Shop by goal

  • Metabolic Research
  • GH-Axis Research
  • Muscle & IGF Research
  • Tissue and Cellular Models
  • Regenerative Research
  • Cellular Senescence Research
  • Cognitive Research
  • Multi-Compound Blends
  • Accessories
  • All compounds →
  • Popular compounds

  • BPC-157
  • TB-500
  • GHK-Cu
  • GLP1-RC-RT
  • GLP1-RC-SM
  • Ipamorelin
  • All bestsellers →
  • Research resources

  • Research Glossary
  • Peptide Guides
  • Delivery Guide
  • Track Order
  • Recently viewed

  • Peptide 101
  • Research Areas
  • Peptide Blog
  • Community Forum
  • Crypto Blog
  • Research Glossary
  • Reconstitution Calculator
  • Peptide Tracker
  • Research Protocol Tools
  • Peptide Guides
  • Sign In
  • Create Account
  • Track My Order
  • Refer a Friend
  • My Account
  • My Orders
  • My Referrals
  • Log Out
  • How-to guides
  • Home
  • Security & Vulnerability Disclosure
  • Security policy

    Security & Vulnerability Disclosure

    New-U Research Compounds is operated by Hilxera Distribution Services LLC. We take the security of our website, customer information and operational systems seriously.

    On this page

  • Reporting vulnerabilities
  • Scope
  • Good-faith research
  • Out of scope and prohibited testing
  • Third-party services
  • What to include in a report
  • Response process
  • Responsible disclosure
  • Bug bounty program
  • Contact
  • Reporting vulnerabilities

    If you believe you have identified a security vulnerability affecting new-u.io , please report it privately to:

    Newu.io.peptides@gmail.com

    Please provide enough information for us to reproduce and assess the issue, including the affected URL or component, the steps required to reproduce it, the observed behaviour and the potential security impact.

    Scope

    This policy covers security vulnerabilities in first-party systems operated by New-U and made available through new-u.io.

    A vulnerability affecting a third-party service used by New-U should normally be reported to that service's own security team.

    Good-faith research

    When investigating a suspected vulnerability:

  • use the minimum interaction necessary to demonstrate the issue
  • use your own account and your own data wherever possible
  • avoid accessing information belonging to another customer or user
  • stop testing if you encounter personal data, authentication secrets, payment information or other non-public information
  • do not download, retain, modify, delete or disclose data that is not yours
  • avoid actions that could interrupt the website or affect another user's experience
  • provide us with a reasonable opportunity to investigate and remediate a valid vulnerability before publishing technical details
  • If you unexpectedly access sensitive or personal information, stop testing and include only the minimum information required for us to locate the affected data.

    Out of scope and prohibited testing

    Do not perform:

  • denial-of-service, distributed denial-of-service or resource-exhaustion testing
  • destructive testing or attempts to corrupt or delete information
  • phishing, impersonation or other social-engineering attacks
  • physical-security testing
  • spam or unsolicited bulk messaging
  • credential stuffing, password spraying or high-volume brute-force authentication attacks
  • malware deployment or persistence attempts
  • high-volume automated scanning that materially affects service availability
  • attacks against customers, employees, suppliers or contractors
  • attempts to manipulate live orders, refunds, chargebacks or fulfilment records
  • fraudulent purchases or tests involving stolen or unauthorized payment credentials
  • testing designed to create real financial loss
  • Third-party services

    Third-party systems are outside the scope of this policy unless New-U explicitly states otherwise.

    This includes, without limitation:

  • card processors
  • bank-transfer providers
  • cryptocurrency payment providers
  • email providers
  • hosting and infrastructure providers
  • analytics providers
  • couriers and fulfilment providers
  • laboratories
  • supplier systems
  • other external APIs or SaaS platforms
  • The fact that a third-party service appears on new-u.io does not authorize testing of that service.

    What to include in a report

    A useful report should contain:

  • the affected URL, endpoint or feature
  • the vulnerability type
  • clear reproduction steps
  • the security impact
  • screenshots or a minimal proof of concept where useful
  • whether any data was accidentally accessed
  • your preferred contact details
  • Do not send passwords, private keys, full payment credentials or unnecessary copies of customer information.

