Security Settings¶
Beyond authentication, the Security module lets you configure security headers (such as Content-Security-Policy, Referrer-Policy, and Permissions-Policy) from Security → Settings → Security Headers or from configuration.
Also see Data Protection for how the keys used to protect authentication cookies and tokens are stored, which matters as soon as you run multiple instances of the same site.