No custom redirects added.
HTTP Security Headers
SAMEORIGIN — blocks iframe embedding
nosniff — prevents MIME sniffing
strict-origin-when-cross-origin
Legacy XSS filter header
Forces HTTPS for 1 year via header