Home / Notes / security-headers-privacy-cookies
website security headers privacy cookies
HSTS, CSP, X-Frame-Options, a crawlable privacy page, and no ungated marketing cookies. We make the legal baseline match the live HTML.
A privacy URL that 404s, or robots Disallow /privacy, is the opposite of compliance theatre.
nosniff, DENY framing, referrer-policy, permissions-policy, CSP, HSTS. Privacy page that says what the desk actually collects.
Technical edge cookies vs marketing. Consent Mode default-denied when GA4 exists. GPC honored when a banner is mounted.
The page has to name this host, this mailbox, and this Telegram. We write that.