Public rider information
Security and vulnerability reporting
Report a suspected vulnerability through the authorized security contact without exposing rider data or disrupting service.
Ownership and accountability
Who is responsible for Otranspo
- Owner and operator
- One independent Ottawa–Gatineau citizen, named on the independence page
- Service responsibility
- The owner named above owns Otranspo and is accountable for its product, operations, privacy decisions, security response, and public explanations.
- Editorial control
- The owner named above makes the final editorial and publishing decisions. Transit agencies, cities, data providers, hosting companies, analytics providers, and donors do not direct coverage or conclusions.
- Funding model
- The owner named above bears the project’s operating costs. Otranspo carries no advertising. If voluntary donations are available, they do not buy access, favourable coverage, or editorial control.
- Official status
- Otranspo is not affiliated with, endorsed by, or operated by OC Transpo, STO, the City of Ottawa, or the Ville de Gatineau. It supplements official information and does not run transit service.
- Application explanation reviewed
- September 14, 2026
- Next source review due
- October 14, 2026
This review compares the public explanation with the current application source and configured capability rules. It is not a legal opinion or proof that a pending source revision has reached production. Current service health and published corrections have their own evidence pages.
Private message
Write to Otranspo
No account is required. This is Otranspo’s support queue, not an incident report to OC Transpo or STO. Messages are never published automatically.
This channel is not monitored for emergencies, and no response time is promised until a staffed support roster is published.
Private security channel
This category routes directly to Otranspo’s restricted privacy and security queue. Include only the affected page or component, impact, and minimal safe steps.
Do not paste an active password, API key, session token, private rider report, or another person’s information. Revoke or rotate an exposed secret first.
How to report
Use the authorized security contact on the contact page. Include the affected URL or component, an impact description, minimal reproducible steps, and a safe way to respond. Do not include credentials, private reports, precise journeys, or another person’s data.
For an active emergency or immediate physical danger, contact 9-1-1 or the affected transit operator. The Otranspo security contact is not an emergency dispatch channel.
Testing boundary
Do not disrupt service, access data that is not yours, retain personal information, weaken controls, perform denial-of-service or social-engineering tests, or contact riders. Stop when a vulnerability or personal-data exposure is demonstrated.
Otranspo does not publish an unreviewed legal safe-harbour promise or a bug-bounty payment promise. Obtain explicit written authorization before intrusive testing.
Handling and disclosure
Reports are restricted to authorized security responders, linked to the relevant incident or finding, and retained under the security evidence policy. Public disclosure requires repair, privacy review, and an authorized decision. If a specialized contact is unavailable, use the general Otranspo email and do not assume a response time.