Responsible Disclosure Policy

NOTED
FIRST SEEN 2026-09-02 · VERSION 20260902_rev01 · COMPARED WITH 20260901_rev01

What changed, in plain language

Nothing meaningful changed. The only difference is the scrambled code in the contact email link, which the site's spam-protection tool regenerates automatically. The policy's rules for security researchers are identical.

This change appears to be cosmetic (formatting, typos, or contact details).

Changelog

  1. ± CHANGEDContact email link code refreshed

    The security contact email is hidden behind an automatic spam-protection scrambler, and that scrambled code was regenerated. The email address itself and everything else in the policy stayed the same.

    https://www.theatlantic.com/cdn-cgi/l/email-protection#2655434553544f525f66524e4347524a4748524f450845494b

    https://www.theatlantic.com/cdn-cgi/l/email-protection#c9baacaabcbba0bdb089bda1aca8bda5a8a7bda0aae7aaa6a4

Full text changes — 20260901_rev01 to 20260902_rev01

COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED

1717· Spamming
1818
1919· Social engineering (including phishing) of Atlantic Media staff or contractors
2020
2121· Any physical attempts against Atlantic Media property or data centers
2222
23While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#2655434553544f525f66524e4347524a4748524f450845494b) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe!
23While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#c9baacaabcbba0bdb089bda1aca8bda5a8a7bda0aae7aaa6a4) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe!