Shop by goal
Metabolic Research
GH-Axis Research
Muscle & IGF Research
Tissue and Cellular Models
Regenerative Research
Cellular Senescence Research
Cognitive Research
Multi-Compound Blends
Accessories
All compounds →
Popular compounds
BPC-157
TB-500
GHK-Cu
GLP1-RC-RT
GLP1-RC-SM
Ipamorelin
All bestsellers →
Research resources
Research Glossary
Peptide Guides
Delivery Guide
Track Order
Recently viewed
Peptide 101
Research Areas
Peptide Blog
Community Forum
Crypto Blog
Research Glossary
Reconstitution Calculator
Peptide Tracker
Research Protocol Tools
Peptide Guides
Sign In
Create Account
Track My Order
Refer a Friend
My Account
My Orders
My Referrals
Log Out
How-to guides
Home
Security & Vulnerability Disclosure
Security policy
Security & Vulnerability Disclosure
New-U Research Compounds is operated by Hilxera Distribution Services LLC. We take the security of our website, customer information and operational systems seriously.
On this page
Reporting vulnerabilities
Scope
Good-faith research
Out of scope and prohibited testing
Third-party services
What to include in a report
Response process
Responsible disclosure
Bug bounty program
Contact
Reporting vulnerabilities
If you believe you have identified a security vulnerability affecting new-u.io , please report it privately to:
Newu.io.peptides@gmail.com
Please provide enough information for us to reproduce and assess the issue, including the affected URL or component, the steps required to reproduce it, the observed behaviour and the potential security impact.
Scope
This policy covers security vulnerabilities in first-party systems operated by New-U and made available through new-u.io.
A vulnerability affecting a third-party service used by New-U should normally be reported to that service's own security team.
Good-faith research
When investigating a suspected vulnerability:
use the minimum interaction necessary to demonstrate the issue
use your own account and your own data wherever possible
avoid accessing information belonging to another customer or user
stop testing if you encounter personal data, authentication secrets, payment information or other non-public information
do not download, retain, modify, delete or disclose data that is not yours
avoid actions that could interrupt the website or affect another user's experience
provide us with a reasonable opportunity to investigate and remediate a valid vulnerability before publishing technical details
If you unexpectedly access sensitive or personal information, stop testing and include only the minimum information required for us to locate the affected data.
Out of scope and prohibited testing
Do not perform:
denial-of-service, distributed denial-of-service or resource-exhaustion testing
destructive testing or attempts to corrupt or delete information
phishing, impersonation or other social-engineering attacks
physical-security testing
spam or unsolicited bulk messaging
credential stuffing, password spraying or high-volume brute-force authentication attacks
malware deployment or persistence attempts
high-volume automated scanning that materially affects service availability
attacks against customers, employees, suppliers or contractors
attempts to manipulate live orders, refunds, chargebacks or fulfilment records
fraudulent purchases or tests involving stolen or unauthorized payment credentials
testing designed to create real financial loss
Third-party services
Third-party systems are outside the scope of this policy unless New-U explicitly states otherwise.
This includes, without limitation:
card processors
bank-transfer providers
cryptocurrency payment providers
email providers
hosting and infrastructure providers
analytics providers
couriers and fulfilment providers
laboratories
supplier systems
other external APIs or SaaS platforms
The fact that a third-party service appears on new-u.io does not authorize testing of that service.
What to include in a report
A useful report should contain:
the affected URL, endpoint or feature
the vulnerability type
clear reproduction steps
the security impact
screenshots or a minimal proof of concept where useful
whether any data was accidentally accessed
your preferred contact details
Do not send passwords, private keys, full payment credentials or unnecessary copies of customer information.
Response process
New-U will aim to:
acknowledge a valid security report within 3 business days
begin triage as soon as reasonably practicable
request additional reproduction information where required
provide material status updates for confirmed issues when appropriate
coordinate disclosure timing for confirmed vulnerabilities in good faith
Response targets are operational goals rather than guarantees.
Responsible disclosure
Please do not publicly disclose an unresolved vulnerability before New-U has had a reasonable opportunity to investigate and remediate it.
We may acknowledge researchers who responsibly report meaningful vulnerabilities, with their permission, but we do not currently operate a paid bug-bounty programme.
No bug bounty
Unless New-U has expressly agreed otherwise in writing:
reporting a vulnerability does not create a right to payment
New-U does not promise a bounty or reward
costs incurred by a researcher are not reimbursable
Contact
Security reports: Newu.io.peptides@gmail.com
General customer support, order questions, delivery matters and payment-support requests should continue through the normal support channels rather than the security mailbox.
Machine-readable disclosure information: https://new-u.io/.well-known/security.txt (RFC 9116 format)
PRECISION. PURITY. PERFORMANCE.
Research peptides at >99% HPLC-verified purity, third-party tested by Janoshik Analytical & Freedom Diagnostics, with Certificates of Analysis published per released batch. Supplied strictly for laboratory research use.
Shop
All research compounds
Price list
Where to buy peptides
Compare compounds
Compare vial sizes
Affiliate programme
Research
Peptide 101
Published COAs
Research areas
Research blog
How-to guides
Peptide guides
Research glossary
Support
Track your order
Contact us
Shipping & delivery
International shipping
FAQ
Community forum
Refund policy
Ways to Pay
Google Pay
Apple Pay
Venmo
Cryptocurrency
Crypto wallets
Cash App
Card payments
Bank transfer (SEPA)
Paying with crypto
Live crypto prices
Shop by goal
Metabolic Research
GH-Axis Research
Muscle & IGF Research
Tissue and Cellular Models
Regenerative Research
Cellular Senescence Research
Cognitive Research
Multi-Compound Blends
Accessories
Shop by compound
BPC-157
TB-500
GHK-Cu
Tesamorelin
Retatrutide
Semaglutide
Tirzepatide
CJC-1295 (without DAC)
All compounds →
Shop by region
United Kingdom
United States
Australia
Canada
Canada (FR)
Ireland
Northern Ireland
Malta
Germany
France
Spain
Italy
Netherlands
Portugal
Greece
Austria
Poland
Sweden
Finland
Denmark
Norway
Croatia
Slovakia
Slovenia
Estonia
Latvia
Lithuania
Czechia
Hungary
Romania
Bulgaria
Belgium
Belgium (FR)
Luxembourg
Deutsch
Ελληνικά
Español
Français
Italiano
Research use only - all claims made on this site are for testing and research use only. Purchasers must be 21 years of age or older.
All rights reserved. Copyright of New-U held with Hilxera Distribution Services LLC 2026.
Website & business operated by Hilxera Distribution Services LLC. Registered in Wyoming, ID: 2026-001928701.
Principal office: 1712 Pioneer Ave., Ste. 500, Cheyenne, WY 82001, USA
© 2026 New-U Research Compounds · new-u.io
Research use only — not for human consumption. All products are supplied strictly for laboratory research purposes.
© 2026 New-U Research Compounds · new-u.io — Copyright held with Hilxera Distribution Services LLC. All rights reserved.