Responsible Disclosure Policy
NOTEDWhat changed, in plain language
The only change is the scrambled code in the contact email link. The Atlantic uses Cloudflare's email-protection feature, which re-scrambles the address each time the page is served, so the underlying email address and every rule in the policy stay exactly the same.
This change appears to be cosmetic (formatting, typos, or contact details).
Changelog
- ± CHANGEDContact email link code changed (same address)
The website hides the security contact email behind a scrambled code so spam bots can't read it. That code was regenerated, so the link text in the page changed. The actual email address, and everything else in the policy, is unchanged.
https://www.theatlantic.com/cdn-cgi/l/email-protection#81f2e4e2f4f3e8f5f8c1f5e9e4e0f5ede0eff5e8e2afe2eeec
https://www.theatlantic.com/cdn-cgi/l/email-protection#1261777167607b666b52667a7773667e737c667b713c717d7f
Full text changes — 20260815_rev01 to 20260816_rev01
COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED
| 17 | 17 | · Spamming |
| 18 | 18 | |
| 19 | 19 | · Social engineering (including phishing) of Atlantic Media staff or contractors |
| 20 | 20 | |
| 21 | 21 | · Any physical attempts against Atlantic Media property or data centers |
| 22 | 22 | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#81f2e4e2f4f3e8f5f8c1f5e9e4e0f5ede0eff5e8e2afe2eeec) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#1261777167607b666b52667a7773667e737c667b713c717d7f) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! |