Responsible Disclosure Policy
NOTEDWhat changed, in plain language
The only change is a new obfuscated string in the email-protection link for the security contact address. The visible text, policy rules, and exclusions are identical. This is a cosmetic/technical change with no effect on consumers.
This change appears to be cosmetic (formatting, typos, or contact details).
Changelog
- ± CHANGEDSecurity contact email link code changed
The scrambled code in the link behind the security contact email was replaced with a different one. The email is hidden by anti-spam scrambling, so the code changes on its own from time to time. Nothing about how or where to report a security problem changed.
https://www.theatlantic.com/cdn-cgi/l/email-protection#c7b4a2a4b2b5aeb3be87b3afa2a6b3aba6a9b3aea4e9a4a8aa
https://www.theatlantic.com/cdn-cgi/l/email-protection#aeddcbcddbdcc7dad7eedac6cbcfdac2cfc0dac7cd80cdc1c3
Full text changes — 20260811_rev02 to 20260812_rev01
COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED
| 17 | 17 | · Spamming |
| 18 | 18 | |
| 19 | 19 | · Social engineering (including phishing) of Atlantic Media staff or contractors |
| 20 | 20 | |
| 21 | 21 | · Any physical attempts against Atlantic Media property or data centers |
| 22 | 22 | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#c7b4a2a4b2b5aeb3be87b3afa2a6b3aba6a9b3aea4e9a4a8aa) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#aeddcbcddbdcc7dad7eedac6cbcfdac2cfc0dac7cd80cdc1c3) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! |