generated: '2026-09-13' method: searched source: >- https://publicisgroupe-csr-smart-data.com/assets/upload/en/Information%20Security%202020.pdf (Publicis Groupe, "Information Security", from JANUS — Publicis Groupe Code of Ethics) and first-party source in PublicisSapient/knowhow-mcp; read 2026-09-13 name: Publicis Groupe — standards and compliance conformance conformance: - id: iso-27001 conforms: true scope: partial evidence: https://publicisgroupe-csr-smart-data.com/assets/upload/en/Information%20Security%202020.pdf statement: >- "Publicis Groupe has adopted industry-recognized ISO 27001 information security standard as baseline on which the global security program has been built. Certain critical business areas are formally ISO 27001 certified and undergo periodic external audits with the certifying organizations." The document names backend IT shared services infrastructure and the Epsilon business as examples of certified scope, and states the ISMS is audited annually by an external certification body. note: >- Scope is explicitly partial — the Groupe claims ISO 27001 alignment group-wide and certification only for named business areas. It is not a group-wide certification and is not recorded as one. - id: iso-22301 conforms: unknown evidence: https://publicisgroupe-csr-smart-data.com/assets/upload/en/Information%20Security%202020.pdf statement: >- The Global Security Organisation's remit includes "Business continuity framework (e.g. ISO 22301) adoption, implementation and certifications". The document does not state that certification has been achieved, so conformance is left unknown rather than asserted. - id: gdpr conforms: true evidence: https://publicisgroupe-csr-smart-data.com/assets/upload/en/Information%20Security%202020.pdf statement: >- The security policies are stated to "address the requirements regulations such as the European General Data Protection Regulation (GDPR)". Publicis Groupe is French-headquartered and publishes a privacy and cookies notice at https://www.publicisgroupe.com/en/cookies. - id: soc-2 conforms: false evidence: https://publicisgroupe-csr-smart-data.com/assets/upload/en/Information%20Security%202020.pdf statement: >- SOC 1 / SOC 2 appear in this document only as certifications held by the Groupe's DATACENTER PROVIDERS, not by Publicis Groupe. Recorded explicitly as a non-claim so a later pass does not misread the mention as a first-party certification. - id: mcp-2024-11-05 conforms: true evidence: >- https://github.com/PublicisSapient/knowhow-mcp — McpService.java returns protocolVersion "2024-11-05" from initialize, and McpController implements the HTTP+SSE transport (GET /mcp/sse issuing an `endpoint` event, POST /mcp/messages). statement: >- knowhow-mcp implements Model Context Protocol revision 2024-11-05 with the legacy HTTP+SSE transport. @psnext/lscg exposes a second MCP server over stdio; its protocol revision is not stated in the published README. note: >- 2024-11-05 is a superseded MCP revision; the current Streamable HTTP transport is not implemented. - id: oauth2 conforms: partial evidence: '@psnext/slingcli README — "/login slingshot and complete login in the browser window that opens"' statement: >- Slingshot uses an interactive browser authorization flow and bearer access tokens, but publishes no authorization-server metadata, no scope reference and no token endpoint, so the flow cannot be independently verified as RFC 6749 / RFC 8414 conformant. - id: rfc9457 conforms: false evidence: no public error contract was found on any Publicis Groupe host statement: No RFC 9457 problem+json error envelope is published for any Groupe API surface. - id: domain-standard conforms: false statement: >- Publicis Groupe's market (advertising and media) has live domain standards — OpenRTB, IAB tech-lab specifications, ads.txt/sellers.json — but the Groupe publishes no contract of its own that declares one. Its bidding and identity surfaces are operated by Epsilon and CJ Affiliate, which are profiled separately. Reward-only check: recorded as absent, not penalised, and deliberately not invented. compliance_program: published: true documents: - name: Information Security (from JANUS — Publicis Groupe Code of Ethics) url: https://publicisgroupe-csr-smart-data.com/assets/upload/en/Information%20Security%202020.pdf - name: Global Data Privacy Policy Summary (JANUS appendix) url: https://publicisgroupe-csr-smart-data.com/assets/upload/en/Janus_Data_Privacy_appendix.pdf - name: CSR Smart Data library url: https://publicisgroupe-csr-smart-data.com/en/links certifications: - ISO 27001 (partial scope — named business areas, externally audited annually) frameworks: - ISO 27001 - ISO 22301 (adoption stated, certification not claimed) - GDPR counts: asserted: 8 conforming: 4