Secure a web application at its edge — Content Security Policy, security response headers, subresource integrity, cookie and session flags, CORS, the reverse-proxy trust boundary, and bot/spam protection. Use when setting up or reviewing headers and CSP, adding a third-party script or font, configuring cookies or CORS, putting an app behind a CDN or proxy, protecting a public form, or when a browser console reports a blocked resource.