Grade your security headers.
Run curl -I https://yoursite.com (or copy Response Headers from dev tools) and paste them below. You get a grade, what's present, weak, or missing — and the exact headers to add.
The cheapest security you're not shipping
Security headers are close to free — a few lines in your reverse proxy — and they shut down whole classes of attack: protocol downgrades, clickjacking, MIME confusion, and a big slice of XSS. On a managed platform some of these came set by default. On a box you own, they're yours to add, and they're the first thing a security review checks. This grades what you've got and hands you the rest.
Headers are one part of the request path. A backend also needs service routing, health checks, and traffic rules that act on requests. Keep the proxy's header configuration explicit and manage the operating workflow around it.
Configure the headers. Control managed traffic.
Infraveil's managed gateway routes requests to your backend services and applies configured traffic rules, alongside service health and release controls. Your reverse proxy and application still own the headers they send; use this checker when changing that configuration.
See how it works