Open
Cached
·
just now
21
Headers
Detected Technologies from Headers
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Present
camera=(), microphone=(), geolocation=(); +1 more
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
Accept-Encoding
connection: close transfer-encoding: chunked vary: Accept-Encoding
Caching Headers
Cache-Control
public, max-age=0, must-revalidate
cache-control: public, max-age=0, must-revalidate
Content Headers
Content-Type
text/html; charset=utf-8
content-type: text/html; charset=utf-8
CORS Headers
Access-Control-Allow-Origin
*
access-control-allow-origin: *
Cookies Headers
Other Headers
Date
Sat, 21 Feb 2026 14:09:09 GMT
Nel
{"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Reporting-Endpoints
csp-endpoint="https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub043e3a57772658a58a4bb910ce747aa1&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=env:prod%2cservice:web%2cversion:d1036df161fafd5a319bd51e51ce4f2d527c1064"
Timing-Allow-Origin
https://app.vanta.com, https://app.eu.vanta.com, https://app.aus.vanta.com
X-Permitted-Cross-Domain-Policies
none
cf-cache-status: DYNAMIC
cf-ray: 9d16d1e11ce70823-IAD
date: Sat, 21 Feb 2026 14:09:09 GMT
nel: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
report-to: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Cp1iz0qLym1E5QLu9cuKUPtgyJVFdb0ECgl9H1MOg9zjryEKiDE3m4URTcy5CDEMpIsqMkReA3SCxwy5udvbCdHgT1WpSyLj6vpb8vopknU1lsD4MKem6UmL%2B15lz2FJHFI3BtoqGA6ZQlPVgOzO"}],"group":"cf-nel","max_age":604800}
reporting-endpoints: csp-endpoint="https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub043e3a57772658a58a4bb910ce747aa1&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=env:prod%2cservice:web%2cversion:d1036df161fafd5a319bd51e51ce4f2d527c1064"
timing-allow-origin: https://app.vanta.com, https://app.eu.vanta.com, https://app.aus.vanta.com
x-permitted-cross-domain-policies: none
Recommendations
Enable compression (gzip/brotli) to improve performance