Hurrah

Security

Last updated 2026-05-05. Effective immediately.

Reporting a vulnerability

Email security@hurrahreviews.com with a description of the issue, the affected URL or endpoint, and steps to reproduce. We acknowledge every report within 24 hours and aim to triage within 72 hours.

What’s in scope

  • hurrahreviews.com and any subdomain
  • The Pulse API surface under /api/
  • Authentication, session, and RLS policies
  • Webhook signature verification (Resend, Stripe)
  • OAuth flows (Google Business Profile)

What’s out of scope

  • Denial-of-service attacks or any test that degrades service for other users
  • Social-engineering OPT Digital staff or customers
  • Physical attacks on infrastructure
  • Findings from automated scanners without a working proof-of-concept
  • Missing best-practice headers on routes that don’t materially affect security

Safe-harbour

We will not pursue legal action against researchers who:

  • Make a good-faith effort to avoid privacy violations and data destruction
  • Use only the access necessary to demonstrate the issue
  • Give us a reasonable window to remediate before public disclosure
  • Do not extort or threaten Hurrah or our customers

What you’ll get back from us

  • Acknowledgement within 24 hours
  • Triage decision (severity + remediation timeline) within 72 hours
  • Public credit on a security-acknowledgements page if you want it
  • For high-severity findings affecting customer data, written confirmation when the fix is deployed

Hurrah is operated by OPT Digital Limited (NZ). For privacy or compliance questions unrelated to a security vulnerability, see our Privacy Policy or email privacy@hurrahreviews.com.