Responsible Disclosure Policy

NOTED
FIRST SEEN 2026-08-30 · VERSION 20260830_rev01 · COMPARED WITH 20260829_rev01

What changed, in plain language

The only change is the scrambled email-protection code in the contact link for reporting security issues. The email address itself and every policy term stayed the same.

This change appears to be cosmetic (formatting, typos, or contact details).

Changelog

  1. ± CHANGEDContact link code refreshed

    The site's spam-protection code inside the security contact link was regenerated. The link still points to the same reporting inbox, and no wording in the policy changed.

    https://www.theatlantic.com/cdn-cgi/l/email-protection#2e5d4b4d5b5c475a576e5a464b4f5a424f405a474d004d4143

    https://www.theatlantic.com/cdn-cgi/l/email-protection#4e3d2b2d3b3c273a370e3a262b2f3a222f203a272d602d2123

Full text changes — 20260829_rev01 to 20260830_rev01

COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED

1717· Spamming
1818
1919· Social engineering (including phishing) of Atlantic Media staff or contractors
2020
2121· Any physical attempts against Atlantic Media property or data centers
2222
23While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#2e5d4b4d5b5c475a576e5a464b4f5a424f405a474d004d4143) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe!
23While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#4e3d2b2d3b3c273a370e3a262b2f3a222f203a272d602d2123) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe!