Skip to content

Responsible Disclosure Policy

The Atlantic published a new Responsible Disclosure Policy inviting security researchers to report bugs privately. It asks finders to report quickly, wait a "reasonable" time before going public, avoid privacy violations and data destruction, and stay away from denial-of-service, spamming, social engineering, and physical attacks. There is no formal reporting system — reports go to an email address. Nothing here changes ordinary readers' or subscribers' rights, and the policy promises no reward and no legal protection to researchers.

Researchers are asked to stay quiet, but get nothing in returnIf you find a security flaw, the policy asks you to keep it private for a "reasonable…

If you find a security flaw, the policy asks you to keep it private for a "reasonable amount of time" — a period the company never defines. In exchange, it does not promise a reward, and it does not promise it won't take legal action against you for testing in good faith (what other companies call a "safe harbor"). So the obligation runs one way. This only affects people who go looking for bugs, not regular readers or subscribers.

“Provide us a reasonable amount of time to resolve the issue before any disclosure to the public or a third-party.”

What you can do — If you find a security problem, report it to the listed email address rather than posting it publicly, keep a dated copy of what you sent, and ask for a specific fix timeline in writing before agreeing to stay quiet.

USER OBLIGATIONS
20260811_rev01COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED
1No technology is perfect, and The Atlantic believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. If you believe you've found a security issue in our product or service, we encourage you to notify us. We welcome working with you to resolve the issue promptly.
+ ADDEDNew responsible disclosure policy published

The Atlantic added a page telling people how to report security problems they find in its site or apps. It says it wants to work with researchers and fix issues quickly.

2
3**Disclosure Policy**
4
5· Let us know as soon as possible upon discovery of a potential security issue, and we'll make every effort to quickly resolve the issue.
6
7· Provide us a reasonable amount of time to resolve the issue before any disclosure to the public or a third-party.
+ ADDEDRules for people who report a bug

Anyone who finds a security hole is asked to tell The Atlantic right away, hold off on telling the public or anyone else until it's fixed, and avoid snooping in other people's accounts or breaking anything while testing.

8
9· Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit permission of the account holder.
10
11**Exclusions**
12
13While researching, we'd like to ask you to refrain from:
+ ADDEDTesting methods that are off-limits

The policy asks researchers not to knock the service offline, send spam, trick staff or contractors into giving up access, or try to get into buildings and data centers physically.

14
15· Denial of service
16
17· Spamming
18
19· Social engineering (including phishing) of Atlantic Media staff or contractors
20
21· Any physical attempts against Atlantic Media property or data centers
22
23While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#4635232533342f323f06322e2327322a2728322f256825292b) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe!
+ ADDEDNo formal bug-reporting system — email only

There is no bug bounty program or reporting portal. Reports go to a single email address, and the page asks only for "critical" issues.