HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
Date: Tue, 24 Jun 2025 10:01:00 GMT
X-V-Cache: HIT 1 web-03.prod.us-east-2.fast.host
Access-Control-Allow-Origin: https://www.sigfig.com
Vary: Accept-Encoding
Expires: Tue, 24 Jun 2025 10:01:21 GMT
Cache-Control: max-age=30
X-Static-Hostname: app-private-php-03.prod.us-east-2.fast.host
Access-Control-Allow-Credentials: true
Content-Security-Policy: child-src 'self' https://*.cloudfront.net https://*.docusign.com https://*.docusign.net https://*.plaid.com https://*.sigfig.com https://cdnjs.cloudflare.com https://go.oncehub.com https://secure.scheduleonce.com https://www.snapengage.com https://*.cambridgesavings.com https://*.csbwebonline.com; connect-src 'self' blob: https://*.auth0.com https://*.doubleclick.net https://*.getsentry.com https://*.hotjar.com https://*.optimizely.com https://*.posthog.com https://*.posthog.financial https://*.sentry.io https://*.sigfig.com https://*.wellsfargo.com https://*.zdassets.com https://*.zendesk.com https://53gp2a6uuff25jajc3tsxjw4zi.appsync-api.us-east-2.amazonaws.com https://5izjmltxqzeohk4bexfrxsvruu.appsync-api.us-east-1.amazonaws.com https://6t6iiakfafadtab7nwkh6hf67y.appsync-api.us-east-1.amazonaws.com https://7nap3ezfpjcdbm2f62cgwvao2i.appsync-api.us-east-1.amazonaws.com https://l7zgowilqfb4hm7qr77uynpi4e.appsync-api.us-east-1.amazonaws.com https://nrxa3ixv65gcbbaohwec47wd7q.appsync-api.us-east-1.amazonaws.com https://ntsnhipklzfgvbbx644xangdry.appsync-api.us-east-1.amazonaws.com https://plcynlxvu5ejbpfb6ev7xjdw7u.appsync-api.us-east-1.amazonaws.com https://qzshmvqprjgdfmjlhdadm654n4.appsync-api.us-east-1.amazonaws.com https://s2nfp4bis5hsni2trkmqahm4ni.appsync-api.us-west-2.amazonaws.com https://sc4uu4gugjgx3hhageta6wb2y4.appsync-api.us-east-1.amazonaws.com https://sphte6uhurgddekyagqqjgtip4.appsync-api.us-east-2.amazonaws.com https://tgjyrcfo7jb3zgcn6hxi5j3du4.appsync-api.us-west-2.amazonaws.com https://zdb3tzrntjbzndbfucl5g74jnm.appsync-api.us-east-1.amazonaws.com https://zoq27apzlbfmdogfumwyxzsewa.appsync-api.us-east-1.amazonaws.com https://assets.contentstack.io https://bam.nr-data.net https://bam-cell.nr-data.net https://cdn.contentstack.io https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://graphql.contentstack.com https://images.contentstack.io https://heapanalytics.com https://maps.googleapis.com https://sentry.io https://sigfigprod.112.2o7.net https://www.snapengage.com wss://*.hotjar.com https://*.cambridgesavings.com https://*.csbwebonline.com; default-src 'self' https://*.sigfig.com https://*.cambridgesavings.com https://*.csbwebonline.com; frame-src 'self' https://*.auth0.com https://*.cloudfront.net https://*.docusign.com https://*.docusign.net https://*.hotjar.com/ https://*.sigfig.com https://*.plaid.com https://go.oncehub.com https://secure.scheduleonce.com https://www.snapengage.com https://*.cambridgesavings.com https://*.csbwebonline.com; font-src 'self' data: https://*.cloudfront.net https://*.sigfig.com https://fonts.gstatic.com https://heapanalytics.com https://*.cambridgesavings.com https://*.csbwebonline.com; img-src 'self' data: http://*.ggpht.com http://*.googleusercontent.com http://*.gstatic.com https://*.cloudfront.net https://*.doubleclick.net https://*.ggpht.com https://*.google-analytics.com https://*.googleapis.com https://*.googleusercontent.com https://*.gstatic.com https://*.sigfig.com https://cdn.optimizely.com https://csi.gstatic.com https://heapanalytics.com https://www.snapengage.com https://images.contentstack.io https://*.cambridgesavings.com https://*.csbwebonline.com; media-src 'self' https://*.cloudfront.net https://assets.contentstack.io https://*.sigfig.com https://*.cambridgesavings.com https://*.csbwebonline.com; object-src 'self' https://www.snapengage.