content-length: |
126354 |
connection: |
close |
content-type: |
text/html; charset=utf-8 |
date: |
Tue, 01 Oct 2024 13:52:19 GMT |
access-control-expose-headers: |
Request-Context |
cache-control: |
no-cache, no-store |
expires: |
-1 |
pragma: |
no-cache |
set-cookie: |
shell#lang=en; path=/; secure; SameSite=None,ASP.NET_SessionId=5030wwih2hyzvvax2ouyijkd; path=/; secure; HttpOnly; SameSite=None,shell#lang=en; path=/; secure; SameSite=None,ASP.NET_SessionId=5030wwih2hyzvvax2ouyijkd; path=/; secure; HttpOnly; SameSite=None,SC_ANALYTICS_GLOBAL_COOKIE=1f3c3b316b744d3d879cfb433e947ccb|False; expires=Fri, 29-Sep-2034 13:52:19 GMT; path=/; secure; HttpOnly; SameSite=None,__RequestVerificationToken=He3OPrkCB1-P11uBNHOCd2KnbsMtCqZpauyXkpg6Cajc7a8k9LZJO7POP3CFNgHoELMg6trMtHC_fWadfZ-mvMfXFBVCMRrEsy6FmRDuz-c1; path=/; secure; HttpOnly; SameSite=None,TS01e0082c=015a26809278ed9d4929ee567a2d83c27f49ea7ba68b17b33887aab63fb16fb7d0909086d2bf0c76510832ed875b7441d569dac8da; Path=/; Secure; HTTPOnly,TS6a47c25a027=08caa50cc8ab200014e6151e1aaeaa7cfb4ee25e0fa87d93c5ede382d44a6a4624f377420534e0ee08e97608f61130001fa280f76716a58cb3d76454009462e0a65a68d2467682d8292099c9bf44dcda2433b44734b1f79c954a111e450e92d1; Path=/ |
x-frame-options: |
SAMEORIGIN |
content-security-policy: |
default-src 'self' *.relay42.com 6162542.fls.doubleclick.net;script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: *.centraalbeheer.nl *.doubleclick.net *.facebook.net *.google.com *.googlesyndication.com *.hs-scripts.com *.linkedin.com *.r42tag.com *.relay42.com *.svtrd.com *.usabilla.com achmeadpm.achmea.nl:9999 ajax.googleapis.com api.usabilla.com app.contentsquare.com bat.bing.com cba.nmrc.nl cdn.ampproject.org cdn.harvest.graindata.com d6tizftlrpuof.cloudfront.net googleads.g.doubleclick.net https://www.googleoptimize.com https://www.googletagmanager.com js.hs-analytics.net js.hs-banner.com js.hsadspixel.net js.hsleadflows.net js.monitor.azure.com js.usemessages.com maps.googleapis.com player.quadia.net r.bing.com snap.licdn.com static.cloud.coveo.com surfly.com t.contentsquare.net tags.nmrc.nl www.dwin1.com www.google-analytics.com www.googleadservices.com www.youtube.com www.zenaps.com www.awin1.com;script-src-elem 'unsafe-inline' https:;style-src 'self' 'unsafe-inline' d6tizftlrpuof.cloudfront.net www.google.com optimize.google.com static.cloud.coveo.com;img-src 'self' data: *.centraalbeheer.nl *.contentsquare.net *.doubleclick.net *.googlesyndication.com *.r42tag.com *.relay42.com *.svtrd.com *.svtrd.com *.usabilla.com adservice.google.com adservice.google.nl bat.bing.com c.az.contentsquare.net c.contentsquare.net cba.imgix.net clients1.google.com d6tizftlrpuof.cloudfront.net forms.hubspot.com https://www.googletagmanager.com l.contentsquare.net linkedin.com maps.googleapis.com maps.gstatic.com optimize.google.com px.ads.linkedin.com px4.ads.linkedin.com region1.analytics.google.com region1.google-analytics.com server.arcgisonline.com track.hubspot.com www.advieskeuze.nl www.awin1.com www.facebook.com www.google-analytics.com www.google.com www.google.nl www.googleapis.com www.googletagmanager.com www.zenaps.com https://i.ytimg.com;font-src 'self';connect-src 'self' analytics.cloud.coveo.com *.achmea.nl *.centraalbeheer.nl *.contentsquare.net *.doubleclick.net *.facebook.net *.googlesyndication.com *.hubapi.com *.nxtid.nl api.advieskeuze.nl api.hsforms.com api.hubspot.com api.usabilla.com bat.bing.com c.az.contentsquare.net c.contentsquare.net calculations.figlo.com cba.imgix.net cba.nmrc.nl controle.achmea.consentmonitor.nl https://*.in.applicationinsights.azure.com forms.hubspot.com formulier.centraalbeheer.nl geocode.arcgis.com k-aeu1.contentsquare.net l.contentsquare.net maps.googleapis.com r.contentsquare.net region1.analytics.google.com region1.google-analytics.com surfly.com t.svtrd.com wss://bat.bing.com www.google-analytics.com www.google.com *.service.signalr.net wss://*.service.signalr.net adservice.google.com adservice.google.nl px.ads.linkedin.com https://*.monitor.azure.com;media-src 'self';object-src 'self';child-src 'self' blob: youtube.com *.doubleclick.net t.svtrd.com cba.nmrc.nl www.youtube-nocookie.com youtube-nocookie.com surfly.com optimize.google.com d6tizftlrpuof.cloudfront.net redirect.surfly.com centraalbeheer-nl-p.surfly.com surfly.com surfly-com-p.surfly.com *.centraalbeheer.nl player.quadia.net localfocuswidgets.net;frame-ancestors 'self' youtube.com www.youtube-nocookie.com youtube-nocookie.com player.quadia.net;form-action * 'self' t.svtrd.com *.achmea.nl;manifest-src 'self';report-uri https://centraalbeheer.ams.report-uri.com/r/t/csp/enforce; |
