Omnicom Group · Vulnerability Disclosure
Omnicom Vulnerability Disclosure
Vulnerability disclosure
Omnicom Group runs a coordinated vulnerability disclosure program on Hackerone.
Fortune 500AdvertisingMarketingHolding CompanyMediaPublic RelationsMarketing TechnologyCommerceData & Analytics
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-08-12'
method: probed
source: >-
probe-security-programs.py omnicom + manual verification of
https://hackerone.com/omnicom
found: false
summary: >-
Omnicom publishes no vulnerability disclosure program on any host it controls.
No /.well-known/security.txt is served (HTTP 404 on www.omc.com), and
https://www.omc.com/security/ and https://www.omc.com/vulnerability-disclosure/
both return HTTP 404. NO `VulnerabilityDisclosure` or `Security` pointer is
wired in apis.yml.
false_positive_guard:
candidate: https://hackerone.com/omnicom
http_status: 200
verdict: not-a-provider-program
evidence: >-
The page is HackerOne's UNCLAIMED, community-curated directory entry, not an
Omnicom-operated program. Its own meta description reads "This
community-curated security page documents any known process for reporting a
security vulnerability to Omnicom Group", and the element carries the class
`spec-external-unclaimed`. The HackerOne GraphQL API returns
`team(handle:"omnicom")` with `name: "Omnicom Group"` but `policy: null`,
`submission_state: null`, `offers_bounties: null` and `launched_at: null` —
i.e. no policy, no submission state, never launched.
action: >-
Do not credit this URL as a disclosure program on any future round. A
HackerOne 200 alone is not evidence; require a non-null policy /
submission_state.
related_disclosure:
note: >-
Omnicom's 10-K Item 1C describes an internal cybersecurity risk-management
program guided by NIST CSF and ISO 27001, but that is an SEC disclosure about
internal governance, not a public vulnerability-reporting channel, and it
names no certification held by Omnicom.
source: https://www.board-cybersecurity.com/governance/tracker/omnicom-group
probes:
- url: https://www.omc.com/.well-known/security.txt
status: 404
- url: https://www.omc.com/security.txt
status: 404
- url: https://www.omc.com/security/
status: 404
- url: https://www.omc.com/vulnerability-disclosure/
status: 404
- url: https://trust.omc.com
status: 0
note: does not resolve in DNS
- url: https://hackerone.com/omnicom
status: 200
note: unclaimed community-curated directory page, see false_positive_guard
pointers_emitted: []
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/omnicom-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.