HTTP security headers are metadata sent by web servers to instruct browsers on how to handle content. Examples: - Content-Security-Policy (CSP): restricts where scripts can be loaded from (prevents XSS)