Open
Cached
·
just now
14
directives
Content-Security-Policy
Content-Security-Policy: connect-src 'self' https://forms.hsforms.com https://hubspot-forms-static-embed.s3.amazonaws.com https://api.hsforms.com https://*.algolia.net https://cdn.contentful.com https://*.algolianet.com https://analytics.tiktok.com/ https://api.gemini.com https://api.mixpanel.com https://api.coingecko.com https://bat.bing.com https://bnc.lt https://boards-api.greenhouse.io/v1/boards/gemini/jobs https://boards.greenhouse.io https://cdn.builder.io https://exchange.gemini.com https://exchange.qa001.aurora7.net https://geminiexchange.app.link https://gemini.onelink.me https://graphql.contentful.com https://*.hubspot.com https://preview.contentful.com https://stats.g.doubleclick.net https://tr.snapchat.com https://www.gemini.com https://www.google-analytics.com wss://api.gemini.com/v2/marketdata wss://wsapi.fast.gemini.com wss://exchange.gemini.com/ws/competition wss://exchange.qa100.aurora7.net/ws/competition https://exchange.qa100.aurora7.net https://exchange.gemini.com https://mobile.gemini.com https://exchange.sandbox.gemini.com https://analytics.google.com https://*.clarity.ms https://*.mmin.io https://*.moneymade.io https://px.ads.linkedin.com https://px.ads.linkedin.com/attribution_trigger https://px.ads.linkedin.com/collect https://prod.spline.design https://fonts.gstatic.com https://mix.qa100.aurora7.net https://mix.gemini.com https://browser-intake-datadoghq.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://pagead2.googlesyndication.com https://www.google.com https://google.com; img-src 'self' data: https://assets.gemini.com https://cdn.builder.io https://exceptions.hs-embed-reporting.com https://static.hsappstatic.net http://assets.ctfassets.net http://images.ctfassets.net http://t.co https://analytics.twitter.com https://bat.bing.com https://boards-api.greenhouse.io/v1/boards/gemini/jobs https://cdn-images-1.medium.com https://cx.atdmt.com https://data.adxcel-ec2.com https://images.ctfassets.net https://*.hsforms.com https://*.hubspot.com https://resources.vzaar.com https://stats.g.doubleclick.net https://tags.w55c.net https://view.vzaar.com https://www.facebook.com https://www.gemini.com https://googleads.g.doubleclick.net https://www.google-analytics.com https://www.google.com https://www.googletagmanager.com https://fonts.gstatic.com https://tr.snapchat.com images.contentful.com videos.contentful.com videos.ctfassets.net https://*.clarity.ms https://*.mmin.io https://*.moneymade.io https://c.bing.com https://geminym-social-images-public.s3.amazonaws.com https://geminym-social-images-delta-public.s3.amazonaws.com https://geminym-social-images-dev-public.s3.amazonaws.com https://px.ads.linkedin.com/collect https://d1il5533o350rp.cloudfront.net/pixel.gif https://trkn.us https://www.google.com.au/pagead/ https://www.google.com/pagead/ https://www.googleadservices.com https://pagead2.googlesyndication.com https://google.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://cdn.builder.io https://js.hsforms.net https://analytics.tiktok.com https://analytics.twitter.com https://app.link https://bat.bing.com https://bat.bing.com https://boards-api.greenhouse.io/v1/boards/gemini/jobs https://boards.greenhouse.io https://cdnjs.cloudflare.com/ajax/libs/gsap/ https://cdnjs.cloudflare.com/ajax/libs/ScrollMagic/ https://codepen.io https://connect.facebook.net https://googleads.g.doubleclick.net https://js.hsadspixel.net https://js.hscollectedforms.net https://*.hs-scripts.com https://js.hs-analytics.net https://js.hs-banner.com https://*.mountain.com https://s.ytimg.com https://sc-static.net https://stats.g.doubleclick.net https://www.google-analytics.com https://www.google.com https://www.googleadservices.com https://www.googletagmanager.com https://www.gstatic.com https://www.youtube.com static.ads-twitter.com https://*.clarity.ms https://*.mmin.io https://*.moneymade.io https://*.twitter.com https://snap.licdn.com/li.lms-analytics/insight.min.js https://snap.licdn.com/li.lms-analytics/insight.old.min.js https://www.redditstatic.com https://pagead2.googlesyndication.com; style-src 'self' 'unsafe-inline' https://cloud.typography.com https://fonts.googleapis.com https://static.gemini.com https://use.typekit.net https://www.googletagmanager.com https://*.mmin.io https://snap.licdn.com/li.lms-analytics/insight.old.min.js https://p.typekit.net/p.css; font-src 'self' data: https://use.typekit.net https://fonts.gstatic.com; frame-src data: https://cdn.builder.io https://forms.hsforms.com/ http://assets.ctfassets.net https://videos.ctfassets.net https://*.doubleclick.net https://boards.greenhouse.io https://codepen.io https://docs.google.com/ https://tr.snapchat.com https://tr6.snapchat.com https://www.facebook.com https://www.gemini.com https://www.google.com https://www.youtube.com https://platform.twitter.com https://*.mmin.io https://www.googletagmanager.com; media-src 'self' https://video.vzaar.com https://view.vzaar.com images.contentful.com videos.contentful.com videos.ctfassets.net https://cdn.builder.io; object-src https://www.gemini.com http://assets.ctfassets.net; default-src 'self' https://*.clarity.ms https://*.mmin.io https://*.moneymade.io https://c.bing.com; base-uri 'self'; form-action 'self' https://forms.hsforms.com/ https://www.facebook.com https://tr.snapchat.com https://support.gemini.com/hc/search; manifest-src 'self'; frame-ancestors 'self'; report-to https://exchange.gemini.com/collect-csp;
connect-src
Keyword
—
'self'
connect-src
Host
—
connect-src
Host
—
img-src
Keyword
—
'self'
img-src
Scheme
—
data:
img-src
Host
—
img-src
Host
—
script-src
Keyword
—
'self'
script-src
Keyword
—
'unsafe-eval'
script-src
Keyword
—
'unsafe-inline'
script-src
Host
—
style-src
Keyword
—
'self'
style-src
Keyword
—
'unsafe-inline'
style-src
Host
—
font-src
Keyword
—
'self'
font-src
Scheme
—
data:
frame-src
Scheme
—
data:
frame-src
Host
—
media-src
Keyword
—
'self'
default-src
Keyword
—
'self'
default-src
Host
—
base-uri
Keyword
—
'self'
form-action
Keyword
—
'self'
manifest-src
Keyword
—
'self'
frame-ancestors
Keyword
—
'self'
Content-Security-Policy-Report-Only
No report-only CSP headers found.