Content-Security-Policy: default-src 'self'
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: no-referrer
Permissions-Policy: geolocation=()
Strict-Transport-Security: max-age=63072000; includeSubDomains
X-XSS-Protection: 1; mode=block
Feature-Policy: camera 'none'
Expect-CT: max-age=86400, enforce
Cross-Origin-Embedder-Policy: require-corp
Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Resource-Policy: same-site
Cache-Control: no-store
Clear-Site-Data: "cache", "cookies", "storage"
Set-Cookie: name=value; HttpOnly; Secure; SameSite=Strict
Server-Timing: miss, db;dur=53, app;dur=47.2
Report-To: {"group":"default","max_age":31536000,"endpoints":[{"url":"https://example.com/reports"}]}
NEL: {"report_to":"default","max_age":31536000}
Content-DPR: 2.0
Downlink: 1.5