date: |
Wed, 02 Oct 2024 11:12:30 GMT |
content-type: |
text/html; charset=utf-8 |
transfer-encoding: |
chunked |
connection: |
close |
cache-control: |
public, max-age=259200 |
vary: |
origin,Accept-Encoding |
x-ua-compatible: |
IE=edge,chrome=1 |
x-frame-options: |
sameorigin |
x-xss-protection: |
1; mode=block |
referrer-policy: |
no-referrer |
feature-policy: |
geolocation 'self'; midi 'none'; sync-xhr 'none'; microphone 'none'; camera 'none'; magnetometer 'none'; gyroscope 'none'; fullscreen 'self'; payment 'none'; |
access-control-allow-origin: |
https://www.paragonbank.co.uk |
set-cookie: |
ASP.NET_SessionId=1veglwt11c3diy35qz0er3yt; path=/; secure; HttpOnly,osVisitor=85c3c485-d65a-412d-b5c9-53a40049e3b4; expires=Mon, 02-Oct-2124 11:12:30 GMT; path=/; secure; HttpOnly,osVisit=ef69ca1d-b958-41a4-a210-4a5cf164c434; expires=Wed, 02-Oct-2024 11:42:30 GMT; path=/; secure; HttpOnly,pageLoadedFromBrowserCache=false; path=/; secure |
strict-transport-security: |
max-age=31536000;includeSubDomains |
content-security-policy: |
base-uri 'self'; child-src blob: 'self' gap: app.powerbi.com dev.visualwebsiteoptimizer.com widget.trustpilot.com *.surveymonkey.com *.twitter.com *.vimeo.com *.youtube.com https://www.google.com/ https://td.doubleclick.net/; frame-src blob: 'self' gap: app.powerbi.com dev.visualwebsiteoptimizer.com widget.trustpilot.com *.surveymonkey.com *.twitter.com *.vimeo.com *.youtube.com https://www.google.com/ https://td.doubleclick.net/; connect-src fonts.googleapis.com fonts.gstatic.com global.sitesearch360.com ict.infinity-tracking.net insights.sitesearch360.com 'self' *.feefo.com *.google.com *.onetrust.com *.paragonbankinggroup.co.uk *.twimg.com *.twitter.com *.visualwebsiteoptimizer.com https://*.google-analytics.com https://www.google.co.uk/ https://stats.g.doubleclick.net/; default-src 'self' gap: 'unsafe-inline' 'unsafe-eval'; font-src 'self' data: fonts.gstatic.com; img-src * data: blob:; media-src data: 'self'; script-src gap: 'self' cdn.sitesearch360.com cdn-ukwest.onetrust.com ict.infinity-tracking.net snap.licdn.com unpkg.com widget.trustpilot.com *.doubleclick.net *.feefo.com *.paragonbankinggroup.co.uk *.surveymonkey.com *.twimg.com *.twitter.com *.youtube.com *.visualwebsiteoptimizer.com https://www.googletagmanager.com/ 'unsafe-inline' 'unsafe-eval'; style-src 'self' dev.visualwebsiteoptimizer.com fonts.googleapis.com register.feefo.com *.twimg.com *.twitter.com 'unsafe-inline'; frame-ancestors gap: 'self' *.surveymonkey.com; report-uri /SecurityUtils/rest/Report/ReportViolations?Params=gECl1AgjY%2BAgiSioyobPPQdaTHoo9zP8WUNfYBKlCnbZk%2FmKQnFLk24y35T7PHnWk%2FaXk1jug1OfYjqgz%2FrJiA%3D%3D; |
x-content-security-policy: |
