Header findings
4API key exposed in JS bundle
A live OpenAI key was leaked in /static/app.js; rotate immediately.
Missing header: Content-Security-Policy
The Content-Security-Policy header is absent from HTTP responses.
Permissions-Policy not set
Define explicit permissions for camera, microphone, and geolocation.
Strict-Transport-Security present
HSTS configured with max-age=31536000; includeSubDomains.