Skip to main content
← Changelog

Security Headers and Event Routes Hardened Public Sites

Public sites gain stronger security headers, event-instance route improvements, compressed responses, and sorting fixes for search and event endpoints.

As the first production sites came online, they needed a safer, more predictable baseline. Public sites now gain stronger security headers, event-instance route improvements, compressed responses, and sorting fixes for search and event endpoints, so early production sites load more predictably and carry a safer default security posture while the custom-theme architecture continues to evolve.

Operational work with tangible outcomes

For customer launches, these are improvements with direct effects: pages load more predictably, event routes are easier to wire, and public responses carry safer default headers. These are the changes that matter most once real traffic arrives on a production site.

A safer baseline before launch

Security header defaults reduce the repeated setup work involved in preparing a site for launch. They provide a consistent starting point, while teams can still review project-specific security requirements before going live.

Improvement Security