What is measured
The audit looks for CSP, HSTS, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and frame protection.
Trust and structured data
This check records baseline headers that restrict unsafe loading and interpretation of a page.
The audit looks for CSP, HSTS, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and frame protection.
Production responses contain a meaningful set that matches the website’s actual resources and features.
Add policies at the reverse proxy or application layer and test them in report-only mode before strict enforcement.
A present header does not prove that its value is effective; an overly broad policy can create false confidence.
Reference