploit path, or reports that a page lacks a cookie banner — it lacks one because it sets no cookies, which is documented in our Cookie Policy.
Safe harbour
If you make a good-faith effort to comply with this policy during your research, we will consider it authorised, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you. If a third party brings action against you for research conducted in accordance with this policy, we will make that authorisation clear.
Good faith means:
- Stopping as soon as you have demonstrated the issue — do not pivot deeper.
- Not accessing, modifying, or destroying data that is not yours.
- Not degrading the service for readers, some of whom are looking up urgent symptoms.
- Giving us reasonable time to fix the issue before disclosing it publicly.
Our commitments back to you
- Acknowledgement within 3 business days.
- An assessment and expected timeline within 10 business days.
- Notification when the issue is resolved.
- Public credit if you want it, and none if you would rather stay anonymous.
Reporting a content error instead
If you have found a factual or clinical error rather than a security issue, that matters just as much to us and has its own route: email corrections@glp1.healthcare. Our corrections process is set out in the Editorial Policy.