https://www.lusha.com/privacy_topic/data-privacy/

Submitted URL:
https://www.lusha.com/privacy_topic/data-privacyRedirected
Report Finished:

Risks · 0 found

Practices that may pose security risks

  • No classification

Security Headers · 7 found

HTTP response headers that can harden the security of a web application

Learn more...
NameValueSupportInfo
Strict-Transport-Securitymax-age=31536000; includeSubDomainsGoodDeclare that a website is only accessible over a secure connection (HTTPS).

Click to learn more...
X-Frame-OptionsSAMEORIGINGoodIndicate whether a browser should be allowed to render a page in a <frame>, <iframe>, <embed> or <object>.

Click to learn more...
X-Content-Type-OptionsnosniffGoodIndicate that the MIME types advertised in the Content-Type headers should be followed and not be changed.

Click to learn more...
Content-Security-Policydefault-src 'self' *.google.com *.lusha.com https://www.g2.com https://gist.github.com localhost https://*.clarity.ms https://c.bing.com 'unsafe-inline'; img-src 'self' data: https://forms.hsforms.com/ https://forms-na1.hsforms.com/ https://js.chilipiper.com/images/ https://www.g2.com https://www.google.co.uk https://*.googlesyndication.com https://*.ads.linkedin.com https://analytics.twitter.com https://*.intercomcdn.com https://ci5.googleusercontent.com https://cdn.cookielaw.org https://sync-t1.taboola.com https://googleads.g.doubleclick.net/ https://*.privacysandbox.googleadservices.com https://ct.capterra.com/ https://cdn.cookielaw.org/logos https://trc.taboola.com https://cds.taboola.com https://google.com/pagead/ https://i.ytimg.com https://alb.reddit.com/ https://www.google.com/pagead/ https://mk0lplushacrhatidvnw.kinstacdn.com/ https://www.google.com/ads/ga-audiences https://t.co/i/ https://c.bing.com/c.gif https://c.clarity.ms/c.gif https://cx.atdmt.com https://q.quora.com connect.facebook.net www.googletagmanager.com https://s.w.org/images/core/emoji/13.0.0/svg/ https://www.w3.org https://www-services.lusha.com www.linkedin.com embedwistia-a.akamaihd.net https://js.intercomcdn.com https://static.intercomassets.com https://downloads.intercomcdn.com https://uploads.intercomusercontent.com https://gifs.intercomcdn.com https://messenger-apps.intercom.io *.intercom-attachments.com forms.hubspot.com p.adsymptotic.com www.yesware.com www.outreach.io *.lusha.com ek1m512i34ve2rek3k8v02in-wpengine.netdna-ssl.com salesloft.com www.google.com www.google-analytics.com www.google.co.il *.gstatic.com bat.bing.com www.facebook.com track.hubspot.com stats.g.doubleclick.net *.google-analytics.com *.analytics.google.com https://11988414.fls.doubleclick.net https://ad.doubleclick.net https://ade.googlesyndication.com https://stats.sa-as.com https://privacy-policy.truste.com https://flagcdn.com https://secure.gravatar.com https://track-eu1.hubspot.com https://perf-eu1.hsforms.com https://downloads.intercomcdn.eu https://static.intercomassets.eu; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.intercomcdn.com data: localhost https://www.trustradius.com/trustquotes/trustquotes.js https://pagead2.googlesyndication.com/ https://js.hsleadflows.net https://www.g2.com https://www.google.com/pagead https://cdn.nmgassets.com https://www.googleadservices.com https://trc.taboola.com https://ssl.google-analytics.com/ga.js https://cdn.taboola.com https://analytics.tiktok.com https://cdn.cookielaw.org https://tpc.googlesyndication.com https://www.redditstatic.com/ads/pixel.js https://mk0lplushacrhatidvnw.kinstacdn.com/ https://tags.crwdcntrl.net https://analytics.twitter.com/ https://cdn.jsdelivr.net/npm/@webcomponents/[email protected]/bundles/webcomponents-sd.js https://ssl.kaptcha.com/collect/sdk https://cdn.jsdelivr.net/npm/@webcomponents/[email protected]/bundles/webcomponents-ce.js https://cdnjs.cloudflare.com/ajax/libs/webcomponentsjs/2.4.1/custom-elements-es5-adapter.js https://static.ads-twitter.com/uwt.js https://unpkg.com/react@16/umd/react.production.min.js https://unpkg.com/react-dom@16/umd/react-dom.production.min.js https://www.clarity.ms js.hs-banner.com js.hsadspixel.net *.lusha.com js.intercomcdn.com https://app.intercom.io widget.intercom.io snap.licdn.com www.comeet.co www.comeet.com forms.hsforms.com js.hsforms.net s.ytimg.com www.googletagmanager.com *.google.com www.google-analytics.com *.googleadservices.com *.typekit.net js.stripe.com connect.facebook.net bat.bing.com sjs.bizographics.com survey.survicate.com surveys-static.survicate.com js.hs-scripts.com js.hs-analytics.net js.usemessages.com tracking.g2crowd.com *.gstatic.com px.ads.linkedin.com www.linkedin.com *.fullstory.com fullstory.com dc.ads.linkedin.com *.salesloft.com *.youtube.com https://cdnjs.cloudflare.com/ajax/libs/js-sha256/ https://stats.sa-as.com/live.js https://unpkg.com/aos@next/dist/aos.js https://ipinfo.io https://extreme-ip-lookup.com