Responsible Disclosure Policy

NOTED
FIRST SEEN 2026-08-19 · VERSION 20260819_rev01 · COMPARED WITH 20260818_rev01

What changed, in plain language

The only change is a rewritten obfuscated email link for reporting security issues. The wording of the policy is identical — no rules, rights, or obligations changed.

This change appears to be cosmetic (formatting, typos, or contact details).

Changelog

  1. ± CHANGEDSecurity contact email link updated

    The scrambled link used to hide the security contact email address from spam bots was regenerated. The visible text and everything else on the page stayed the same.

    https://www.theatlantic.com/cdn-cgi/l/email-protection#0b786e687e79627f724b7f636e6a7f676a657f626825686466

    https://www.theatlantic.com/cdn-cgi/l/email-protection#1b687e786e69726f625b6f737e7a6f777a756f727835787476

Full text changes — 20260818_rev01 to 20260819_rev01

COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED

1717· Spamming
1818
1919· Social engineering (including phishing) of Atlantic Media staff or contractors
2020
2121· Any physical attempts against Atlantic Media property or data centers
2222
23While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#0b786e687e79627f724b7f636e6a7f676a657f626825686466) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe!
23While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#1b687e786e69726f625b6f737e7a6f777a756f727835787476) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe!