hello@datascale.de+49 89 921 35 623tracked cookie-free · /openDEEN

Search services, integrations and blog posts.

DatascaleResourcesChecksSecurity headers

Check · C06 · Security & bots

Security headers

HSTS, X-Frame-Options, and CSP are the security baseline every audit checks.

What we check

Checks HSTS, X-Frame-Options, and Content-Security-Policy in the response headers.

Why it matters

HSTS, X-Frame-Options, and CSP are the security baseline every audit checks.

Common causes

  • The host ships default headers, nobody ever configured a security policy.
  • A CSP existed but was removed entirely after frontend errors instead of being repaired.
  • Proxy or CDN overwrite the headers set by the backend on delivery.

The fix

Configure HSTS + CSP with frame-ancestors, then target securityheaders.com grade B.

Check it yourself first

The Tracking Check tests this point along with all the others, in seconds.

Start the Tracking Check →
What does a failing "Security headers" check mean?

HSTS, X-Frame-Options, and CSP are the security baseline every audit checks. Configure HSTS + CSP with frame-ancestors, then target securityheaders.com grade B.

How do you fix a failing "Security headers" check?

Configure HSTS + CSP with frame-ancestors, then target securityheaders.com grade B.

The fix, delivered

Wired up in days, not sprints.

Findings from the Tracking Check go into a ranked sequence with effort estimates in the Audit Sprint, every module with an acceptance criterion.