    Response process

    New-U will aim to:

  • acknowledge a valid security report within 3 business days
  • begin triage as soon as reasonably practicable
  • request additional reproduction information where required
  • provide material status updates for confirmed issues when appropriate
  • coordinate disclosure timing for confirmed vulnerabilities in good faith
  • Response targets are operational goals rather than guarantees.

    Responsible disclosure

    Please do not publicly disclose an unresolved vulnerability before New-U has had a reasonable opportunity to investigate and remediate it.

    We may acknowledge researchers who responsibly report meaningful vulnerabilities, with their permission, but we do not currently operate a paid bug-bounty programme.

    No bug bounty

    Unless New-U has expressly agreed otherwise in writing:

  • reporting a vulnerability does not create a right to payment
  • New-U does not promise a bounty or reward
  • costs incurred by a researcher are not reimbursable
  • Contact

    Security reports: Newu.io.peptides@gmail.com

    General customer support, order questions, delivery matters and payment-support requests should continue through the normal support channels rather than the security mailbox.

    Machine-readable disclosure information: https://new-u.io/.well-known/security.txt (RFC 9116 format)

    PRECISION. PURITY. PERFORMANCE.

    Research peptides at >99% HPLC-verified purity, third-party tested by Janoshik Analytical & Freedom Diagnostics, with Certificates of Analysis published per released batch. Supplied strictly for laboratory research use.

    Shop

  • All research compounds
  • Price list
  • Where to buy peptides
  • Compare compounds
  • Compare vial sizes
  • Affiliate programme
  • Research

  • Peptide 101
  • Published COAs
  • Research areas
  • Research blog
  • How-to guides
  • Peptide guides
  • Research glossary
  • Support

  • Track your order
  • Contact us
  • Shipping & delivery
  • International shipping
  • FAQ
  • Community forum
  • Refund policy
  • Ways to Pay

  • Google Pay
  • Apple Pay
  • Venmo
  • Cryptocurrency
  • Crypto wallets
  • Cash App
  • Card payments
  • Bank transfer (SEPA)
  • Paying with crypto
  • Live crypto prices
  • Shop by goal

  • Metabolic Research
  • GH-Axis Research
  • Muscle & IGF Research
  • Tissue and Cellular Models
  • Regenerative Research
  • Cellular Senescence Research
  • Cognitive Research
  • Multi-Compound Blends
  • Accessories
  • Shop by compound

  • BPC-157
  • TB-500
  • GHK-Cu
  • Tesamorelin
  • Retatrutide
  • Semaglutide
  • Tirzepatide
  • CJC-1295 (without DAC)
  • All compounds →
  • Shop by region

  • United Kingdom
  • United States
  • Australia
  • Canada
  • Canada (FR)
  • Ireland
  • Northern Ireland
  • Malta
  • Germany
  • France
  • Spain
  • Italy
  • Netherlands
  • Portugal
  • Greece
  • Austria
  • Poland
  • Sweden
  • Finland
  • Denmark
  • Norway
  • Croatia
  • Slovakia
  • Slovenia
  • Estonia
  • Latvia
  • Lithuania
  • Czechia
  • Hungary
  • Romania
  • Bulgaria
  • Belgium
  • Belgium (FR)
  • Luxembourg
  • Deutsch
  • Ελληνικά
  • Español
  • Français
  • Italiano
  • Research use only - all claims made on this site are for testing and research use only. Purchasers must be 21 years of age or older.

    All rights reserved. Copyright of New-U held with Hilxera Distribution Services LLC 2026.

    Website & business operated by Hilxera Distribution Services LLC. Registered in Wyoming, ID: 2026-001928701.

    Principal office: 1712 Pioneer Ave., Ste. 500, Cheyenne, WY 82001, USA

    © 2026 New-U Research Compounds · new-u.io

    Research use only — not for human consumption. All products are supplied strictly for laboratory research purposes.

    © 2026 New-U Research Compounds · new-u.io — Copyright held with Hilxera Distribution Services LLC. All rights reserved.