company

EEK's Security Headers Are Now Audit-Grade

EEK deployed HSTS preload, a comprehensive Content Security Policy covering Stripe and CloudFront, and Permissions-Policy headers. The platform meets the standards of regulated financial and legal environments.

14 May 20262 min read

Security Infrastructure That Matches the Sensitivity of the Data

EEK processes card payments, holds personal vehicle and customer data, generates legal documents, and handles insurance claims documentation. The platform's security posture needs to match the sensitivity of what it handles.

EEK deployed HTTP Strict Transport Security (HSTS) preload with a one-year max-age on both the apex and www domains — ensuring every browser that has ever visited eek.nz enforces HTTPS permanently. A comprehensive Content Security Policy was configured, covering Stripe's payment frame allowlist, CloudFront media for call recordings, and Vercel's edge function scripts. Permissions-Policy headers restrict what browser APIs the site can access.

What This Means for Customers

Every EEK transaction — from viewing your portal to paying your invoice — takes place on a connection that cannot be downgraded to HTTP, on a page that cannot load content from unauthorised sources, on a site that cannot be manipulated by malicious scripts. These are not visible to users, but they are the infrastructure that makes EEK safe to use for payment and sensitive personal data. The configuration now meets the standards expected of regulated financial and legal service environments.

Need help right now?

Our team is available 24/7 to help with misfuelling emergencies.

0800 769 000