base-uri 'self'; child-src blob: 'self' gap: app.powerbi.com dev.visualwebsiteoptimizer.com widget.trustpilot.com *.surveymonkey.com *.twitter.com *.vimeo.com *.youtube.com https://www.google.com/ https://td.doubleclick.net/; frame-src blob: 'self' gap: app.powerbi.com dev.visualwebsiteoptimizer.com widget.trustpilot.com *.surveymonkey.com *.twitter.com *.vimeo.com *.youtube.com https://www.google.com/ https://td.doubleclick.net/; connect-src fonts.googleapis.com fonts.gstatic.com global.sitesearch360.com ict.infinity-tracking.net insights.sitesearch360.com 'self' *.feefo.com *.google.com *.onetrust.com *.paragonbankinggroup.co.uk *.twimg.com *.twitter.com *.visualwebsiteoptimizer.com https://*.google-analytics.com https://www.google.co.uk/ https://stats.g.doubleclick.net/; default-src 'self' gap: 'unsafe-inline' 'unsafe-eval'; font-src 'self' data: fonts.gstatic.com; img-src * data: blob:; media-src data: 'self'; script-src gap: 'self' cdn.sitesearch360.com cdn-ukwest.onetrust.com ict.infinity-tracking.net snap.licdn.com unpkg.com widget.trustpilot.com *.doubleclick.net *.feefo.com *.paragonbankinggroup.co.uk *.surveymonkey.com *.twimg.com *.twitter.com *.youtube.com *.visualwebsiteoptimizer.com https://www.googletagmanager.com/ 'unsafe-inline' 'unsafe-eval'; style-src 'self' dev.visualwebsiteoptimizer.com fonts.googleapis.com register.feefo.com *.twimg.com *.twitter.com 'unsafe-inline'; frame-ancestors gap: 'self' *.surveymonkey.com; report-uri /SecurityUtils/rest/Report/ReportViolations?Params=gECl1AgjY%2BAgiSioyobPPQdaTHoo9zP8WUNfYBKlCnbZk%2FmKQnFLk24y35T7PHnWk%2FaXk1jug1OfYjqgz%2FrJiA%3D%3D; |
x-webkit-csp: |
base-uri 'self'; child-src blob: 'self' gap: app.powerbi.com dev.visualwebsiteoptimizer.com widget.trustpilot.com *.surveymonkey.com *.twitter.com *.vimeo.com *.youtube.com https://www.google.com/ https://td.doubleclick.net/; frame-src blob: 'self' gap: app.powerbi.com dev.visualwebsiteoptimizer.com widget.trustpilot.com *.surveymonkey.com *.twitter.com *.vimeo.com *.youtube.com https://www.google.com/ https://td.doubleclick.net/; connect-src fonts.googleapis.com fonts.gstatic.com global.sitesearch360.com ict.infinity-tracking.net insights.sitesearch360.com 'self' *.feefo.com *.google.com *.onetrust.com *.paragonbankinggroup.co.uk *.twimg.com *.twitter.com *.visualwebsiteoptimizer.com https://*.google-analytics.com https://www.google.co.uk/ https://stats.g.doubleclick.net/; default-src 'self' gap: 'unsafe-inline' 'unsafe-eval'; font-src 'self' data: fonts.gstatic.com; img-src * data: blob:; media-src data: 'self'; script-src gap: 'self' cdn.sitesearch360.com cdn-ukwest.onetrust.com ict.infinity-tracking.net snap.licdn.com unpkg.com widget.trustpilot.com *.doubleclick.net *.feefo.com *.paragonbankinggroup.co.uk *.surveymonkey.com *.twimg.com *.twitter.com *.youtube.com *.visualwebsiteoptimizer.com https://www.googletagmanager.com/ 'unsafe-inline' 'unsafe-eval'; style-src 'self' dev.visualwebsiteoptimizer.com fonts.googleapis.com register.feefo.com *.twimg.com *.twitter.com 'unsafe-inline'; frame-ancestors gap: 'self' *.surveymonkey.com; report-uri /SecurityUtils/rest/Report/ReportViolations?Params=gECl1AgjY%2BAgiSioyobPPQdaTHoo9zP8WUNfYBKlCnbZk%2FmKQnFLk24y35T7PHnWk%2FaXk1jug1OfYjqgz%2FrJiA%3D%3D; |
x-content-type-options: |
nosniff |
cf-cache-status: |
DYNAMIC |
server: |
cloudflare |
cf-ray: |
8cc441fdeb2b7752-AMS |