content-type: |
text/html; charset=UTF-8 |
transfer-encoding: |
chunked |
connection: |
close |
date: |
Wed, 02 Oct 2024 10:11:58 GMT |
set-cookie: |
AWSALB=3UErOhmfxkGOnrDBdgofnCEZGfKOpbfUnDQk79swvUIf3yjzGgjfnivQ9A5vHJ5RY8OTwIUkt6KWIzlcwfSw+miFByw1b7uOXVIF7oxb0ixtxaheiUeLUNKadrkg; Expires=Wed, 09 Oct 2024 10:11:57 GMT; Path=/,AWSALBCORS=3UErOhmfxkGOnrDBdgofnCEZGfKOpbfUnDQk79swvUIf3yjzGgjfnivQ9A5vHJ5RY8OTwIUkt6KWIzlcwfSw+miFByw1b7uOXVIF7oxb0ixtxaheiUeLUNKadrkg; Expires=Wed, 09 Oct 2024 10:11:57 GMT; Path=/; SameSite=None; Secure |
server: |
none |
expect-ct: |
max-age=86400, enforce |
referrer-policy: |
strict-origin-when-cross-origin |
strict-transport-security: |
max-age=31536000; includeSubdomains; preload |
x-content-type-options: |
nosniff |
x-permitted-cross-domain-policies: |
none |
x-xss-protection: |
1; mode=block |
x-frame-options: |
sameorigin |
content-security-policy: |
upgrade-insecure-requests ; default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' data: blob: google.com *.google.com google.com.au *.google.com.au googleoptimize.com *.googleoptimize.com googleapis.com *.googleapis.com googletagservices.com *.googletagservices.com googleadservices.com *.googleadservices.com googletagmanager.com *.googletagmanager.com google-analytics.com *.google-analytics.com googleanalytics.com *.googleanalytics.com googlesyndication.com *.googlesyndication.com gstatic.com *.gstatic.com force.com *.force.com salesforce-sites.com *.salesforce-sites.com my.site.com *.my.site.com formstack.com *.formstack.com atag.adgile.media bing.com *.bing.com code.jquery.com connect.facebook.net doubleclick.net *.doubleclick.net hotjar.com *.hotjar.com hotjar.io *.hotjar.io js.adsrvr.com match.adsrvr.org pixel.roymorgan.com podbean.com *.podbean.com rules.quantcount.com script.crazyegg.com secure.quantserve.com stripe.com *.stripe.com tealiumiq.com *.tealiumiq.com tiqcdn.com *.tiqcdn.com trkcall.com *.trkcall.com ups.analytics.yahoo.com visualwebsiteoptimizer.com *.visualwebsiteoptimizer.com widget.trustpilot.com yourir.info zdassets.com *.zdassets.com zopim.com *.zopim.com; style-src 'self' 'unsafe-inline' data: google.com *.google.com googleapis.com *.googleapis.com force.com *.force.com salesforce-sites.com *.salesforce-sites.com my.site.com *.my.site.com formstack.com *.formstack.com doubleclick.net *.doubleclick.net match.adsrvr.org tealiumiq.com *.tealiumiq.com yourir.info; font-src 'self' gstatic.com *.gstatic.com force.com *.force.com my.salesforce-sites.com *.my.salesforce-sites.com my.site.com *.my.site.com hotjar.com *.hotjar.com hotjar.io *.hotjar.io match.adsrvr.org tealiumiq.com *.tealiumiq.com; media-src 'self' force.com *.force.com my.salesforce-sites.com *.my.salesforce-sites.com my.site.com *.my.site.com match.adsrvr.org static.zdassets.com tealiumiq.com *.tealiumiq.com; img-src 'self' data: data:0 https://slatergordon.imgix.net https://assets.slatergordon.com.au google.com *.google.com google.com.au *.google.com.au google-analytics.com *.google-analytics.com googleapis.com *.googleapis.com googletagmanager.com *.googletagmanager.com googleusercontent.com *.googleusercontent.com gstatic.com *.gstatic.com force.com *.force.com my.salesforce-sites.com *.my.salesforce-sites.com my.site.com *.my.site.com formstack.com *.formstack.com bing.com *.bing.com doubleclick.net *.doubleclick.net facebook.com *.facebook.com hotjar.com *.hotjar.com hotjar.io *.hotjar.io i.ytimg.com img.youtube.com imgix.net *.imgix.net insight.adsrvr.com match.adsrvr.org pixel.quantserve.com slatergordon.com.au *.slatergordon.com.au tealiumiq.com *.tealiumiq.com vimeocdn.com *.vimeocdn.com visualwebsiteoptimizer.com *.visualwebsiteoptimizer.com zopim.io *.zopim.io connect.facebook.net; frame-src 'self' google.com *.google.com googletagmanager.com *.googletagmanager.com force.com *.force.com my.salesforce-sites.com *.my.salesforce-sites.com my.site.com *.my.site.com forceusercontent.com *.forceusercontent.com formstack.com *.formstack.com doubleclick.net *.doubleclick.net facebook.com *.facebook.com hotjar.com *.hotjar.com hotjar.io *.hotjar.io match.adsrvr.org podbean.com *.podbean.com slatergordon.com.au *.slatergordon.com.au stripe.com *.stripe.com tealiumiq.com *.tealiumiq.com vimeo.com *.vimeo.com widget.trustpilot.com youtube.com *.youtube.com; frame-ancestors 'self' slatergordon.com.au *.slatergordon.com.au; connect-src 'self' googleapis.com *.googleapis.com google-analytics.com *.google-analytics.com force.com *.force.com my.salesforce-sites.com *.my.salesforce-sites.com my.site.com *.my.site.com formstack.com *.formstack.com *.s3.amazonaws.com *.tealiumiq.com atag.adgile.media crazyegg.com *.crazyegg.com doubleclick.net *.doubleclick.net ekr.zdassets.com hotjar.com *.hotjar.com *.hotjar.com:* wss://*.hotjar.com hotjar.io *.hotjar.io match.adsrvr.org slatergordonchat.zendesk.com trkcall.com *.trkcall.com visualwebsiteoptimizer.com *.visualwebsiteoptimizer.com wss://widget-mediator.zopim.com www.facebook.com yourir.info; |
permissions-policy: |
accelerometer=(), autoplay=(), camera=(), document-domain=(), encrypted-media=(), fullscreen=(self "https://www.youtube.com"), geolocation=(self), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), xr-spatial-tracking=() |
feature-policy: |
accelerometer 'none'; autoplay 'none'; camera 'none'; document-domain 'none'; encrypted-media 'none'; fullscreen 'self' https://www.youtube.com; geolocation 'self'; gyroscope 'none'; magnetometer 'none'; microphone 'none'; midi 'none'; payment 'none'; picture-in-picture 'none'; publickey-credentials-get 'none'; screen-wake-lock 'none'; sync-xhr 'none'; usb 'none'; xr-spatial-tracking 'none'; |
cache-control: |
public, max-age=0, s-maxage=31536000 |
vary: |
Accept-Encoding |
x-cache: |
Miss from cloudfront |
via: |
1.1 b031f43146c9801101822eabdc464390.cloudfront.net (CloudFront) |
x-amz-cf-pop: |
PRG50-C1 |
alt-svc: |
h3=":443"; ma=86400 |
x-amz-cf-id: |
gUrc4JEWfCNgorBRs3u5HHQYsyhJwmsgk8S7-Hqt-0Or2C7OWOHOtg== |