Cache-Control | private |
Content-Type | text/html; charset=utf-8 |
Content-Encoding | gzip |
Vary | Accept-Encoding |
Strict-Transport-Security | max-age=31536000; includeSubDomains |
X-Frame-Options | sameorigin |
X-Content-Type-Options | nosniff |
X-Xss-Protection | 1; mode=block |
Referrer-Policy | no-referrer-when-downgrade |
Content-Security-Policy | script-src 'self' 'unsafe-eval' 'unsafe-inline' www.googletagmanager.com www.google-analytics.com maps.googleapis.com *.piwikpro.com *.newrelic.com https://www.youtube.com/iframe_api *.bam.nr-data.net https://bam.nr-data.net https://csi.gstatic.com https://az416426.vo.msecnd.net https://s.ytimg.com https://ajax.aspnetcdn.com/ajax/jQuery/jquery-2.1.1.min.js https://ajax.aspnetcdn.com/ajax/jquery.validate/1.13.1/jquery.validate.min.js https://ajax.aspnetcdn.com/ajax/mvc/5.1/jquery.validate.unobtrusive.min.js; frame-ancestors 'self'; worker-src 'self' data: blob: |