- use all Helmet's default headers except `X-DNS-Prefetch-Control` - use `Referrer-Policy` - use cache headers when: - a user is logged in, OR - a project is displayed