Responsible Disclosure Policy
NOTEDFIRST SEEN 2026-09-03 · VERSION 20260903_rev01 · COMPARED WITH 20260902_rev01
What changed, in plain language
The only change is to an obfuscated contact email link — the scrambled code in the URL was updated. No policy terms changed.
This change appears to be cosmetic (formatting, typos, or contact details).
Changelog
- ± CHANGEDContact email link code updated
The security contact email is hidden behind a scrambling system to block spam bots. The scrambled code in that link was refreshed. The email address it points to and everything else in the policy stay the same.
https://www.theatlantic.com/cdn-cgi/l/email-protection#c9baacaabcbba0bdb089bda1aca8bda5a8a7bda0aae7aaa6a4
https://www.theatlantic.com/cdn-cgi/l/email-protection#f380969086819a878ab3879b9692879f929d879a90dd909c9e
Full text changes — 20260902_rev01 to 20260903_rev01
COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED
| 17 | 17 | · Spamming |
| 18 | 18 | |
| 19 | 19 | · Social engineering (including phishing) of Atlantic Media staff or contractors |
| 20 | 20 | |
| 21 | 21 | · Any physical attempts against Atlantic Media property or data centers |
| 22 | 22 | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#c9baacaabcbba0bdb089bda1aca8bda5a8a7bda0aae7aaa6a4) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#f380969086819a878ab3879b9692879f929d879a90dd909c9e) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! |