Responsible Disclosure Policy
Nothing in this policy actually changed. The only difference is the scrambled code in the link for the security contact email address, which the site's spam-protection tool regenerates on every page load. The email address it points to is the same one as before, and every rule about reporting security issues is unchanged.
Cosmetic change: formatting, typos, or contact details.
| 17 | 17 | · Spamming |
| 18 | 18 | |
| 19 | 19 | · Social engineering (including phishing) of Atlantic Media staff or contractors |
| 20 | 20 | |
| 21 | 21 | · Any physical attempts against Atlantic Media property or data centers |
| 22 | 22 | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#4635232533342f323f06322e2327322a2728322f256825292b) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#c7b4a2a4b2b5aeb3be87b3afa2a6b3aba6a9b3aea4e9a4a8aa) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! | |
± CHANGEDContact email link code regenerated (no real change) The Atlantic hides its security contact email behind a scrambling tool so spam bots can't read it. That scrambled code was regenerated, so the link text looks different. It still leads to the exact same email address, and the sentence around it is word-for-word identical. | ||