Report a security issue
Found a vulnerability in kdts.ca or a KDTS system? Email security@kdts.ca.
What to include
- What you found and where
- Steps to reproduce it
- How we can reach you
Please don't
- Test against our clients' systems. Only kdts.ca and KDTS-owned systems are in scope.
- Access, change or delete data that isn't yours
- Run denial-of-service tests, social engineering or physical attempts
- Share the issue publicly before we've had a reasonable chance to fix it
What happens next
We aim to acknowledge reports within two business days and will keep you updated while we investigate. We don't run a paid bug bounty, but we appreciate good-faith reports and will credit you if you'd like.
Our machine-readable contact details are in security.txt.