- Sets X-Frame-Options to SAMEORIGIN - Sets Strict-Transport-Security to: max-age=31536000; includeSubDomains; preload