Do security headers matter for my app?
They matter a little. Security headers such as Content-Security-Policy, Strict-Transport-Security and X-Content-Type-Options tell browsers to block some attacks, and most hosting platforms let you add them in minutes. Scanners report missing headers prominently, but they are rarely the serious finding. Fix them, then spend your attention on authorization and database rules.
The useful ones
| Header | What it does |
|---|---|
| Strict-Transport-Security | Forces HTTPS on return visits |
| Content-Security-Policy | Limits where scripts can load from, reducing XSS impact |
| X-Content-Type-Options: nosniff | Stops browsers guessing file types |
| Referrer-Policy | Controls what URL is sent to other sites |
| frame-ancestors (in CSP) | Stops your app being framed for clickjacking |
Adding them
Set them in your host's configuration (for example a headers file or the platform's settings) or at a CDN such as Cloudflare. Start Content-Security-Policy in report-only mode so it does not break your app.
Checking yours
Open your site, then the browser's developer tools, and look at the response headers on the main page. Free online header checkers grade them in seconds. Typical AI-built apps hosted on modern platforms already have HTTPS and some defaults; most are missing a Content-Security-Policy and sometimes Strict-Transport-Security.
Add HSTS once you are sure the whole site, including subdomains you include, works over HTTPS. Build the Content-Security-Policy gradually: start with report-only, list the domains your app actually loads scripts and styles from, and tighten from there. A strict policy is one of the best defences against XSS, because it stops injected scripts from running even when a sanitising step is missed. Then move on: headers are hygiene, and the findings that cause breaches are elsewhere.
Getting it checked
TrazTech offers vibe-coding QA and security review, listed from $2,000 CAD. Get at least one other quote on the same scope; the questions to ask a testing firm help compare them.
Related questions
Get a scope for your app
Tell us what you built, what it stores and who is about to use it.
Get matchedCommon questions
Why does my scanner rate these as high?
Scanners score what they can see. A tester scores what an attacker can do, and missing headers alone rarely let them do much.
Will a strict CSP break my AI-built app?
It can, if the app loads scripts from many places. Test in report-only mode first.