Skip to main content
HelpFR
Back to rider information

Public rider information

Security and vulnerability reporting

Report a suspected vulnerability through the authorized security contact without exposing rider data or disrupting service.

Ownership and accountability

Who is responsible for Otranspo

Owner and operator
One independent Ottawa–Gatineau citizen, named on the independence page
Service responsibility
The owner named above owns Otranspo and is accountable for its product, operations, privacy decisions, security response, and public explanations.
Editorial control
The owner named above makes the final editorial and publishing decisions. Transit agencies, cities, data providers, hosting companies, analytics providers, and donors do not direct coverage or conclusions.
Funding model
The owner named above bears the project’s operating costs. Otranspo carries no advertising. If voluntary donations are available, they do not buy access, favourable coverage, or editorial control.
Official status
Otranspo is not affiliated with, endorsed by, or operated by OC Transpo, STO, the City of Ottawa, or the Ville de Gatineau. It supplements official information and does not run transit service.
Application explanation reviewed
September 14, 2026
Next source review due
October 14, 2026

This review compares the public explanation with the current application source and configured capability rules. It is not a legal opinion or proof that a pending source revision has reached production. Current service health and published corrections have their own evidence pages.

Private message

Write to Otranspo

No account is required. This is Otranspo’s support queue, not an incident report to OC Transpo or STO. Messages are never published automatically.

This channel is not monitored for emergencies, and no response time is promised until a staffed support roster is published.

What do you need?Privacy or security

Private security channel

This category routes directly to Otranspo’s restricted privacy and security queue. Include only the affected page or component, impact, and minimal safe steps.

Do not paste an active password, API key, session token, private rider report, or another person’s information. Revoke or rotate an exposed secret first.

Would you like a reply?

Attachments are not accepted. Do not include passwords, tokens, payment information, exact location, or medical detail.

4,000 characters maximum

How to report

Use the authorized security contact on the contact page. Include the affected URL or component, an impact description, minimal reproducible steps, and a safe way to respond. Do not include credentials, private reports, precise journeys, or another person’s data.

For an active emergency or immediate physical danger, contact 9-1-1 or the affected transit operator. The Otranspo security contact is not an emergency dispatch channel.

Testing boundary

Do not disrupt service, access data that is not yours, retain personal information, weaken controls, perform denial-of-service or social-engineering tests, or contact riders. Stop when a vulnerability or personal-data exposure is demonstrated.

Otranspo does not publish an unreviewed legal safe-harbour promise or a bug-bounty payment promise. Obtain explicit written authorization before intrusive testing.

Handling and disclosure

Reports are restricted to authorized security responders, linked to the relevant incident or finding, and retained under the security evidence policy. Public disclosure requires repair, privacy review, and an authorized decision. If a specialized contact is unavailable, use the general Otranspo email and do not assume a response time.