generated: '2026-09-13' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts hosts: - host: www.publicisgroupe.com https: true tls_version: TLSv1.2 cert_expires: Mar 7 23:59:59 2027 GMT hsts: true hsts_max_age: 16070400 - host: knowhow.suite.publicissapient.com https: true tls_version: TLSv1.3 cert_expires: Mar 1 23:59:59 2027 GMT hsts: true hsts_max_age: 63072000 - host: www.publicissapient.com https: true tls_version: TLSv1.3 cert_expires: Dec 3 23:59:59 2026 GMT hsts: true hsts_max_age: 63072000 domains: - domain: publicisgroupe.com dnssec: false caa: [] spf: true dmarc: true dmarc_policy: none - domain: publicissapient.com dnssec: false caa: [] spf: true dmarc: true dmarc_policy: none observations: - host: dev.sapientslingshot.com finding: >- TLS certificate expired. The wildcard *.sapientslingshot.com certificate issued by GoDaddy Secure Certificate Authority - G2 ran from 2025-05-09 to 2026-05-09 and was still being served on 2026-09-13, so the host fails default certificate validation. Probed 2026-09-13. - host: dev-slingshot.sapientaiproducts.com finding: >- dev.sapientslingshot.com redirects here, and this host answers HTTP 200 with a Prometheus exposition payload (Content-Type text/plain; version=0.0.4) for every path probed, including /, /docs, /health and /openapi.json. It is an unauthenticated metrics endpoint on a development deployment, not an API contract, and no spec was derived from it. Probed 2026-09-13. - scope_note: >- Hosts probed by the script are those named in apis.yml. sapientslingshot.com and sapientaiproducts.com are not apis.yml hosts; the two findings above were recorded during contract discovery.