Cache-Control | private,no-cache, no-store |
Content-Type | text/html; charset=utf-8 |
X-Frame-Options | SAMEORIGIN |
Content-Security-Policy | default-src 'self' *.doubleclick.net *.google-analytics.com *.aimianz.com *.facebook.com *.westpac.co.nz *.typography.com; script-src 'self' api.addressfinder.nz *.westpac.co.nz *.google-analytics.com *.googletagmanager.com *.facebook.net 'unsafe-inline' 'unsafe-eval'; style-src 'self' api.addressfinder.nz *.bootstrapcdn.com *.typography.com 'unsafe-inline'; font-src *.bootstrapcdn.com data:; |
X-XSS-Protection | 1; mode=block |
Strict-Transport-Security | max-age=16070400; includeSubDomains |
X-Content-Type-Options | nosniff |
Content-Length | 64861 |