Responsible Disclosure Policy
NOTEDWhat changed, in plain language
The only change is to the obfuscated contact email link — the scrambled code in the URL was regenerated. The actual policy text, rules, and exclusions are identical. Nothing about your rights or the company's obligations changed.
This change appears to be cosmetic (formatting, typos, or contact details).
Changelog
- ± CHANGEDContact email link code regenerated
The Atlantic uses a spam-protection service that scrambles email addresses in the page code. That scrambled string was regenerated, so the link looks different but points to the same reporting contact. No wording in the policy changed.
https://www.theatlantic.com/cdn-cgi/l/email-protection#7b081e180e09120f023b0f131e1a0f171a150f121855181416
https://www.theatlantic.com/cdn-cgi/l/email-protection#d6a5b3b5a3a4bfa2af96a2beb3b7a2bab7b8a2bfb5f8b5b9bb
Full text changes — 20260827_rev01 to 20260828_rev01
COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED
| 17 | 17 | · Spamming |
| 18 | 18 | |
| 19 | 19 | · Social engineering (including phishing) of Atlantic Media staff or contractors |
| 20 | 20 | |
| 21 | 21 | · Any physical attempts against Atlantic Media property or data centers |
| 22 | 22 | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#7b081e180e09120f023b0f131e1a0f171a150f121855181416) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#d6a5b3b5a3a4bfa2af96a2beb3b7a2bab7b8a2bfb5f8b5b9bb) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! |