# 2.7 — Security headers (GREEN) Phase: 2 — Topology (Surface B) Stage: GREEN - [ ] Security headers on all responses: CSP (no `unsafe-inline`), `X-Content-Type-Options: nosniff`, `Referrer-Policy: no-referrer`, HSTS; CORS same-origin only