Ottawa transit rider information
Independent information — not affiliated with OC Transpo or STO
Security and vulnerability reporting
Report a suspected vulnerability through the authorized security contact without exposing rider data or disrupting service.
How to report
Use the authorized security contact on the contact page. Include the affected URL or component, an impact description, minimal reproducible steps, and a safe way to respond. Do not include credentials, private reports, precise journeys, or another person’s data.
For an active emergency or immediate physical danger, contact 9-1-1 or the affected transit operator. The Otranspo security contact is not an emergency dispatch channel.
Testing boundary
Do not disrupt service, access data that is not yours, retain personal information, weaken controls, perform denial-of-service or social-engineering tests, or contact riders. Stop when a vulnerability or personal-data exposure is demonstrated.
Otranspo does not publish an unreviewed legal safe-harbour promise or a bug-bounty payment promise. Obtain explicit written authorization before intrusive testing.
Handling and disclosure
Reports are restricted to authorized security responders, correlated to an incident or finding, and retained under the security evidence policy. Public disclosure requires remediation, privacy review, and an authorized decision; acknowledgement or timing is not guaranteed until accountable contacts are configured.