ASAP Today
Oniyore desk

Home / Notes / security-headers-privacy-cookies

website security headers privacy cookies

Security Headers, Privacy Page, and Cookie Law on a Real Site

HSTS, CSP, X-Frame-Options, a crawlable privacy page, and no ungated marketing cookies. We make the legal baseline match the live HTML.

Get help Talk to us

Headers are not a PDF policy

A privacy URL that 404s, or robots Disallow /privacy, is the opposite of compliance theatre.

Baseline we put on ASAP

nosniff, DENY framing, referrer-policy, permissions-policy, CSP, HSTS. Privacy page that says what the desk actually collects.

Cookies

Technical edge cookies vs marketing. Consent Mode default-denied when GA4 exists. GPC honored when a banner is mounted.

Do not copy a generator

The page has to name this host, this mailbox, and this Telegram. We write that.

Questions

Do I need a cookie banner?
If you set marketing cookies or GA4, yes. If the desk has empty measurement IDs, we do not fake a banner over nothing.
HSTS preload?
max-age=31536000; includeSubDomains when HTTPS is stable. Preload list is a later, explicit step.

More notes