generated: '2026-09-05' method: searched source: >- https://github.com/colpal/csirt — the Colgate-Palmolive Company CSIRT repository, published by the company's own verified GitHub organization (github.com/colpal, "Colgate-Palmolive Company", is_verified: true), carrying the signed RFC 2350 team description, its SHA256 signature, and the CP CSIRT S/MIME public certificate. Document contents read from RFC2350.pdf v1.2, revised 20 August 2025. name: Colgate-Palmolive Company Computer Security Incident Response Team short_name: CP CSIRT program: type: incident-response-team standard: RFC 2350 document_version: '1.2' document_created: '2024-02-14' document_revised: '2025-08-20' tlp: CLEAR signed: true signature_algorithm: SHA256 over RFC2350.pdf, S/MIME digital certificate bug_bounty: false bounty_platform: null safe_harbor_stated: false note: >- Colgate-Palmolive does not run a public bug bounty and publishes no /.well-known/security.txt on any of its web properties (probed 2026-09-05, see well-known/colgate-palmolive-well-known.yml). Its disclosure surface is instead an RFC 2350 CSIRT description published to a public GitHub repository — a documented, signed, contactable intake channel, but one a researcher only finds by knowing the org exists. contact: email: csirt@colpal.com phone: '+1-212-310-2000' phone_note: United States only; toll-free incident reporting line. preferred_method: email encryption: scheme: S/MIME certificate_url: https://raw.githubusercontent.com/colpal/csirt/main/CPCSIRTPublic.pem certificate_file: security/colgate-palmolive-csirt-smime-public.pem note: >- Reporters are asked to encrypt incident reports with the CP CSIRT S/MIME public certificate where possible. locations: - country: US address: 909 River Rd, Piscataway, NJ 08854, United States - country: IN address: 8th Floor, Prima Bay, L&T Gate No 5, Saki Vihar Road, Powai, Mumbai, Maharashtra 400072 timezones: - EST - IST constituency: >- The employees and business partners of Colgate-Palmolive Company. The CP CSIRT operates under the authority of Colgate-Palmolive Company and coordinates incident response across the organization and its subsidiaries. scope: incident_types: >- All types of computer security incidents which occur, or threaten to occur, at the CP CSIRT constituency. Level of support varies with the type and severity of the incident. cooperation: >- CP CSIRT cooperates with other teams, organizations and law enforcement agencies as necessary. Information disclosure is governed by Colgate-Palmolive's data protection and privacy policies. report_fields: - Contact details — name of person, organization name and address, email address, telephone number - Short summary of the incident / emergency / crisis and type of event - Affected system(s) - Estimated impact (e.g. loss of communications) - Additional information — observations that led to discovery, scanning results, log extracts, screenshots documents: - name: RFC 2350 team description url: https://github.com/colpal/csirt/blob/main/RFC2350.pdf file: security/colgate-palmolive-rfc2350.pdf http_status: 200 fetched: '2026-09-05' - name: CP CSIRT S/MIME public certificate url: https://github.com/colpal/csirt/blob/main/CPCSIRTPublic.pem file: security/colgate-palmolive-csirt-smime-public.pem http_status: 200 fetched: '2026-09-05' - name: SHA256 signature of RFC2350.pdf url: https://github.com/colpal/csirt/blob/main/RFC2350.pdf.sig http_status: 200 fetched: '2026-09-05' x-evidence: fetched: '2026-09-05' repository: https://github.com/colpal/csirt repository_status: 200 org_verified: true org_url: https://github.com/colpal