Security Headers and Event Routes Hardened Public Sites
Public sites gain stronger security headers, event-instance route improvements, compressed responses, and sorting fixes for search and event endpoints.
As the first production sites came online, they needed a safer, more predictable baseline. Public sites now gain stronger security headers, event-instance route improvements, compressed responses, and sorting fixes for search and event endpoints, so early production sites load more predictably and carry a safer default security posture while the custom-theme architecture continues to evolve.
Operational work with tangible outcomes
For customer launches, these are improvements with direct effects: pages load more predictably, event routes are easier to wire, and public responses carry safer default headers. These are the changes that matter most once real traffic arrives on a production site.
A safer baseline before launch
Security header defaults reduce the repeated setup work involved in preparing a site for launch. They provide a consistent starting point, while teams can still review project-specific security requirements before going live.