Gracenote · Vulnerability Disclosure

Gracenote Vulnerability Disclosure

Vulnerability disclosure

Gracenote itself publishes no vulnerability disclosure policy, no security.txt and no security contact on gracenote.com or on either developer portal. Its parent, Nielsen, runs a HackerOne program. Whether gracenote.com hosts are in that program's scope could not be established anonymously, so this is recorded as a parent-company finding, not as a Gracenote disclosure channel.

Gracenote runs a coordinated vulnerability disclosure program on Hackerone.

Artificial IntelligenceAutomotiveContent MetadataEntertainmentMCPMusicNielsenSportsSports DataStreamingTelevisionVideoVideo Metadata
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-12'
method: probed
source: https://hackerone.com/nielsen?type=team
provider: Gracenote
providerId: gracenote
description: >-
  Gracenote itself publishes no vulnerability disclosure policy, no security.txt and no security
  contact on gracenote.com or on either developer portal. Its parent, Nielsen, runs a HackerOne
  program. Whether gracenote.com hosts are in that program's scope could not be established
  anonymously, so this is recorded as a parent-company finding, not as a Gracenote disclosure channel.
security_txt:
  present: false
  probed:
  - url: https://gracenote.com/.well-known/security.txt
    status: 404
  - url: https://www.gracenote.com/.well-known/security.txt
    status: 404
  - url: https://devportal.gracenote.com/.well-known/security.txt
    status: 403
  - url: https://developer.tmsapi.com/.well-known/security.txt
    status: 403
disclosure_page:
  present: false
  probed:
  - url: https://gracenote.com/security/
    status: 404
  - url: https://gracenote.com/trust/
    status: 404
  - url: https://www.nielsen.com/legal/vulnerability-disclosure-policy/
    status: 404
  - url: https://www.nielsen.com/responsible-disclosure/
    status: 404
bug_bounty:
  present: true
  scope_covers_gracenote: unknown
  program:
    platform: HackerOne
    handle: nielsen
    team_id: 6078
    name: Nielsen
    url: https://hackerone.com/nielsen
    website: http://www.nielsen.com
    allows_disclosure_assistance: true
  evidence:
    url: https://hackerone.com/nielsen?type=team
    status: 200
    fetched: '2026-09-12'
    body_excerpt: '{"id":6078,"name":"Nielsen","handle":"nielsen","url":"https://hackerone.com/nielsen"}'
  control: https://hackerone.com/nielsen-nonexistent-xyz returned 404, confirming the 200 above is a real program and not an SPA catch-all.
  caveat: >-
    The program's policy and asset scope are not readable without a HackerOne account
    (api.hackerone.com returns 401; the policy_scopes endpoint returns 404 anonymously). Nothing on
    gracenote.com or either developer portal links to this program. A researcher who found a
    Gracenote vulnerability would have to infer the route from the corporate parent relationship.
parent_security_page:
  url: https://www.nielsen.com/security/
  status: 200
  note: >-
    Reachable, but the rendered content is a Nielsen "Security Risk Management Portal" product page
    and a language switcher — it is not a vulnerability-disclosure policy.
pointer_decision: >-
  No `Security` pointer is emitted in apis.yml. The scorer's security_disclosure check asserts that
  THIS provider publishes a disclosure route; Gracenote does not, and crediting it with its parent's
  unverified-scope program would be a claim we made on their behalf. This is a real, fixable gap: a
  security.txt on gracenote.com naming the Nielsen HackerOne program would close it in one file.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/gracenote-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.