date: |
Thu, 10 Oct 2024 14:13:03 GMT |
content-type: |
text/html; charset=utf-8 |
content-length: |
217219 |
connection: |
close |
content-security-policy: |
connect-src 'self' api.rollbar.com www.tag4arm.com *.smartlook.cloud *.google-analytics.com *.analytics.google.com *.googletagmanager.com adservice.google.com stats.g.doubleclick.net www.google.com/pagead/ pagead2.googlesyndication.com googleads.g.doubleclick.net translate.googleapis.com consentcdn.cookiebot.com api.pay360.com mpsnare.iesnare.com wss://mpsnare.iesnare.com wss://ws.pusherapp.com *.pusher.com api.talkdeskapp.com api.talkdeskapp.eu api.talkdeskappca.com wss://tsock.us1.twilio.com wss://tsock.ie1.twilio.com mcs.us1.twilio.com mcs.ie1.twilio.com *.dynatrace.com firstbanco-production-attachments.s3.eu-west-1.amazonaws.com d3gj43804r9iyz.cloudfront.net;default-src 'self';font-src 'self' data: fonts.googleapis.com fonts.gstatic.com talkdeskchatsdk.talkdeskapp.com d3gj43804r9iyz.cloudfront.net;form-action 'self';frame-src 'self' tpc.googlesyndication.com fls.doubleclick.net bid.g.doubleclick.net 8103783.fls.doubleclick.net td.doubleclick.net www.youtube.com consentcdn.cookiebot.com bamboo.web.emea-1.jumio.ai web.emea-1.jumio.ai upload.web.emea-1.jumio.ai widget.trustpilot.com secure.mite.pay360.com dev.mite.pay360.com secure.pay360.com plata.prismic.io bambooloans.prismic.io cti-client-web.meza.talkdeskapp.eu api.talkdeskapp.eu;img-src 'self' data: www.tag4arm.com 8103783.fls.doubleclick.net stats.g.doubleclick.net lh3.googleusercontent.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com ssl.gstatic.com www.gstatic.com www.google.com www.google.co.uk googleads.g.doubleclick.net ade.googlesyndication.com www.google.com/ads/ www.google.com/pagead/ ad.doubleclick.net translate.google.com imgsct.cookiebot.com images.prismic.io bambooloans.cdn.prismic.io plata.cdn.prismic.io qa-cdn-talkdesk.talkdeskdev.com talkdeskchatsdk.talkdeskapp.com media.us1.twilio.com s3-eu-west-1.amazonaws.com/firstbanco-email-assets/ s3-eu-west-1.amazonaws.com/firstbanco-production-broker-logos/ d3gj43804r9iyz.cloudfront.net;object-src 'self';script-src 'self' 'unsafe-inline' 'unsafe-eval' cdn.rollbar.com/rollbarjs/ www.tag4arm.com *.smartlook.com ajax.googleapis.com googleads.g.doubleclick.net ssl.google-analytics.com tagmanager.google.com tpc.googlesyndication.com tpc.googlesyndication.com www.google-analytics.com www.google.com/pagead/ www.googleadservices.com www.googletagmanager.com consent.cookiebot.com consentcdn.cookiebot.com api.mite.pay360.com api.pay360.com widget.trustpilot.com mpsnare.iesnare.com js.pusher.com static.cdn.prismic.io prismic.io html2canvas.hertzen.com/dist/html2canvas.min.js talkdeskchatsdk.talkdeskapp.com d3gj43804r9iyz.cloudfront.net;style-src 'self' 'unsafe-inline' use.fontawesome.com fonts.googleapis.com tagmanager.google.com d3gj43804r9iyz.cloudfront.net;upgrade-insecure-requests ;block-all-mixed-content ;report-uri /csp-violations;media-src https://mpsnare.iesnare.com data:;style-src-elem 'self' 'unsafe-inline' use.fontawesome.com fonts.googleapis.com tagmanager.google.com d3gj43804r9iyz.cloudfront.net;script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' cdn.rollbar.com/rollbarjs/ www.tag4arm.com *.smartlook.com ajax.googleapis.com googleads.g.doubleclick.net ssl.google-analytics.com tagmanager.google.com tpc.googlesyndication.com tpc.googlesyndication.com www.google-analytics.com www.google.com/pagead/ www.googleadservices.com www.googletagmanager.com consent.cookiebot.com consentcdn.cookiebot.com api.mite.pay360.com api.pay360.com widget.trustpilot.com mpsnare.iesnare.com js.pusher.com static.cdn.prismic.io prismic.io html2canvas.hertzen.com/dist/html2canvas.min.js talkdeskchatsdk.talkdeskapp.com d3gj43804r9iyz.cloudfront.net; |
feature-policy: |
accelerometer 'none'; ambient-light-sensor 'none'; autoplay 'none'; battery 'none'; cross-origin-isolated 'none'; display-capture 'none'; document-domain 'none'; encrypted-media 'none'; execution-while-not-rendered 'none'; execution-while-out-of-viewport 'none'; geolocation 'none'; keyboard-map 'none'; midi 'none'; navigation-override 'none'; notifications 'none'; picture-in-picture 'none'; publickey-credentials-get 'none'; screen-wake-lock 'none'; usb 'none'; web-share 'none'; xr-spatial-tracking 'none'; push 'none'; microphone 'none'; magnetometer 'none'; gyroscope 'none'; speaker 'none'; vibrate 'none'; fullscreen 'none'; payment 'none'; camera 'self'; |
referrer-policy: |
strict-origin-when-cross-origin |
permissions-policy: |
accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), cross-origin-isolated=(), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), geolocation=(), keyboard-map=(), midi=(), navigation-override=(), notifications=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), usb=(), web-share=(), xr-spatial-tracking=(), push=(), microphone=(), magnetometer=(), gyroscope=(), speaker=(), vibrate=(), fullscreen=(), payment=(), camera=(self) |
strict-transport-security: |
max-age=31536000; includeSubDomains; preload=false |
x-frame-options: |
DENY |
x-xss-protection: |
0 |
x-content-type-options: |
nosniff |
x-permitted-cross-domain-policies: |
none |
cache-control: |
no-cache |
link: |
<https://d3gj43804r9iyz.cloudfront.net/master/49ad690602d0fa68ce35e750f9c77255130bdc20/webpack-cookie_consent-725725f82d3dec933486.css>; rel=preload; as=style; nopush,<https://d3gj43804r9iyz.cloudfront.net/master/49ad690602d0fa68ce35e750f9c77255130bdc20/application-caf13a07f846a62c54f1c9967d2588a8f04f7a1d2a97f2bba7f820a1397780e3.css>; rel=preload; as=style; nopush,<https://d3gj43804r9iyz.cloudfront.net/master/49ad690602d0fa68ce35e750f9c77255130bdc20/home-9e912307ba3b98c3312d9e512ba4688d9456837514f2419a8eb4ca5e1dfc4440.js>; rel=preload; as=script; nopush,<https://d3gj43804r9iyz.cloudfront.net/master/49ad690602d0fa68ce35e750f9c77255130bdc20/webpack-home-1903af01900b806dbf44.js>; rel=preload; as=script; crossorigin=anonymous; nopush,<https://d3gj43804r9iyz.cloudfront.net/master/49ad690602d0fa68ce35e750f9c77255130bdc20/webpack-vendors-5da2a3bffbbeb73313b5.js>; rel=preload; as=script; crossorigin=anonymous; nopush |
etag: |
W/"6fdf37733469ed2b79b2e727d442dbb2" |
set-cookie: |
_session_id=ad0171eaf9f5f7f161b3c9bcf9f65fbd; path=/; expires=Thu, 10 Oct 2024 14:43:03 GMT; HttpOnly; secure |
x-request-id: |
321988e7-1b9d-409f-9dd1-17d8bc6b75c0 |
x-runtime: |
0.085310 |
vary: |
Accept-Encoding, Origin |
|