Responsible Disclosure Policy
NOTEDWhat changed, in plain language
The only change is a rotated email-obfuscation code in the contact link. The address behind the link is the same; nothing about the policy's rules or your rights changed.
This change appears to be cosmetic (formatting, typos, or contact details).
Changelog
- ± CHANGEDContact link's scrambled email code changed
The Atlantic uses a Cloudflare tool that scrambles its security contact email so spam bots can't read it. That scrambled code was regenerated, so the link ends with different characters. The policy text, the rules for researchers, and where reports go are all unchanged.
https://www.theatlantic.com/cdn-cgi/l/email-protection#deadbbbdabacb7aaa79eaab6bbbfaab2bfb0aab7bdf0bdb1b3
https://www.theatlantic.com/cdn-cgi/l/email-protection#e89b8d8b9d9a819c91a89c808d899c8489869c818bc68b8785
Full text changes — 20260825_rev01 to 20260826_rev01
COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED
| 17 | 17 | · Spamming |
| 18 | 18 | |
| 19 | 19 | · Social engineering (including phishing) of Atlantic Media staff or contractors |
| 20 | 20 | |
| 21 | 21 | · Any physical attempts against Atlantic Media property or data centers |
| 22 | 22 | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#deadbbbdabacb7aaa79eaab6bbbfaab2bfb0aab7bdf0bdb1b3) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#e89b8d8b9d9a819c91a89c808d899c8489869c818bc68b8785) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! |