Security headers across the whole domain
CSP, HSTS (2 years, includeSubDomains, preload), X-Frame-Options SAMEORIGIN, X-Content-Type-Options nosniff, Referrer-Policy and Permissions-Policy (camera, microphone, geolocation disabled) apply to every route. The header that advertises the framework is removed.
