Hello, Why is it required to have security headers alike HSTS, CSP and X-FRAME OPTIONS if the API is not browsable?