--- title: Security --- By default, Sapper does not add security headers to your app, but you may add them yourself using middleware such as [Helmet][]. ### Content Security Policy (CSP) Sapper generates inline `