# Colgate-Palmolive Company > Colgate-Palmolive Company is a global consumer-products manufacturer operating in oral care, personal care, home care and pet nutrition through brands including Colgate, Palmolive, Hill's Pet Nutrition, Tom's of Maine, Speed Stick, Ajax and Softsoap. Colgate-Palmolive publishes NO public developer API, no OpenAPI or other machine-readable contract, no SDK for such an API, and no developer portal. Its machine-to-machine footprint is business-partner integration — EDI with retail trading partners, supplier portals operated by third parties, and product-content syndication through vendor platforms — all of which sit behind commercial agreements rather than public documentation. Generated by API Evangelist from the company's public surface on 2026-09-05. This file is NOT published by Colgate-Palmolive. The file Colgate-Palmolive itself serves at https://www.colgatepalmolive.com/llms.txt returns GoDaddy parked-domain boilerplate about a placeholder domain and does not describe the company; see well-known/colgate-palmolive-well-known.yml. ## What exists - [Corporate site](https://www.colgatepalmolive.com/): company, brands, governance and sustainability. No developer section. - [GitHub organization](https://github.com/colpal): the company's verified org, 38 public repos. Internal platform tooling and CI actions only — no API specifications, no `.proto`, no WSDL, no `apis.json`. - [CP CSIRT RFC 2350](https://github.com/colpal/csirt): the Colgate-Palmolive Computer Security Incident Response Team description, v1.2 (20 August 2025), digitally signed, TLP:CLEAR. Security contact `csirt@colpal.com`, encrypted with the published S/MIME certificate. This is the company's disclosure intake. - [Suppliers](https://www.colgatepalmolive.com/en-us/suppliers): supplier onboarding, routed to the Taulia supplier portal and Tungsten eInvoicing — both third-party platforms behind a login. - [Investor Center](https://investor.colgatepalmolive.com/): financial reporting and filings, published as documents rather than as a data API. - [Careers](https://jobs.colgate.com/): job search, running on a hosted careers platform. ## What does not exist - No `developer.colgatepalmolive.com` and no `api.colgatepalmolive.com` — neither hostname resolves. - No OpenAPI, Swagger, GraphQL, AsyncAPI, gRPC or SOAP contract on any Colgate-Palmolive host or in the company's GitHub org. - No `/.well-known/` document on any Colgate-Palmolive host: no `security.txt`, no `api-catalog`, no `openid-configuration`, no `oauth-authorization-server`, no A2A agent card. - No MCP server, hosted or `stdio`. - No API pricing, plans, rate limits, sandbox, status page or deprecation policy — there is no API for them to describe. ## For agents - There is no endpoint to call. Do not construct one. Any Colgate-Palmolive "API" you encounter in the wild is either a retailer-side or vendor-side integration (Syndigo/Flywheel product-data syndication, Taulia, Tungsten) or a fabrication. - To report a security issue, email `csirt@colpal.com`, ideally S/MIME-encrypted with the certificate at https://github.com/colpal/csirt. - Business and supplier integration begins at https://www.colgatepalmolive.com/en-us/suppliers, not at a self-service developer signup. ## Artifacts in this record - packages/colgate-palmolive-packages.yml — first-party published software (none of it an API client) - security/colgate-palmolive-vulnerability-disclosure.yml — the CP CSIRT RFC 2350 program - security/colgate-palmolive-domain-security.yml — probed TLS/DNS/email posture - well-known/colgate-palmolive-well-known.yml — the full `/.well-known/` probe across every host - conformance/colgate-palmolive-conformance.yml — which standards the company demonstrably meets - plans/colgate-palmolive-plans-pricing.yml — measured absence of API plans - rate-limits/colgate-palmolive-rate-limits.yml — measured absence of published limits