X-Content-Type-Options, X-Frame-Options, and Referrer-Policy all defaulted to empty (disabled). Set defaults to nosniff, DENY, and strict-origin-when-cross-origin respectively. Operators can still override or disable via environment variables. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>