Enable Native Clickjacking Protection via X-Frame-Options and CSP Frame-Ancestors Headers

Currently, HubSpot-hosted pages do not set X-Frame-Options or Content-Security-Policy (CSP) frame-ancestors headers by default. This leaves HubSpot sites potentially vulnerable to clickjacking attacks.

While adding a CSP meta tag in the <head> of HubSpot pages helps in most browsers, it is not as robust as server-level headers and requires ongoing manual management. For regulated industries or scenarios requiring PCI-level compliance, native support for setting these headers directly in HubSpot would significantly improve security and reduce reliance on third-party infrastructure.