https://unpkg.com/@lottiefiles/[email protected]/dist/lottie-player.js https://platform.linkedin.com/in.js https://ml314.com/ https://vi.ml314.com/ https://js.chilipiper.com/marketing.js https://cdn.amcharts.com/ https://js-eu1.hs-scripts.com/ https://js-eu1.hubspot.com/ https://js-eu1.hsleadflows.net/ https://js-eu1.hs-banner.com/ https://js-eu1.hs-analytics.net/ https://js-eu1.hsadspixel.net/fb.js https://ajax.googleapis.com/ https://googleads.g.doubleclick.net/ https://video-messages.intercomcdn.com https://messenger-apps.eu.intercom.io https://*.intercom-attachments-1.com https://*.intercom-attachments.eu https://*.intercom-attachments-2.com https://*.intercom-attachments-3.com https://*.intercom-attachments-4.com https://*.intercom-attachments-5.com https://*.intercom-attachments-6.com https://*.intercom-attachments-7.com https://*.intercom-attachments-8.com https://*.intercom-attachments-9.com https://static.intercomassets.eu https://js.partnerstack.com; style-src 'self' 'unsafe-inline' localhost https://www.g2.com https://mk0lplushacrhatidvnw.kinstacdn.com/ https://www.googletagmanager.com *.comeet.co *.comeet.com *.lusha.com *.typekit.net tagmanager.google.com fonts.googleapis.com; font-src 'self' data: localhost https://fonts.intercomcdn.com https://www.g2.com https://mk0lplushacrhatidvnw.kinstacdn.com/ https://www.google.com use.typekit.net *.lusha.com js.intercomcdn.com surveys-static.survicate.com fonts.googleapis.com fonts.gstatic.com; connect-src 'self' data: localhost https://*.clarity.ms https://px.ads.linkedin.com https://px.ads.linkedin.com https://forms.hsforms.com/embed/ https://forms.hubspot.com/ https://hubspot-forms-static-embed.s3.amazonaws.com/prod/ https://www.google.co.il/ads/ https://api.chilipiper.com/ https://tracking.chilipiper.com/ https://www.g2.com https://api.hubapi.com https://analytics.tiktok.com https://googleads.g.doubleclick.net/ https://privacyportal-eu.onetrust.com/request/v1/consentreceipts https://pagead2.googlesyndication.com https://geolocation.onetrust.com *.taboola.com https://*.crwdcntrl.net/ https://*.google.com https://cdn.cookielaw.org *.lottiefiles.com https://o412513.ingest.sentry.io https://www.clarity.ms bat.bing.com https://www-services.lusha.com api.hubapi.com https://api.intercom.io https://api-iam.intercom.io https://api-ping.intercom.io https://nexus-websocket-a.intercom.io https://nexus-websocket-b.intercom.io https://nexus-long-poller-a.intercom.io https://nexus-long-poller-b.intercom.io wss://nexus-websocket-a.intercom.io wss://nexus-websocket-b.intercom.io https://uploads.intercomcdn.com https://uploads.intercomusercontent.com http://www-services-local.lusha.co:3030/v2/user-events http://www-services-local.lusha.com:3030/v2/user-events https://private-144d5-gallusha.apiary-mock.com/questions embedwistia-a.akamaihd.net api.hubspot.com *.lusha.com *.fullstory.com respondent.survicate.com www.google-analytics.com scout.salesloft.com www.facebook.com stats.g.doubleclick.net *.google-analytics.com *.analytics.google.com https://ipinfo.io https://api.ipify.org https://ipecho.net https://myexternalip.com https://cta-eu1.hubspot.com https://perf-eu1.hsforms.com https://api-eu1.hubapi.com https://track-eu1.hubspot.com https://forms-eu1.hubspot.com https://tracking.g2crowd.com https://google.com/pagead https://google.com/ccm https://api-iam.eu.intercom.io https://via.intercom.io https://api.eu.intercom.io https://api-iam.intercom.io https://api-iam.eu.intercom.io https://api-ping.intercom.io https://nexus-europe-websocket.intercom.io wss://nexus-europe-websocket.intercom.io https://uploads.intercomcdn.eu https://uploads.eu.intercomcdn.com; child-src localhost https://www.g2.com https://share.intercom.io https://intercom-sheets.com https://www.intercom-reporting.com https://www.youtube.com https://player.vimeo.com https://fast.wistia.net; frame-src localhost https://tpc.googlesyndication.com https://capture.navattic.com https://lusha.chilipiper.com https://www.g2.com https://business.facebook.com https://privacyportal-eu.onetrust.com/ https://*.doubleclick.net https://www.youtube.com/ https://tsdtocl.com/ https://www.linkedin.com www.comeet.com intercom-sheets.com forms.hsforms.com forms.hubspot.com js.stripe.com www.google.com *.lusha.com www.facebook.com *.youtube.com www.comeet.co https://11988414.fls.doubleclick.net; form-action localhost www.facebook.com *.lusha.com https://intercom.help https://api-iam.intercom.io https://forms.hsforms.com/submissions/ https://intercom.help https://api-iam.eu.intercom.io; worker-src blob: *.lusha.com localhost; frame-ancestors 'self' *.lusha.com https://www.lusha-business.com/contact-us; media-src 'self' data: blob: localhost *.lusha.com https://*.intercomcdn.com https://js.intercomcdn.com; object-src 'none'; GoodControl resources the user agent is allowed to load for a given page.

