Independent. Not owned by or funded by any pharmaceutical manufacturer.
Evidence-sourced · medically-reviewed where indicated
Legal

Security and vulnerability disclosure

Effective 2026-07-24

Report a vulnerability

Email security@glp1.healthcare. We aim to acknowledge within 3 business days. We do not operate a paid bug bounty, but we will credit you publicly if you would like that, and we will always tell you what we did about it.

What this site is, from a security standpoint

The attack surface here is unusually small, and that is deliberate. GLP-1 Healthcare is a statically generated site with no user accounts, no login, no database of readers, no payment processing, and no forms that submit to us. There is no reader data to breach because we do not collect any — see our Privacy Policy.

The interactive tools — the provider match quiz, the cost pathway tool, and the glossary search — run entirely in your browser. Your answers are never transmitted to us.

In scope

Out of scope

Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will consider it authorised, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you. If a third party brings action against you for research conducted in accordance with this policy, we will make that authorisation clear.

Good faith means:

Our commitments back to you

Reporting a content error instead

If you have found a factual or clinical error rather than a security issue, that matters just as much to us and has its own route: email corrections@glp1.healthcare. Our corrections process is set out in the Editorial Policy.