Skip to main content

Ottawa transit rider information

Otranspo
FR
Back to rider information

Security and vulnerability reporting

Report a suspected vulnerability through the authorized security contact without exposing rider data or disrupting service.

How to report

Use the authorized security contact on the contact page. Include the affected URL or component, an impact description, minimal reproducible steps, and a safe way to respond. Do not include credentials, private reports, precise journeys, or another person’s data.

For an active emergency or immediate physical danger, contact 9-1-1 or the affected transit operator. The Otranspo security contact is not an emergency dispatch channel.

Testing boundary

Do not disrupt service, access data that is not yours, retain personal information, weaken controls, perform denial-of-service or social-engineering tests, or contact riders. Stop when a vulnerability or personal-data exposure is demonstrated.

Otranspo does not publish an unreviewed legal safe-harbour promise or a bug-bounty payment promise. Obtain explicit written authorization before intrusive testing.

Handling and disclosure

Reports are restricted to authorized security responders, correlated to an incident or finding, and retained under the security evidence policy. Public disclosure requires remediation, privacy review, and an authorized decision; acknowledgement or timing is not guaranteed until accountable contacts are configured.