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.adobedtm.com https://*.cloudfront.net https://*.doubleclick.net https://*.google-analytics.com https://*.googleapis.com https://*.hotjar.com/ https://*.newrelic.com https://*.optimizely.com https://*.plaid.com https://*.posthog.com https://*.posthog.financial https://*.sigfig.com https://*.zdassets.com https://*.zendesk.com https://apis.google.com https://bam.nr-data.net https://bam-cell.nr-data.net https://cdn.heapanalytics.com https://cdnjs.cloudflare.com https://heapanalytics.com https://nexus.ensighten.com https://optimizely.s3.amazonaws.com https://sigfigprod.112.2o7.net https://www.snapengage.com https://*.cambridgesavings.com https://*.csbwebonline.com; style-src 'self' 'unsafe-inline' https://*.cloudfront.net https://*.googleapis.com https://*.sigfig.com https://heapanalytics.com https://*.cambridgesavings.com https://*.csbwebonline.com;
X-Content-Security-Policy: child-src 'self' https://*.cloudfront.net https://*.docusign.com https://*.docusign.net https://*.plaid.com https://*.sigfig.com https://cdnjs.cloudflare.com https://go.oncehub.com https://secure.scheduleonce.com https://www.snapengage.com https://*.cambridgesavings.com https://*.csbwebonline.com; connect-src 'self' blob: https://*.auth0.com https://*.doubleclick.net https://*.getsentry.com https://*.hotjar.com https://*.optimizely.com https://*.posthog.com https://*.posthog.financial https://*.sentry.io https://*.sigfig.com https://*.wellsfargo.com https://*.zdassets.com https://*.zendesk.com https://53gp2a6uuff25jajc3tsxjw4zi.appsync-api.us-east-2.amazonaws.com https://5izjmltxqzeohk4bexfrxsvruu.appsync-api.us-east-1.amazonaws.com https://6t6iiakfafadtab7nwkh6hf67y.appsync-api.us-east-1.amazonaws.com https://7nap3ezfpjcdbm2f62cgwvao2i.appsync-api.us-east-1.amazonaws.com https://l7zgowilqfb4hm7qr77uynpi4e.appsync-api.us-east-1.amazonaws.com https://nrxa3ixv65gcbbaohwec47wd7q.appsync-api.us-east-1.amazonaws.com https://ntsnhipklzfgvbbx644xangdry.appsync-api.us-east-1.amazonaws.com https://plcynlxvu5ejbpfb6ev7xjdw7u.appsync-api.us-east-1.amazonaws.com https://qzshmvqprjgdfmjlhdadm654n4.appsync-api.us-east-1.amazonaws.com https://s2nfp4bis5hsni2trkmqahm4ni.appsync-api.us-west-2.amazonaws.com https://sc4uu4gugjgx3hhageta6wb2y4.appsync-api.us-east-1.amazonaws.com https://sphte6uhurgddekyagqqjgtip4.appsync-api.us-east-2.amazonaws.com https://tgjyrcfo7jb3zgcn6hxi5j3du4.appsync-api.us-west-2.amazonaws.com https://zdb3tzrntjbzndbfucl5g74jnm.appsync-api.us-east-1.amazonaws.com https://zoq27apzlbfmdogfumwyxzsewa.appsync-api.us-east-1.amazonaws.com https://assets.contentstack.io https://bam.nr-data.net https://bam-cell.nr-data.net https://cdn.contentstack.io https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://graphql.contentstack.com https://images.contentstack.io https://heapanalytics.com https://maps.googleapis.com https://sentry.io https://sigfigprod.112.2o7.net https://www.snapengage.com wss://*.hotjar.com https://*.cambridgesavings.com https://*.csbwebonline.com; default-src 'self' https://*.sigfig.com https://*.cambridgesavings.com https://*.csbwebonline.com; frame-src 'self' https://*.auth0.com https://*.cloudfront.net https://*.docusign.com https://*.docusign.net https://*.hotjar.com/ https://*.sigfig.com https://*.plaid.com https://go.oncehub.com https://secure.scheduleonce.com https://www.snapengage.com https://*.cambridgesavings.com https://*.csbwebonline.com; font-src 'self' data: https://*.cloudfront.net https://*.sigfig.com https://fonts.gstatic.com https://heapanalytics.com https://*.cambridgesavings.com https://*.csbwebonline.com; img-src 'self' data: http://*.ggpht.com http://*.googleusercontent.com http://*.gstatic.com https://*.cloudfront.net https://*.doubleclick.net https://*.ggpht.com https://*.google-analytics.com https://*.googleapis.com https://*.googleusercontent.com https://*.gstatic.com https://*.sigfig.com https://cdn.optimizely.com https://csi.gstatic.com https://heapanalytics.com https://www.snapengage.com https://images.contentstack.io https://*.cambridgesavings.com https://*.csbwebonline.com; media-src 'self' https://*.cloudfront.net https://assets.contentstack.io https://*.sigfig.com https://*.cambridgesavings.com https://*.csbwebonline.com; object-src 'self' https://www.snapengage.com; script-src 'self' 'unsafe-eva