Responsible Disclosure Policy
NOTEDWhat changed, in plain language
Nothing about the policy itself changed. The only difference is the scrambled code in the contact email link, which the site's spam-protection system regenerates automatically. All rules for security researchers stay exactly the same.
This change appears to be cosmetic (formatting, typos, or contact details).
Changelog
- ± CHANGEDContact email link code refreshed
The Atlantic hides its security contact email behind a scrambling service so spam bots can't read it. That scrambled code was regenerated, so the link text changed. The email address it points to and everything else in the policy are unchanged.
https://www.theatlantic.com/cdn-cgi/l/email-protection#1261777167607b666b52667a7773667e737c667b713c717d7f
https://www.theatlantic.com/cdn-cgi/l/email-protection#5320363026213a272a13273b3632273f323d273a307d303c3e
Full text changes — 20260816_rev01 to 20260817_rev01
COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED
| 17 | 17 | · Spamming |
| 18 | 18 | |
| 19 | 19 | · Social engineering (including phishing) of Atlantic Media staff or contractors |
| 20 | 20 | |
| 21 | 21 | · Any physical attempts against Atlantic Media property or data centers |
| 22 | 22 | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#1261777167607b666b52667a7773667e737c667b713c717d7f) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#5320363026213a272a13273b3632273f323d273a307d303c3e) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! |