Security, CSP, and consent
Allow only the Flatzer host required by the widget, adapt the directive to your policy, and load the agent after consent when needed.
Content-Security-Policy:
script-src 'self' https://flatzer.com;
connect-src 'self' https://flatzer.com;
img-src 'self' data: https://flatzer.com;
frame-src https://flatzer.com;Start with the minimum host
The loader and its transport use https://flatzer.com. Start by allowing that origin in script-src and connect-src; add img-src or frame-src only if the browser reports that configured content needs them. Adapt existing nonces and directives instead of replacing your whole policy.
Respect your consent model
If your policy requires consent before contacting external services, do not load the snippet until consent is given and remove the widget when it is withdrawn. This technical guide does not replace a legal review of your site.