How This Briefing Works
This report opens with key findings, then maps the gaps between what TVScientific discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.
Key Findings
Pending Analysis
6 BTI behavioral codes detected across 2 deployments. Full claims extraction required for gap analysis.
Claims vs. Observed Behavior
Pending Analysis
“Claims analysis pending”
6 BTI behavioral codes detected across 2 deployments. Full claims extraction required for gap analysis.
What This Means For You
What To Do About It
Role-specific actions based on observed behavior
If You Use TVScientific
- →Audit all 12 TVScientific scripts to understand what data each collects and where it is transmitted
- →Verify your privacy policy explicitly discloses cross-device tracking linking web behavior to CTV viewing
- →Ensure your CMP consent categories cover cross-device identity resolution as a distinct processing purpose
- →Review your DPA with TVScientific for coverage of cross-device identity data and CTV viewing profiles
If You're Evaluating TVScientific
- →Require TVScientific to provide a complete data flow diagram showing how web visitor data connects to CTV identity graphs
- →Demand disclosure of all identity resolution partners and sub-processors involved in cross-device matching
- →Assess whether 12 scripts are proportionate to the CTV measurement value — request script consolidation
- →Compare TVScientific against server-side CTV attribution alternatives that reduce client-side data collection
Negotiation Leverage
- →12 scripts for CTV measurement is disproportionate client-side overhead — negotiate script consolidation and demand justification for each script's purpose
- →Cross-domain sync bridging web and CTV identity creates a novel cross-context processing activity — require explicit documentation of legal basis under GDPR Article 6 for each identity linkage
- →6 BTI behavioral codes including fingerprinting and identity resolution — use as leverage to negotiate enhanced DPA terms with specific cross-device data provisions
- →Cross-device identity profiles spanning web and television constitute high-risk processing under GDPR Article 35 — negotiate shared DPIA obligations and regular compliance reporting
- →Identity resolution linking website visitors to TV households creates sensitive profiling data — negotiate strict purpose limitation and prohibit use of your audience data for third-party audience modeling
Runtime Detections
BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.
Evasion infrastructure, auditor bypass
Impact: Evasion infrastructure may cause TVScientific to behave differently during audits, masking the true scope of cross-device identity collection when compliance teams attempt to verify data flows.
Keystroke/mouse tracking
Impact: Behavioral tracking on a CTV measurement platform captures interaction patterns that feed audience modeling across devices. Under BIPA and emerging biometric privacy laws, this data may qualify as protected biometric information requiring explicit opt-in consent.
Identity stitching
Impact: Identity stitching across domains is the mechanism that bridges web and CTV identity. This means a visitor's behavior on your website is linked to their television viewing habits — creating a cross-context behavioral profile that neither your visitors nor your privacy team can fully observe or control.
Device identification
Impact: Device fingerprinting enables persistent cross-device identification without relying on cookies or authenticated sessions. For CTV attribution, fingerprinting creates a bridge between browser and TV device identities that survives cookie deletion and browser privacy controls.
Long-lived identifiers
Impact: Long-lived identifiers maintain cross-device profiles over time, enabling TVScientific to build longitudinal viewing and browsing histories. This creates a permanent record linking your site visitors to their television consumption patterns.
PII deanonymization
Impact: PII deanonymization on a CTV platform resolves anonymous website visitors to identifiable individuals and links them to television households. This transforms your website into a data collection point for cross-device identity graphs that span web and broadcast media.
IOC Manifest
Indicators of compromise across 4 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.
Ecosystem & Supply Chain
Evidence Artifacts
Artifacts collected during analysis, available with evidence-tier access.
Complete network capture with all requests and responses
82 detection signatures across scripts, domains, cookies, and network endpoints