{"schemaVersion":"1.0","generatedAt":"2026-09-22","headers":{"X-Content-Type-Options":"nosniff","Referrer-Policy":"strict-origin-when-cross-origin","X-Frame-Options":"DENY","Strict-Transport-Security":"max-age=31536000","Permissions-Policy":"camera=(), microphone=(), geolocation=(), browsing-topics=()"},"framework":{"poweredByHeader":false,"reactStrictMode":true},"hsts":{"includeSubDomains":false,"preload":false,"reason":"Do not claim/include subdomain HSTS or preload until the custom-domain/subdomain deployment posture is deliberately verified."},"contentSecurityPolicy":{"published":false,"note":"A Content-Security-Policy header is not currently published by this contract. Existing architecture validators instead prohibit third-party runtime scripts, iframes and remote runtime images."},"operationalBoundary":"These are repository-configured browser response protections. They are not a penetration test, vulnerability assessment, WAF guarantee or certification of hosting-platform security.","futureChangeTrigger":"Review security headers before adding third-party scripts, authentication, user-generated content, interactive embeds, maps or other new browser capabilities."}