Optional categories are off until you choose. You can change or withdraw your choice using Cookie settings in the footer.

XRENN Labs s.r.o.

Security guides

Missing security headers: improve protection without breaking the website

A missing header is a configuration observation. It is not evidence that someone has exploited your website, and a copied header can break the very workflow you need to protect.

Editorial author: XRENN Labs s.r.o. · Updated:

CSP and browser capabilities solve different problems

Content-Security-Policy constrains permitted resource sources and other browser behavior. Permissions-Policy controls whether features such as camera or geolocation are available in a document and its frames, subject to browser support. Their presence alone says little about whether the chosen directives match your application.

Sources: MDN — Content-Security-Policy · MDN — Permissions-Policy

What our scanner measures

We request public web responses, follow permitted redirects and try alternative domain endpoints within the scan budget. The report identifies the observed endpoint and security headers. A successful response can be assessed; headers on an access-controlled response remain limited evidence. We do not bypass sign-in to inspect private pages.

Presence is not a browser security audit

One response does not represent every route, API, cache variant or error page. A CSP header may still allow overly broad sources. The scanner does not simulate every browser interaction or prove the absence of XSS. Its grade is a XRENN™ assessment, not a Mozilla Observatory result.

Deploy through observation and testing

Inventory scripts, styles, frames and API connections, including payment, consent and sign-in components. A CSP Report-Only policy can expose violations before enforcement; it does not itself block the violating activity. Review reports, then enforce a tailored policy. Grant only the browser capabilities the service actually needs, and check embedded content too.

Sources: MDN — Content-Security-Policy · MDN — Permissions-Policy

Re-scan and exercise real user journeys

Check the response headers after deployment and after any CDN cache refresh. Then test mobile and desktop sign-in, form validation, submission and third-party components with their intended consent settings. A higher header score cannot replace those functional checks or application testing.

Editorial method and primary sources

These explanations are checked against the implemented scanner scope and the references below. They distinguish public observations from checks requiring authorized internal access. A content update is not a customer audit or an independently certified review.

Related guides

Expert guarantor

Cybersecurity, NIS2 & AI with Guarantor.

Direct contact with the expert guarantor for ISO 27001 ISMS, new Czech Cyber Security Act (ZKB 264/2025 Sb.) / NIS2 compliance, penetration testing, and world-class AI security.

Whether you are addressing the requirements of the new Czech Cyber Security Act (ZKB 264/2025 Sb.), the European NIS2 directive, ISO/IEC 27001 certification, or securely deploying frontier AI models and offline EdgeGuardian appliances, send your project inquiry to schedule an expert consultation.

Expertise & Diplomas

ISO/IEC 27001:2023 Lead Auditor

Information Security Management (ISMS), audit certification, and security policy implementation.

MBA Cybersecurity Academic Degree

Master of Business Administration – strategic and technical cybersecurity governance.

NIS2 & ZKB 264/2025 Sb. Compliance

Guarantor of compliance with the new Cyber Security Act and EU NIS2 directive.

AI & LLM Security Frontier AI

World-class frontier LLM model security, AI Red Teaming, and EdgeAI defense.