We enabled the Strict-Transport-Security header by default for any HTTPS enabled sites.