Cache-Control | max-age=0, private, must-revalidate |
Content-Encoding | gzip |
Content-Security-Policy | default-src 'self'; connect-src 'self' https://*.mixpanel.com https://mixpanel.com; font-src 'self' data://* https://cdn.blackbox.cool https://*.mxpnl.com; frame-src 'self' https://js.stripe.com; img-src 'self' data: https://bam.nr-data.net https://www.gravatar.com https://www.google-analytics.com https://cdn.blackbox.cool https://q.stripe.com https://*.mxpnl.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google-analytics.com https://cdn.blackbox.cool https://js.stripe.com https://api.stripe.com https://q.stripe.com https://mixpanel.com https://*.mixpanel.com https://*.mxpnl.com; style-src 'self' 'unsafe-inline' https://cdn.blackbox.cool; media-src 'self' https://cdn.blackbox.cool; child-src 'self' https://js.stripe.com |
Content-Type | text/html; charset=utf-8 |
Server | nginx/1.4.6 (Ubuntu) |
Strict-Transport-Security | max-age=15552000; includeSubDomains |
Vary | Accept-Encoding, Origin |
X-Request-Id | 7ed0ce09-b07c-41f6-a405-3c146819fa55 |
X-Runtime | 0.004606 |
Connection | keep-alive |