Security
Security
WorkRadar Canada accepts good-faith reports of potential security issues from anyone who finds one. This page explains how to report a concern and the boundaries we ask every reporter to stay within.
How to report
If you believe you have found a potential security issue, please send it to us through the Support page. A useful report includes:
- A clear description of the potential issue.
- The minimal safe reproduction information you already have — not a full walkthrough built by testing further.
- The realistic impact, as best you can tell.
- The date you found it.
- A way for us to reach you.
If you already have information about an issue
If you already possess information about a potential issue, please send us what you already have. Please do not continue testing, verifying, scanning, exploiting, or reproducing it further, and do not access or view any additional accounts or data to prove it. Sending what you already know is enough for us to look into it.
What we ask you not to do
This page does not authorize security testing against WorkRadar Canada. To keep real candidates, employers, and their data safe, we ask that you do not:
- Access, view, copy, or download another person's account or private data.
- Bypass authentication, email verification, or role/company access controls.
- Bypass payment controls, or test Stripe or other payment flows without our written permission.
- Attempt privilege escalation against real accounts.
- Modify, delete, or publish any data.
- Guess passwords or perform credential stuffing.
- Run automated abuse, scanning, fuzzing, or load testing.
- Attempt to disrupt or degrade WorkRadar Canada's availability (DoS/DDoS).
If you have already identified an issue, please do not continue testing merely to prove it further, and please do not reproduce it against real users or real data.
What WorkRadar Canada does not promise
WorkRadar Canada does not operate a public bug bounty program, and does not guarantee a reward, compensation, payment, or reimbursement for any report. Any recognition or compensation, if WorkRadar Canada ever chooses to consider it, is entirely discretionary and does not create an obligation.
WorkRadar Canada may review a report, but does not promise a response time, confirmation that a report is valid, a remediation timeline, or compensation of any kind.
FAQ
Does WorkRadar Canada run a bug bounty program?
No. WorkRadar Canada does not operate a public bug bounty program and does not guarantee a reward, compensation, payment, or reimbursement for a report. If WorkRadar Canada ever chooses to recognize or compensate a report, that decision is entirely discretionary and does not create an obligation.
Am I authorized to test WorkRadar Canada for vulnerabilities?
This page does not authorize security testing of any kind. Please report what you already know instead of probing further. See "What we ask you not to do" below.
Will I get a response, or know when an issue is fixed?
WorkRadar Canada may review a report, but does not promise a response time, confirmation, or a specific remediation timeline.
How do I send a report?
Use the Support page. Include a clear description, the minimal safe reproduction information you already have, the realistic impact, the date you found it, and a way to reach you.
