Responsible Disclosure Policy
NOTEDWhat changed, in plain language
The only change is a rotated email-obfuscation code in the link to the security contact address. The wording of the policy is identical, so nothing about your rights or the researcher rules changed.
This change appears to be cosmetic (formatting, typos, or contact details).
Changelog
- ± CHANGEDSecurity contact link code updated
The scrambled code The Atlantic uses to hide its security contact email from spam bots was regenerated. The visible text, the address it points to, and every rule in the policy stayed the same.
https://www.theatlantic.com/cdn-cgi/l/email-protection#186b7d7b6d6a716c61586c707d796c7479766c717b367b7775
https://www.theatlantic.com/cdn-cgi/l/email-protection#e09385839592899499a094888581948c818e948983ce838f8d
Full text changes — 20260822_rev01 to 20260823_rev01
COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED
| 17 | 17 | · Spamming |
| 18 | 18 | |
| 19 | 19 | · Social engineering (including phishing) of Atlantic Media staff or contractors |
| 20 | 20 | |
| 21 | 21 | · Any physical attempts against Atlantic Media property or data centers |
| 22 | 22 | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#186b7d7b6d6a716c61586c707d796c7479766c717b367b7775) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#e09385839592899499a094888581948c818e948983ce838f8d) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! |