Skip to content

Responsible Disclosure Policy

The only change is to the obfuscated email link code for the security contact address. The wording of the policy is identical. This is a technical/cosmetic update with no effect on consumers.

Cosmetic change: formatting, typos, or contact details.

20260826_rev01 → 20260827_rev01COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED
1717· Spamming
1818
1919· Social engineering (including phishing) of Atlantic Media staff or contractors
2020
2121· Any physical attempts against Atlantic Media property or data centers
2222
23While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#e89b8d8b9d9a819c91a89c808d899c8489869c818bc68b8785) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe!
23While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#7b081e180e09120f023b0f131e1a0f171a150f121855181416) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe!
± CHANGEDSecurity contact email link code changed

The scrambled code behind the 'email protected' link for reporting security issues was updated. The visible text and the policy itself did not change. This is how the site hides the email address from spam bots, and it can change when the page is regenerated.