Affiliate-supportedIndependent editorialWe never sell medicationSee how
GLP1Zoom welcomes coordinated disclosure of security vulnerabilities. This page documents what we want to hear about, how to reach us, and what to expect.
Email [email protected]. PGP key available at /.well-known/pgp-key.txt. Machine-readable contact data lives at /.well-known/security.txt (RFC 9116).
/api/*/admin/api/affiliate/*GLP1Zoom will not pursue legal action against researchers who:
We will publicly credit reporters in our hall of fame unless anonymity is requested.
We don't currently run a paid bounty program. Reports are voluntary and appreciated; credit and swag where appropriate.
If a finding involves real user data, do NOT exfiltrate, modify, or share it. Describe the issue, redact any sensitive fields, and stop probing. We will reproduce in our staging environment with synthetic data.
Last updated 2026-06-03. Policy effective until superseded.