Group
  • Security

    Enforce security headers site-wide

    Adds CSP, HSTS, X-Frame-Options, and other security headers with a report-only rollout before enforcing.

    • Improve quality
    • Plan & validate
    • Intermediate
    • General

Free Prompt

Add security headers to my app site-wide. Set up Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options, and Referrer-Policy. Start CSP in report-only mode, review the reports with me, then switch to enforcing.

What This Does / How This Helps

Adds the security headers browsers expect — CSP, HSTS, X-Frame-Options, and friends — with CSP rolled out in report-only mode first so nothing breaks. Once the reports look clean, it switches to enforcing, shutting down clickjacking, downgrade, and content-sniffing attacks site-wide.

Want to skip doing this by hand?

Fortivibe audits your app for all of the areas these prompts cover (and more).

See What We Check

Related Prompts