9dcdfc28af3dc6a4-DUB
keep-alive
gzip
text/html; charset=utf-8
Sun, 15 Mar 2026 19:39:35 GMT
cloudflare
__cf_bm=_nVAAc0fpa6iwIPx91SHDLC37Jf_PpAXJ5iJw1wTUPw-1773603575-1.0.1.1-XiGGvmKTBpuJZ1kzQA9JC_xgsZLvLwhlTY1YgiDzqrBnU1EGeNljsWdVUwpqtNj3WwxJs5GcBOK1HJkKl_3VpqrwcgFKPdSZfU2JwZKZIzM; path=/; expires=Sun, 15-Mar-26 20:09:35 GMT; domain=.chartersavingsbank.co.uk; HttpOnly; Secure; SameSite=None
max-age=63072000; includeSubDomains
Accept-Encoding
DYNAMIC
default-src 'self' packages.umbraco.org our.umbraco.org cdn-ukwest.onetrust.com googletagmanager.com privacyportal-uk.onetrust.com cookiepedia.co.uk geolocation.onetrust.com *.googletagmanager.com tagmanager.google.com google-analytics.com *.google-analytics.com cdn.cookielaw.org cookie-cdn.cookiepro.com *.clarity.ms c.bing.com dev.visualwebsiteoptimizer.com *.visualwebsiteoptimizer.com googleads.g.doubleclick.net www.google.co.uk *.google.co.uk widget.trustpilot.com *.trustpilot.com js-eu1.hs-scripts.com *.hs-scripts.com js-eu1.hs-analytics.net js-eu1.hs-banner.com js-eu1.hscollectedforms.net js-eu1.usemessages.com c.clarity.ms *.clarity.ms track-eu1.hubspot.com c.bing.com api-eu1.hubspot.com *.hubspot.com player.vimeo.com *.vimeo.com www.youtube.com *.youtube.com cdn.mouseflow.com *.mouseflow.com api.postcodes.io *.postcodes.io js.hsforms.net *.hsforms.net r3eu01.visualwebsiteoptimizer.com precisemortgages-25146468.hs-sites-eu1.com *.hs-sites-eu1.com *.visualwebsiteoptimizer.com app.vwo.com n.clarity.ms www.google.co.uk c.bing.com *.c.clarity.ms *.clarity.ms;script-src 'self' https://www.youtube-nocookie.com www.gstatic.com *.gstatic.com google.com recaptcha.net 145747460.fs1.hubspotusercontent-eu1.net static.hsappstatic.net rum-static.pingdom.net/prum.min.js platform.twitter.com/widgets.js maxcdn.bootstrapcdn.com connect.facebook.net *.issuu.com *.gstatic.com ajax.googleapis.com maps.googleapis.com unpkg.com ajax.aspnetcdn.com cdnjs.cloudflare.com cdn.jsdelivr.net cookiepedia.co.uk geolocation.onetrust.com *.onetrust.com cdn.cookielaw.org cookie-cdn.cookiepro.com tagmanager.google.com *.google.com google-analytics.com *.google-analytics.com ssl.google-analytics.com cdn.cookielaw.org cookie-cdn.cookiepro.com *.clarity.ms c.bing.com geolocation.onetrust.com privacyportal-uk.onetrust.com cdn-ukwest.onetrust.com googletagmanager.com *.googletagmanager.com www.googletagmanager.com dev.visualwebsiteoptimizer.com *.visualwebsiteoptimizer.com googleads.g.doubleclick.net www.google.co.uk *.google.co.uk widget.trustpilot.com *.trustpilot.com js-eu1.hs-scripts.com *.hs-scripts.com js-eu1.hs-analytics.net js-eu1.hs-banner.com js-eu1.hscollectedforms.net js-eu1.usemessages.com c.clarity.ms r3eu01.visualwebsiteoptimizer.com *.clarity.ms track-eu1.hubspot.com c.bing.com api-eu1.hubspot.com *.hubspot.com player.vimeo.com *.vimeo.com www.youtube.com *.youtube.com cdn.mouseflow.com precisemortgages-25146468.hs-sites-eu1.com *.hs-sites-eu1.com *.mouseflow.com api.postcodes.io *.postcodes.io js.hsforms.net *.hsforms.net perf-eu1.hsforms.com *.hsforms.com *.visualwebsiteoptimizer.com app.vwo.com www.google.co.uk c.bing.com *.c.clarity.ms *.clarity.ms 'unsafe-eval' 'unsafe-inline';style-src 'self' widget.trustpilot.com *.trustpilot.com fonts.googleapis.com cdn.jsdelivr.net cdnjs.cloudflare.com cdn.linearicons.com privacyportal-uk.onetrust.com cookiepedia.co.uk cdn-ukwest.onetrust.com geolocation.onetrust.com tagmanager.google.com fonts.googleapis.com *.onetrust.com cdn.cookielaw.org cookie-cdn.cookiepro.com privacyportal-uk.onetrust.com dev.visualwebsiteoptimizer.com *.visualwebsiteoptimizer.com googleads.g.doubleclick.net www.google.co.uk *.google.co.uk js-eu1.hs-analytics.net js-eu1.hs-banner.com js-eu1.hscollectedforms.net js-eu1.usemessages.com c.clarity.ms *.clarity.ms track-eu1.hubspot.com c.bing.com api-eu1.hubspot.com *.hubspot.com player.vimeo.com *.vimeo.com www.youtube.com *.youtube.com cdn.mouseflow.com *.mouseflow.com api.postcodes.io *.postcodes.io js.hsforms.net *.hsforms.net precisemortgages-25146468.hs-sites-eu1.com *.hs-sites-eu1.com r3eu01.visualwebsiteoptimizer.com *.visualwebsiteoptimizer.com app.vwo.com s3.amazonaws.com www.google.co.uk c.bing.com *.c.clarity.ms *.clarity.m 'unsafe-inline';connect-src *;font-src 'self' data: cdnjs.cloudflare.com fonts.gstatic.com cdn.linearicons.com privacyportal-uk.onetrust.com cookiepedia.co.uk cdn-ukwest.onetrust.com geolocation.onetrust.com *.onetrust.com privacyportal-uk.onetrust.com cdn.cookielaw.org cookie-cdn.cookiepro.com dev.visualwebsiteoptimizer.com *.visualwebsiteoptimizer.com googleads.g.doubleclick.net www.google.co.uk *.google.co.uk widget.trustpilot.com *.trustpilot.com js-eu1.hs-scripts.com *.hs-scripts.com js-eu1.hs-analytics.net js-eu1.hs-banner.com js-eu1.hscollectedforms.net js-eu1.usemessages.com c.clarity.ms *.clarity.ms track-eu1.hubspot.com c.bing.com api-eu1.hubspot.com *.hubspot.com player.vimeo.com *.vimeo.com www.youtube.com *.youtube.com cdn.mouseflow.com *.mouseflow.com api.postcodes.io r3eu01.visualwebsiteoptimizer.com precisemortgages-25146468.hs-sites-eu1.com *.hs-sites-eu1.com *.postcodes.io js.hsforms.net *.hsforms.net www.google.co.uk c.bing.com *.c.clarity.ms *.clarity.ms;img-src 'self' data: via.placeholder.com privacyportal-uk.onetrust.com cookiepedia.co.uk cdn-ukwest.onetrust.com *.issuu.com geolocation.onetrust.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.google.com ssl.gstatic.com www.gstatic.com google-analytics.com *.google-analytics.com *.onetrust.com cdn.cookielaw.org cookie-cdn.cookiepro.com privacyportal-uk.onetrust.com dev.visualwebsiteoptimizer.com *.visualwebsiteoptimizer.com googleads.g.doubleclick.net www.google.co.uk *.google.co.uk widget.trustpilot.com *.trustpilot.com js-eu1.hs-scripts.com *.hs-scripts.com js-eu1.hs-analytics.net js-eu1.hs-banner.com js-eu1.hscollectedforms.net js-eu1.usemessages.com c.clarity.ms *.clarity.ms track-eu1.hubspot.com c.bing.com api-eu1.hubspot.com *.hubspot.com player.vimeo.com *.vimeo.com www.youtube.com *.youtube.com cdn.mouseflow.com *.mouseflow.com api.postcodes.io r3eu01.visualwebsiteoptimizer.com *.postcodes.io js.hsforms.net *.hsforms.net precisemortgages-25146468.hs-sites-eu1.com *.hs-sites-eu1.com *.visualwebsiteoptimizer.com perf-eu1.hsforms.com *.hsforms.com chart.googleapis.com wingify-assets.s3.amazonaws.com app.vwo.com www.google.co.uk c.bing.com *.c.clarity.ms *.clarity.ms;media-src 'self' www.googletagmanager.com *.onetrust.com cdn.cookielaw.org cookie-cdn.cookiepro.com privacyportal-uk.onetrust.com googletagmanager.com *.googletagmanager.com dev.visualwebsiteoptimizer.com *.visualwebsiteoptimizer.com googleads.g.doubleclick.net widget.trustpilot.com *.trustpilot.com js-eu1.hs-scripts.com *.hs-scripts.com api-eu1.hubspot.com *.hubspot.com player.vimeo.com *.vimeo.com www.youtube.com *.youtube.com cdn.mouseflow.com *.mouseflow.com api.postcodes.io *.postcodes.io js.hsforms.net precisemortgages-25146468.hs-sites-eu1.com *.hs-sites-eu1.com *.hsforms.net www.google.co.uk c.bing.com *.c.clarity.ms *.clarity.ms;frame-src https://www.youtube-nocookie.com forms-eu1.hsforms.com google.com www.google.com *.issuu.com *.gstatic.com *.google.com www.googletagmanager.com *.onetrust.com cdn.cookielaw.org cookie-cdn.cookiepro.com privacyportal-uk.onetrust.com googletagmanager.com *.googletagmanager.com dev.visualwebsiteoptimizer.com *.visualwebsiteoptimizer.com googleads.g.doubleclick.net widget.trustpilot.com *.trustpilot.com js-eu1.hs-scripts.com *.hs-scripts.com api-eu1.hubspot.com *.hubspot.com player.vimeo.com *.vimeo.com www.youtube.com *.youtube.com cdn.mouseflow.com *.mouseflow.com api.postcodes.io *.postcodes.io js.hsforms.net *.hsforms.net app.vwo.com precisemortgages-25146468.hs-sites-eu1.com *.hs-sites-eu1.com *.visualwebsiteoptimizer.com www.google.co.uk c.bing.com *.c.clarity.ms *.clarity.ms;worker-src 'self' packages.umbraco.org our.umbraco.org cdn-ukwest.onetrust.com googletagmanager.com privacyportal-uk.onetrust.com cookiepedia.co.uk geolocation.onetrust.com *.googletagmanager.com tagmanager.google.com google-analytics.com *.google-analytics.com cdn.cookielaw.org cookie-cdn.cookiepro.com *.clarity.ms c.bing.com dev.visualwebsiteoptimizer.com *.visualwebsiteoptimizer.com googleads.g.doubleclick.net www.google.co.uk *.google.co.uk widget.trustpilot.com *.trustpilot.com js-eu1.hs-scripts.com *.hs-scripts.com js-eu1.hs-analytics.net js-eu1.hs-banner.com js-eu1.hscollectedforms.net js-eu1.usemessages.com c.clarity.ms *.clarity.ms track-eu1.hubspot.com c.bing.com api-eu1.hubspot.com *.hubspot.com player.vimeo.com *.vimeo.com www.youtube.com *.youtube.com cdn.mouseflow.com *.mouseflow.com api.postcodes.io *.postcodes.io js.hsforms.net r3eu01.visualwebsiteoptimizer.com precisemortgages-25146468.hs-sites-eu1.com *.hs-sites-eu1.com *.hsforms.net www.google.co.uk c.bing.com *.c.clarity.ms *.clarity.ms
accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), cross-origin-isolated=(), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), navigation-override=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=()
no-referrer
nosniff
SAMEORIGIN
ASP.NET
1; mode=block
|