Responsible Disclosure Policy
NOTEDFIRST SEEN 2026-08-29 · VERSION 20260829_rev01 · COMPARED WITH 20260828_rev01
What changed, in plain language
The only change is the scrambled email-protection code in the contact link for reporting security issues. The email address itself and every policy rule stayed the same.
This change appears to be cosmetic (formatting, typos, or contact details).
Changelog
- ± CHANGEDSecurity contact link code updated
The website uses a scrambling trick to hide the security contact email from spam bots. That scrambled code was refreshed. The email address you reach and what the page tells you to do are unchanged.
https://www.theatlantic.com/cdn-cgi/l/email-protection#d6a5b3b5a3a4bfa2af96a2beb3b7a2bab7b8a2bfb5f8b5b9bb
https://www.theatlantic.com/cdn-cgi/l/email-protection#2e5d4b4d5b5c475a576e5a464b4f5a424f405a474d004d4143
Full text changes — 20260828_rev01 to 20260829_rev01
COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED
| 17 | 17 | · Spamming |
| 18 | 18 | |
| 19 | 19 | · Social engineering (including phishing) of Atlantic Media staff or contractors |
| 20 | 20 | |
| 21 | 21 | · Any physical attempts against Atlantic Media property or data centers |
| 22 | 22 | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#d6a5b3b5a3a4bfa2af96a2beb3b7a2bab7b8a2bfb5f8b5b9bb) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#2e5d4b4d5b5c475a576e5a464b4f5a424f405a474d004d4143) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! |