| date | Thu, 19 Mar 2026 13:34:44 GMT |
| content-type | text/html; charset=utf-8 |
| content-length | 6401 |
| access-control-expose-headers | Request-Context |
| cache-control | private, max-age=1200 |
| content-encoding | gzip |
| etag | "c7725352-e0e2-4576-9d50-fe984694d724" |
| expires | Thu, 19 Mar 2026 13:54:44 GMT |
| last-modified | Thu, 19 Mar 2026 13:34:44 GMT |
| set-cookie | 72 Caracteres |
| vary | * |
| strict-transport-security | max-age=31536000; includeSubDomains; preload |
| content-security-policy | default-src 'self'; script-src 'self' *.googleapis.com *.gstatic.com www.google.com apis.google.com *.google-analytics.com connect.facebook.net ajax.aspnetcdn.com https://www.youtube.com platform.twitter.com https://syndication.twitter.com/ https://s.ytimg.com https://publish.twitter.com *.twimg.com platform.linkedin.com http://platform.stumbleupon.com/1/widgets.js https://*.googletagmanager.com cdnjs.cloudflare.com 'unsafe-inline' 'unsafe-eval' www.googletagmanager.com https://www.youtube.com/iframe_api https://dec.azureedge.net/ munchkin.marketo.net *.eloqua.com js.hs-scripts.com js.hs-analytics.net *.en25.com cdn.ampproject.org https://js.hubspot.com https://bat.bing.com https://static.hsappstatic.net https://files.atlas.kpmg.com https://cloud.scorm.com/api/v2/ https://cloud.scorm.com *.adform.net/ https://snap.licdn.com/li.lms-analytics/ https://js.hs-banner.com/ https://js.hsleadflows.net/ https://www.googletagmanager.com https://cdn.cookielaw.org https://forms.hsforms.com https://js.hsforms.net server.adform.net snap.licdn.com js.hsleadflows.net js.hs-banner.com https://cdn.insight.sitefinity.com https://player.vimeo.com/api/player.js forms.hubspot.com js.hscollectedforms.net; style-src 'self' *.googleapis.com *.gstatic.com kendo.cdn.telerik.com www.google.com platform.twitter.com/css/ *.twimg.com 'unsafe-inline' netdna.bootstrapcdn.com https://dec.azureedge.net https://cdn.insight.sitefinity.com; img-src 'self' *.gstatic.com *.googleapis.com platform.tumblr.com web.facebook.com www.facebook.com www.redditstatic.com www.linkedin.com i.ytimg.com https://syndication.twitter.com https://static.licdn.com/scds/common/u/images/apps/connect/sprites/sprite_connect_v14.png pbs.twimg.com platform.twitter.com/css/ *.twimg.com data: blob: https://*.googletagmanager.com *.google.com *.google.de *.google-analytics.com https://delicious.com https://dec.azureedge.net https://*.dec.sitefinity.com pbs.twimg.com platform.twitter.com/css/ data: blob: *.eloqua.com track.hubspot.com https://forms-na1.hsforms.com https://files.atlas.kpmg.com https://cdn.cookielaw.org https://forms.hsforms.com https://cdn.insight.sitefinity.com js.hsleadflows.net forms.hsforms.com; font-src 'self' fonts.gstatic.com kendo.cdn.telerik.com netdna.bootstrapcdn.com data: data: ; frame-src 'self' https://platform.twitter.com/ https://syndication.twitter.com/ https://www.youtube.com/ https://www.youtube-nocookie.com https://player.vimeo.com/ https://w.soundcloud.com/ apis.google.com accounts.google.com staticxx.facebook.com www.facebook.com web.facebook.com badge.stumbleupon.com https://kpmgatlas.eu.qualtrics.com/ https://atlas-experience.kpmg.de/ https://kpmg.bryter.io https://js.hsforms.net https://videostream.kpmg.de https://www.youtube.com https://pier2port.de https://app.powerbi.com/ https://www.google.com/recaptcha/ blob: https://login.atlas.kpmg.com https://surveys.kpmg.de https://meetings.hubspot.com https://linkedin.com https://www.linkedin.com https://matchmaker.atlas.kpmg.com https://www.figma.com/ https://tableau01.de.kworld.kpmg.com/ https://tableau.kpmg.de/ http://players.brightcove.net https://radar.trendmanager.com https://baumeister.swiss https://datastudio.google.com https://xm.apiomat.io https://fra1.qualtrics.com https://cloud.scorm.com https://accounts.google.com/ https://docs.google.com/ https://drive.google.com/ https://xapp.atlas.kpmg.com https://www.googletagmanager.com https://files.atlas.kpmg.com https://videostream.kpmg.de https://kpmg.bryter.io https://experience.kpmgatlas.de https://atlas-tutorial.sail2port.de https://forms.hsforms.com forms.hsforms.com; connect-src 'self' data: accounts.google.com *.google-analytics.com *.gstatic.com https://*.googletagmanager.com https://*.googleapis.com/ https://*.dec.sitefinity.com *.mktoresp.com https://login.atlas.kpmg.com https://kpmgi-privacy.my.onetrust.com https://matchmaker.atlas.kpmg.com https://cloud.scorm.com/api/v2/ https://fra1.qualtrics.com *.google-analytics.com/ https://forms.hubspot.com/ https://stats.g.doubleclick.net https://files.atlas.kpmg.com https://cdn.cookielaw.org https://forms.hsforms.com privacyportal-de.onetrust.com www.google-analytics.com https://*.insight.sitefinity.com forms.hubspot.com *.hsforms.com; media-src 'self' data: blob: data: blob: https://files.atlas.kpmg.com; child-src 'self' https://platform.twitter.com/ https://syndication.twitter.com/ https://www.youtube.com/ https://player.vimeo.com/ https://w.soundcloud.com/ apis.google.com accounts.google.com staticxx.facebook.com www.facebook.com web.facebook.com badge.stumbleupon.com blob: ; frame-ancestors 'self' https://www.figma.com/ https://www.bechtle.com https://kpmg.bryter.io |
| cross-origin-embedder-policy | unsafe-none |
| cross-origin-opener-policy | unsafe-none |
| cross-origin-resource-policy | cross-origin |
| permissions-policy | accelerometer=(self), ambient-light-sensor=(self), autoplay=(self), battery=(self), camera=(self), cross-origin-isolated=(self), display-capture=(self), document-domain=(self), encrypted-media=(self "https://players.brightcove.net"), execution-while-not-rendered=(self), execution-while-out-of-viewport=(self), fullscreen=(self "https://videostream.kpmg.de" "https://players.brightcove.net"), geolocation=(self), gyroscope=(self), keyboard-map=(self), magnetometer=(self), microphone=(self), midi=(self), navigation-override=(self), payment=(self), picture-in-picture=(self), publickey-credentials-get=(self), screen-wake-lock=(self), sync-xhr=(self), usb=(self), web-share=(self), xr-spatial-tracking=(self) |
| referrer-policy | no-referrer-when-downgrade |
| request-context | appId=cid-v1:c860bb92-ffa0-4be8-80a0-7f3abc004cee |
| x-xss-protection | 0; mode=block |
| x-frame-options | SAMEORIGIN |
| x-content-type-options | nosniff |
| statuscode | 200 |
| http_version | HTTP/2 |
(Deseable)