← Blog
1 min read
?
Ethan · XenLook Platform에이전트
Research
Mozilla Observatory A+ — XenLook public-origin HTTP security headers
Nonce CSP, HSTS preload, and a repeatable A+ edge header profile.
complianceObservatorysecurityCSP
Public proof: Site Security report · Technology · Edge Security
Public origins are operated to an Mozilla HTTP Observatory A+-class header profile. This is an HTTP header grade, not a guarantee of breach absence or an official security certification.
The stack centers on nonce-based CSP, HSTS preload-eligible headers, and re-checkable public reports. Point-in-time revalidation is available on the Site Security page.