Responsible Disclosure Policy
The only change is a new scrambled email link for reporting security issues — the address behind Cloudflare's email-protection encoding was re-encoded. The policy text itself is identical.
Cosmetic change: formatting, typos, or contact details.
| 17 | 17 | · Spamming |
| 18 | 18 | |
| 19 | 19 | · Social engineering (including phishing) of Atlantic Media staff or contractors |
| 20 | 20 | |
| 21 | 21 | · Any physical attempts against Atlantic Media property or data centers |
| 22 | 22 | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#4e3d2b2d3b3c273a370e3a262b2f3a222f203a272d602d2123) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#f18294928483988588b185999490859d909f859892df929e9c) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! | |
± CHANGEDSecurity contact email link re-encoded The link people use to report a security problem was updated. The Atlantic hides this email address behind Cloudflare's scrambling tool, and the scrambled version changed. Nothing about the policy, the rules for researchers, or what you can report changed. | ||