generated: '2026-09-12' method: probed source: https://hackerone.com/nielsen?type=team provider: Gracenote providerId: gracenote description: >- Gracenote itself publishes no vulnerability disclosure policy, no security.txt and no security contact on gracenote.com or on either developer portal. Its parent, Nielsen, runs a HackerOne program. Whether gracenote.com hosts are in that program's scope could not be established anonymously, so this is recorded as a parent-company finding, not as a Gracenote disclosure channel. security_txt: present: false probed: - url: https://gracenote.com/.well-known/security.txt status: 404 - url: https://www.gracenote.com/.well-known/security.txt status: 404 - url: https://devportal.gracenote.com/.well-known/security.txt status: 403 - url: https://developer.tmsapi.com/.well-known/security.txt status: 403 disclosure_page: present: false probed: - url: https://gracenote.com/security/ status: 404 - url: https://gracenote.com/trust/ status: 404 - url: https://www.nielsen.com/legal/vulnerability-disclosure-policy/ status: 404 - url: https://www.nielsen.com/responsible-disclosure/ status: 404 bug_bounty: present: true scope_covers_gracenote: unknown program: platform: HackerOne handle: nielsen team_id: 6078 name: Nielsen url: https://hackerone.com/nielsen website: http://www.nielsen.com allows_disclosure_assistance: true evidence: url: https://hackerone.com/nielsen?type=team status: 200 fetched: '2026-09-12' body_excerpt: '{"id":6078,"name":"Nielsen","handle":"nielsen","url":"https://hackerone.com/nielsen"}' control: https://hackerone.com/nielsen-nonexistent-xyz returned 404, confirming the 200 above is a real program and not an SPA catch-all. caveat: >- The program's policy and asset scope are not readable without a HackerOne account (api.hackerone.com returns 401; the policy_scopes endpoint returns 404 anonymously). Nothing on gracenote.com or either developer portal links to this program. A researcher who found a Gracenote vulnerability would have to infer the route from the corporate parent relationship. parent_security_page: url: https://www.nielsen.com/security/ status: 200 note: >- Reachable, but the rendered content is a Nielsen "Security Risk Management Portal" product page and a language switcher — it is not a vulnerability-disclosure policy. pointer_decision: >- No `Security` pointer is emitted in apis.yml. The scorer's security_disclosure check asserts that THIS provider publishes a disclosure route; Gracenote does not, and crediting it with its parent's unverified-scope program would be a claim we made on their behalf. This is a real, fixable gap: a security.txt on gracenote.com naming the Nielsen HackerOne program would close it in one file.