Responsible Disclosure Policy
Nothing about the policy changed. The only difference is the scrambled code in the link to The Atlantic's security contact email, which the site regenerates automatically to hide the address from spam bots. The email address itself, the rules for researchers, and the list of off-limits activities are all the same.
Cosmetic change: formatting, typos, or contact details.
| 17 | 17 | · Spamming |
| 18 | 18 | |
| 19 | 19 | · Social engineering (including phishing) of Atlantic Media staff or contractors |
| 20 | 20 | |
| 21 | 21 | · Any physical attempts against Atlantic Media property or data centers |
| 22 | 22 | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#deadbbbdabacb7aaa79eaab6bbbfaab2bfb0aab7bdf0bdb1b3) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#6516000610170c111c25110d00041109040b110c064b060a08) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! | |
± CHANGEDContact email link code refreshed The Atlantic hides its security contact email behind a scrambled code so spam bots can't read it. That code was regenerated, so the link text changed. The actual email address and everything else in the policy stayed the same. | ||