Site quality · Site security

HSTS preload

We set up HSTS and, when ready, addition to the browser preload list: the site is forced to open only over HTTPS, even on the first visit, without the possibility of a downgrade to http. To eliminate protocol-downgrade attacks and interception over an insecure connection. Honestly upfront: HSTS strengthens connection protection, but preload is a serious commitment that is hard to roll back quickly and requires the WHOLE site and all subdomains to work over HTTPS.

Price
$1,800
Duration
usually 2–4 business days (excluding the preload-inclusion timeline)

HSTS preload — overview

HSTS preload — price, timeline & scope

HSTS preload is a project: we set up the Strict-Transport-Security header with correct max-age, includeSubDomains and preload, check readiness (all subdomains on HTTPS, valid certificates, redirects), and when ready submit the domain to the browser preload list. Honestly about the commitment, this is key: addition to preload is a SERIOUS and hard-to-reverse step: once in the browsers' built-in list the domain will be FORCED to open only over HTTPS for all users, and you cannot quickly 'roll back' (removal from preload takes weeks/months and goes through browser updates). So a mandatory condition: the WHOLE site and ALL subdomains must stably work over HTTPS with valid certificates — otherwise you will block access to whatever is not on HTTPS. Honestly about the scope: HSTS protects against downgrade attacks and interception over an insecure connection, but it is about TRANSPORT — it does not protect against code vulnerabilities/XSS/injections (separate measures). Honestly about the prerequisite: correctly set up TLS (736) is needed — without it HSTS is premature. Honestly about the effect: connection-protection reinforcement, we do NOT guarantee sales growth by itself. Honestly about access: access to the server/config is needed. An important boundary: this is HSTS/preload, not SSL/TLS setup (736 — prerequisite) and not security headers in general (757 — adjacent). If you are not sure all subdomains are forever on HTTPS, submitting to preload is premature (you can limit to HSTS without preload). Picture this: instead of 'an http visit and downgrade are possible' — guaranteed HTTPS even on the first visit. The base price starts from 9,000 ₽ per project; it depends on the number of subdomains.

Problems we solve

  • An http visit and a downgrade attack to an insecure protocol are possible.
  • There is no forced HTTPS on the first visit.
  • HSTS is not set up or without includeSubDomains.
  • You want preload but are not sure subdomains are ready.

What's included in the HSTS preload service

  • Setting up the Strict-Transport-Security header (max-age/includeSubDomains)
  • Checking readiness (all subdomains on HTTPS, certificates, redirects)
  • Staged enabling (first without preload, then preload)
  • Submitting the domain to the preload list when ready
  • A warning about preload's irreversibility
  • Indicating boundaries (transport, not code protection)
  • Checking correctness
  • Handover and review with you

What you get

  • The site opens only over HTTPS, without a downgrade
  • Connection protection even on the first visit
  • A deliberate, safe addition to preload
  • Transport reinforcement (full security — separate)

How the work goes: steps

  • We check TLS and readiness of all subdomains; collect access
  • We set up HSTS, enable in stages, verify
  • When ready we submit to preload, review the consequences with you

Why PDV Expert

  • Fixed price and timeline — no surprises on the invoice.
  • Report and recommendations in plain language — clear without a technical background.
  • In touch at every step and answering questions about the result.

FAQ

  • Can preload be rolled back quickly if needed?

    No, that is its main trait: once in the browsers' built-in list the domain is forced to open only over HTTPS for everyone, and removal from preload takes weeks/months (via browser updates). So we submit to preload only when fully ready — otherwise you can block access to non-HTTPS parts.

  • Will HSTS protect the site from being hacked?

    No, it is about transport: HSTS eliminates downgrade and interception over an insecure connection, but does not protect against XSS, injections and code vulnerabilities — separate measures. And correct TLS (separate) is needed as a prerequisite.

  • Do we really need preload?

    Only if all subdomains are stably and forever on HTTPS. If in doubt — we limit to HSTS without preload (gives almost the same protection for returning users but is reversible). We honestly assess readiness and will not rush an irreversible step.

About the provider

The «HSTS preload» service is provided by PDV Expert — a team specialising in «Site quality». We work under contract and deliver a written report with recommendations.

Prepared by PDV Expert · updated