cache-control: |
no-cache |
pragma: |
no-cache |
content-type: |
text/html; charset=utf-8 |
expires: |
-1 |
content-security-policy: |
default-src 'self' cs-cms-cc.equitad.local; script-src 'self' *.googleapis.com *.gstatic.com www.google.com apis.google.com connect.facebook.net ajax.aspnetcdn.com https://www.youtube.com platform.twitter.com https://syndication.twitter.com/ https://s.ytimg.com https://publish.twitter.com *.twimg.com platform.linkedin.com http://platform.stumbleupon.com/1/widgets.js https://*.googletagmanager.com www.google-analytics.com googleads.g.doubleclick.net bat.bing.com static.hotjar.com widget.trustpilot.com *.callrail.com www.googleadservices.com ssl.google-analytics.com script.hotjar.com gateway.zscalerthree.net *.kameleoon.eu cdn.prod.ca.five9.net *.kameleoon.com js.adsrvr.org *.amazon-adsystem.com amazon-adsystem.com cdn.ampproject.org js.hs-scripts.com js.hs-analytics.net js.hs-banner.com js.hsleadflows.net forms.hubspot.com js.hscollectedforms.net *.eloqua.com *.en25.com https://cdn.insight.sitefinity.com https://dec.azureedge.net web-chat.nativechat.com 'unsafe-inline' 'unsafe-eval'; style-src 'self' *.googleapis.com *.gstatic.com netdna.bootstrapcdn.com kendo.cdn.telerik.com www.google.com platform.twitter.com/css/ *.twimg.com *.kameleoon.com https://cdn.insight.sitefinity.com https://dec.azureedge.net web-chat.nativechat.com 'unsafe-inline'; img-src 'self' *.gstatic.com *.googleapis.com platform.tumblr.com web.facebook.com www.facebook.com www.redditstatic.com www.linkedin.com i.ytimg.com pbs.twimg.com *.twimg.com data: blob: https://*.googletagmanager.com www.google.com www.google.co.cr www.google-analytics.com bat.bing.com stats.g.doubleclick.net googleads.g.doubleclick.net syndication.twitter.com static.licdn.com platform.twitter.com www.equitablebank.ca www.google.ca ssl.google-analytics.com cs-cms-cc.equitad.local ad.doubleclick.net *.kameleoon.com track.hubspot.com js.hsleadflows.net forms.hsforms.com *.eloqua.com https://cdn.insight.sitefinity.com https://dec.azureedge.net web-chat.nativechat.com; font-src 'self' fonts.gstatic.com kendo.cdn.telerik.com netdna.bootstrapcdn.com data:; frame-src 'self' *.fls.doubleclick.net www.facebook.com www.google.com cdn.callrail.com widget.trustpilot.com www.youtube.com td.doubleclick.net cdn.prod.ca.five9.net www.lightcast.com *.amazon-adsystem.com insight.adsrvr.org forms.hsforms.com web-chat.nativechat.com; connect-src 'self' data: accounts.google.com *.gstatic.com https://*.googletagmanager.com www.google-analytics.com stats.g.doubleclick.net bat.bing.com *.callrail.com csmetrics.hotjar.com metrics.hotjar.io analytics.google.com *.kameleoon.com *.kameleoon.eu *.kameleoon.io pagead2.googlesyndication.com https://*.hotjar.io wss://*.hotjar.com *.amazon-adsystem.com *.paa-reporting-advertising.amazon forms.hubspot.com *.hsforms.com https://*.insight.sitefinity.com https://*.dec.sitefinity.com; media-src 'self' data: blob:; child-src 'self' https://platform.twitter.com/ https://syndication.twitter.com/ https://www.youtube.com/ https://www.youtube-nocookie.com https://player.vimeo.com/ https://w.soundcloud.com/ apis.google.com accounts.google.com staticxx.facebook.com www.facebook.com web.facebook.com badge.stumbleupon.com web-chat.nativechat.com |
cross-origin-embedder-policy: |
unsafe-none |
cross-origin-opener-policy: |
unsafe-none |
cross-origin-resource-policy: |
cross-origin |
permissions-policy: |
accelerometer=(self), ambient-light-sensor=(self), autoplay=(self), battery=(self), camera=(self), cross-origin-isolated=(self), display-capture=(self), document-domain=(self), encrypted-media=(self), execution-while-not-rendered=(self), execution-while-out-of-viewport=(self), fullscreen=(self), geolocation=(self), gyroscope=(self), keyboard-map=(self), magnetometer=(self), microphone=(self), midi=(self), navigation-override=(self), payment=(self), picture-in-picture=(self), publickey-credentials-get=(self), screen-wake-lock=(self), sync-xhr=(self), usb=(self), web-share=(self), xr-spatial-tracking=(self) |
referrer-policy: |
no-referrer-when-downgrade |
x-content-type-options: |
nosniff |
x-frame-options: |
SAMEORIGIN |
x-xss-protection: |
1; mode=block |
strict-transport-security: |
max-age=31536000; includeSubDomains; preload |
content-length: |
66102 |
date: |
Thu, 03 Oct 2024 02:58:48 GMT |
connection: |
close |
set-cookie: |
_Secure-ID=123; Secure; Domain=equitablebank.ca |
|