Responsible Disclosure Policy
NOTEDFIRST SEEN 2026-08-25 · VERSION 20260825_rev01 · COMPARED WITH 20260824_rev01
What changed, in plain language
The only change is an updated obfuscation code in the security contact email link. The policy itself is unchanged.
This change appears to be cosmetic (formatting, typos, or contact details).
Changelog
- ± CHANGEDSecurity contact email link code changed
The scrambled code in the link for the security contact email was replaced with a different scrambled code. This is how the site hides the address from spam bots, and it does not change any rule in the policy.
https://www.theatlantic.com/cdn-cgi/l/email-protection#ee9d8b8d9b9c879a97ae9a868b8f9a828f809a878dc08d8183
https://www.theatlantic.com/cdn-cgi/l/email-protection#deadbbbdabacb7aaa79eaab6bbbfaab2bfb0aab7bdf0bdb1b3
Full text changes — 20260824_rev01 to 20260825_rev01
COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED
| 17 | 17 | · Spamming |
| 18 | 18 | |
| 19 | 19 | · Social engineering (including phishing) of Atlantic Media staff or contractors |
| 20 | 20 | |
| 21 | 21 | · Any physical attempts against Atlantic Media property or data centers |
| 22 | 22 | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#ee9d8b8d9b9c879a97ae9a868b8f9a828f809a878dc08d8183) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#deadbbbdabacb7aaa79eaab6bbbfaab2bfb0aab7bdf0bdb1b3) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! |