content-security-policy-report-only: |
default-src 'self' *.relay42.com 6162542.fls.doubleclick.net;script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: *.centraalbeheer.nl *.doubleclick.net *.facebook.net *.google.com *.googlesyndication.com *.hs-scripts.com *.linkedin.com *.r42tag.com *.relay42.com *.svtrd.com *.usabilla.com achmeadpm.achmea.nl:9999 ajax.googleapis.com api.usabilla.com app.contentsquare.com bat.bing.com cba.nmrc.nl cdn.ampproject.org cdn.harvest.graindata.com d6tizftlrpuof.cloudfront.net googleads.g.doubleclick.net https://www.googleoptimize.com https://www.googletagmanager.com js.hs-analytics.net js.hs-banner.com js.hsadspixel.net js.hsleadflows.net js.monitor.azure.com js.usemessages.com maps.googleapis.com player.quadia.net r.bing.com snap.licdn.com static.cloud.coveo.com surfly.com t.contentsquare.net tags.nmrc.nl www.dwin1.com www.google-analytics.com www.googleadservices.com www.youtube.com www.zenaps.com www.awin1.com;script-src-elem 'unsafe-inline' https:;style-src 'self' 'unsafe-inline' d6tizftlrpuof.cloudfront.net www.google.com optimize.google.com static.cloud.coveo.com;img-src 'self' data: *.centraalbeheer.nl *.contentsquare.net *.doubleclick.net *.googlesyndication.com *.r42tag.com *.relay42.com *.svtrd.com *.svtrd.com *.usabilla.com adservice.google.com adservice.google.nl bat.bing.com c.az.contentsquare.net c.contentsquare.net cba.imgix.net clients1.google.com d6tizftlrpuof.cloudfront.net forms.hubspot.com https://www.googletagmanager.com l.contentsquare.net linkedin.com maps.googleapis.com maps.gstatic.com optimize.google.com px.ads.linkedin.com px4.ads.linkedin.com region1.analytics.google.com region1.google-analytics.com server.arcgisonline.com track.hubspot.com www.advieskeuze.nl www.awin1.com www.facebook.com www.google-analytics.com www.google.com www.google.nl www.googleapis.com www.googletagmanager.com www.zenaps.com https://i.ytimg.com;font-src 'self';connect-src 'self' analytics.cloud.coveo.com *.achmea.nl *.centraalbeheer.nl *.contentsquare.net *.doubleclick.net *.facebook.net *.googlesyndication.com *.hubapi.com *.nxtid.nl api.advieskeuze.nl api.hsforms.com api.hubspot.com api.usabilla.com bat.bing.com c.az.contentsquare.net c.contentsquare.net calculations.figlo.com cba.imgix.net cba.nmrc.nl controle.achmea.consentmonitor.nl https://*.in.applicationinsights.azure.com forms.hubspot.com formulier.centraalbeheer.nl geocode.arcgis.com k-aeu1.contentsquare.net l.contentsquare.net maps.googleapis.com r.contentsquare.net region1.analytics.google.com region1.google-analytics.com surfly.com t.svtrd.com wss://bat.bing.com www.google-analytics.com www.google.com *.service.signalr.net wss://*.service.signalr.net adservice.google.com adservice.google.nl px.ads.linkedin.com https://*.monitor.azure.com;media-src 'self';object-src 'self';child-src 'self' blob: youtube.com *.doubleclick.net t.svtrd.com cba.nmrc.nl www.youtube-nocookie.com youtube-nocookie.com surfly.com optimize.google.com d6tizftlrpuof.cloudfront.net redirect.surfly.com centraalbeheer-nl-p.surfly.com surfly.com surfly-com-p.surfly.com *.centraalbeheer.nl player.quadia.net localfocuswidgets.net;frame-ancestors 'self' youtube.com www.youtube-nocookie.com youtube-nocookie.com player.quadia.net;form-action * 'self' t.svtrd.com *.achmea.nl;manifest-src 'self';report-uri https://centraalbeheer.ams.report-uri.com/r/t/csp/enforce; |
x-content-type-options: |
nosniff |
request-context: |
appId=cid-v1:9f336a5e-6631-454e-8cf8-fd07f4dd7f40 |
accept-ch: |
Sec-CH-UA-Full-Version-List,Sec-CH-UA-Platform-Version,Sec-CH-UA-Arch,Sec-CH-UA-Model,Sec-CH-UA-Bitness |
x-xss-protection: |
1; mode=block |
referrer-policy: |
strict-origin-when-cross-origin |
strict-transport-security: |
max-age=31536000; includeSubDomains |
vary: |
Accept-Encoding |