Security
Last updated 2026-05-05. Effective immediately.
Reporting a vulnerability
Email security@hurrahreviews.com with a description of the issue, the affected URL or endpoint, and steps to reproduce. We acknowledge every report within 24 hours and aim to triage within 72 hours.
What’s in scope
hurrahreviews.comand any subdomain- The Pulse API surface under
/api/ - Authentication, session, and RLS policies
- Webhook signature verification (Resend, Stripe)
- OAuth flows (Google Business Profile)
What’s out of scope
- Denial-of-service attacks or any test that degrades service for other users
- Social-engineering OPT Digital staff or customers
- Physical attacks on infrastructure
- Findings from automated scanners without a working proof-of-concept
- Missing best-practice headers on routes that don’t materially affect security
Safe-harbour
We will not pursue legal action against researchers who:
- Make a good-faith effort to avoid privacy violations and data destruction
- Use only the access necessary to demonstrate the issue
- Give us a reasonable window to remediate before public disclosure
- Do not extort or threaten Hurrah or our customers
What you’ll get back from us
- Acknowledgement within 24 hours
- Triage decision (severity + remediation timeline) within 72 hours
- Public credit on a security-acknowledgements page if you want it
- For high-severity findings affecting customer data, written confirmation when the fix is deployed
Hurrah is operated by OPT Digital Limited (NZ). For privacy or compliance questions unrelated to a security vulnerability, see our Privacy Policy or email privacy@hurrahreviews.com.