Content-Security-Policy | default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.twimg.com https://platform.twitter.com https://cdn.heapanalytics.com https://heapanalytics.com https://www.googleadservices.com https://code.highcharts.com https://blueimp.github.io https://*.gosquared.com https://www.google.com https://js.chargebee.com https://*.cloudfront.net https://*.google-analytics.com https://www.gstatic.com https://maps.googleapis.com; img-src 'self' https://*.twitter.com https://*.twimg.com https://heapanalytics.com https://www.google.com https://www.googleadservices.com https://*.doubleclick.net data: https://*.google-analytics.com https://csi.gstatic.com; style-src 'self' 'unsafe-inline' https://*.twimg.com https://*.twitter.com https://heapanlytics.com https://www.gstatic.com https://www.google.com https://*.googleapis.com; font-src 'self' https://heapanlytics.com https://fonts.gstatic.com https://themes.googleusercontent.com; child-src https://*.twitter.com https://dmarcian.chargebee.com https://www.google.com; frame-src https://*.twitter.com https://dmarcian.chargebee.com https://www.google.com; object-src 'none'; connect-src 'self' https://heapanalytics.com https://api.segment.io |