Strict-Transport-Security: max-age=63072000; includeSubDomains; preload Content-Security-Policy: default-src https: Strict-Transport-Security: max-age=63072000; includeSubDomains; preload Content-Security-Policy: default-src https: