diff --git a/static/features.html b/static/features.html
index 44633f19..f2a8adfc 100644
--- a/static/features.html
+++ b/static/features.html
@@ -210,7 +210,12 @@
Authenticated encryption for all of our services
Strong cipher configurations for all of our services (SSH, TLS, etc.) with
only modern AEAD ciphers providing forward secrecy
- Our web services use OCSP stapling with Must-Staple
+ Our web services use robust OCSP stapling with Must-Staple
+ Our web sites do not include any third party content and entirely forbid
+ it via strict Content Security Policy rules
+ Our web sites disable referrer headers to maximize privacy
+ Our web sites fully enable cross origin isolation and disable embedding in
+ other content
DNSSEC implemented for all of our domains
DNS Certification Authority Authorization (CAA) records for all of our
domains permitting only Let's Encrypt to issue certificates with fully