Responsible Disclosure Policy
NOTEDWhat changed, in plain language
Nothing about the policy actually changed. The only difference is the scrambled code in the contact email link, which The Atlantic's website regenerates automatically to hide the address from spam bots. The rules for security researchers are word-for-word the same.
This change appears to be cosmetic (formatting, typos, or contact details).
Changelog
- ± CHANGEDContact email link code refreshed
The Atlantic uses a tool that scrambles its email address so spam bots can't read it. That scrambled code changed, but it still points to the same reporting address. No wording in the policy changed.
https://www.theatlantic.com/cdn-cgi/l/email-protection#aeddcbcddbdcc7dad7eedac6cbcfdac2cfc0dac7cd80cdc1c3
https://www.theatlantic.com/cdn-cgi/l/email-protection#deadbbbdabacb7aaa79eaab6bbbfaab2bfb0aab7bdf0bdb1b3
Full text changes — 20260812_rev01 to 20260813_rev01
COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED
| 17 | 17 | · Spamming |
| 18 | 18 | |
| 19 | 19 | · Social engineering (including phishing) of Atlantic Media staff or contractors |
| 20 | 20 | |
| 21 | 21 | · Any physical attempts against Atlantic Media property or data centers |
| 22 | 22 | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#aeddcbcddbdcc7dad7eedac6cbcfdac2cfc0dac7cd80cdc1c3) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#deadbbbdabacb7aaa79eaab6bbbfaab2bfb0aab7bdf0bdb1b3) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! |