Click to learn more...
Referrer-Policyno-referrer-when-downgradeGoodControl how much referrer information should be included with requests.

Click to learn more...
Clear-Site-DataGoodControl the data stored by a client browser for their origins.

Click to learn more...
X-Permitted-Cross-Domain-PoliciesGoodControl whether a web client such as Adobe Flash Player or Adobe Acrobat has permission to handle data across domains.

Click to learn more...
Permissions-Policyaccelerometer=(); camera=(); geolocation=(); gyroscope=(); magnetometer=(); microphone=(); payment=(); usb=()NewAllow and deny the use of browser features in a document or iframe.

Click to learn more...
Cross-Origin-Embedder-PolicyNewConfigure embedding cross-origin resources into the document.

Click to learn more...
Cross-Origin-Opener-PolicyNewEnsure a top-level document does not share a browsing context group with cross-origin documents.

Click to learn more...
Cross-Origin-Resource-PolicyNewRequest that the browser blocks no-cors cross-origin/cross-site requests to the given resource.

Click to learn more...
X-XSS-Protection1; mode=blockDeprecatedDeprecated. Stops pages from loading when they detect reflected cross-site scripting (XSS) attacks.

Click to learn more...
Feature-PolicyDeprecatedDeprecated. Replaced by the Permissions-Policy header.

Click to learn more...
Expect-CTDeprecatedDeprecated. Opt in to reporting and/or enforcement of Certificate Transparency requirements.

Click to learn more...
Public-Key-PinsDeprecatedDeprecated. Allows HTTPS websites to resist impersonation by attackers using mis-issued or otherwise fraudulent certificates.

Click to learn more...

Security Violations · 0 found

Requests or resources offending security policies

  • None found

Certificates · 10 found

SSL/TLS Certificates enable websites to encrypt transactions between the client and the server and provide server identity verification

SubjectIssue dateExpiry date
*.lusha.comSep 9, 2024, 00:00:00Oct 9, 2025, 23:59:59
upload.video.google.comAug 26, 2024, 07:12:45Nov 18, 2024, 07:12:44
chilipiper.comFeb 5, 2024, 00:00:00Mar 7, 2025, 23:59:59
lusha.comMar 29, 2024, 00:00:00Apr 27, 2025, 23:59:59
*.google-analytics.comAug 26, 2024, 06:33:47Nov 18, 2024, 06:33:46
ifconfig.meAug 17, 2024, 15:06:33Nov 15, 2024, 15:06:32
cookielaw.orgAug 13, 2024, 18:36:46Nov 11, 2024, 19:36:43
geolocation.onetrust.comAug 13, 2024, 18:27:06Nov 11, 2024, 19:27:02
ipify.orgSep 15, 2024, 06:18:44Dec 14, 2024, 06:18:43
*.g.doubleclick.netAug 26, 2024, 06:33:44Nov 18, 2024, 06:33:43