Security headers: 8/8
The only Estonian business software with all 8 HTTP security headers in place — a higher score than any Estonian bank we tested.
HTTP security headers are the first line of defense between a website and the user's browser — they tell the browser which scripts to run, where resources may load from, and whether the page may be framed. The more that are set correctly, the lower the XSS and data-leak risk.
Overall result — security headers (score /8)
Banks are shown anonymously (Estonian bank A–E). The score counts partial credit: full header = 1 point, partial = 0.5, missing = 0.
Two headers no Estonian bank uses at a strict value
Cross-Origin-Opener-Policy and Cross-Origin-Embedder-Policy isolate the browser window context and protect against Spectre-type attacks and cross-origin information leaks. AlfaERP uses them at strict values — the only one of all sites reviewed.
Honest context — security is layered
HTTP security headers are one layer. Banks have additional layers (WAF, 24/7 security operations) that this comparison does not measure. AlfaERP's strength comes from being business software that needs no third-party trackers — enabling a stricter CSP than banks. We combine security headers with eID authentication, TLS 1.3, AES-256 encryption and role-based access.
Data was collected via real HTTP scans of each site's public login page (March 2026, fully re-run May 2026). This comparison reflects the current state (July 2026); results are verifiable by anyone using public tools such as securityheaders.com. Security headers may change over time.
Back to security