Skip to content

Responsible Disclosure Policy

The only change is the scrambled code inside the contact email link. The Atlantic hides its security contact address using Cloudflare's email-protection tool, which produces a different scrambled string each time the page is generated. The actual email address, the policy rules, and everything else are unchanged.

Cosmetic change: formatting, typos, or contact details.

20260831_rev01 → 20260901_rev01COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED
1717· Spamming
1818
1919· Social engineering (including phishing) of Atlantic Media staff or contractors
2020
2121· Any physical attempts against Atlantic Media property or data centers
2222
23While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#f18294928483988588b185999490859d909f859892df929e9c) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe!
23While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#2655434553544f525f66524e4347524a4748524f450845494b) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe!
± CHANGEDContact email link code refreshed

The security-contact email on the page is hidden behind a scrambled link to block spam bots. That scrambled code was regenerated, so the link text looks different. The email address it points to and the rest of the policy did not change.