Technical audit · 2026-05-13

europol.europa.eu

EU Agency for Law Enforcement Cooperation

The EU's law enforcement cooperation agency — 40 requests, 2 domains, both europa.eu. Zero external trackers, zero cookies. CSP, HSTS, Permissions-Policy, X-Frame-Options — a full set of security headers.

Timeline of the leak

+1095 ms · load
webtools.europa.eu/load.js — the EU's shared web-tools infrastructure. A europa.eu subdomain.
+2001–2273 ms
webtools.europa.eu — CSS and JS from the EU's shared infrastructure. Stays within europa.eu.

Context

Europol is the EU’s law enforcement cooperation agency, headquartered in The Hague. It coordinates efforts against organized crime, terrorism, and cybercrime. Governed by Regulation (EU) 2018/1725 and the specific Europol Regulation (EU) 2016/794. Supervised by the EDPS. HAR: 40 requests, 2 domains.

What the HAR shows

Two domains — www.europol.europa.eu and webtools.europa.eu. webtools.europa.eu is the European Commission’s centralized infrastructure for shared web tools, used by numerous EU institutions. Both domains are europa.eu subdomains. Not a single external request, not a single Set-Cookie response.

Security headers — a full set

Europol implements all the key HTTP security headers:

Content-Security-Policy — restricts script loading to self, europa.eu, and webtools.europa.eu. No external CDNs, no advertising networks.

Permissions-Policy — explicitly disables interest-cohort (FLoC/Topics API), camera, geolocation, microphone, gyroscope, magnetometer, the payment API, and publickey-credentials.

Strict-Transport-Security — max-age=16000000, with includeSubDomains and preload.

X-Content-Type-Options: nosniff and X-Frame-Options: SAMEORIGIN — standard protection against clickjacking and MIME sniffing.

This is not a random collection — it is a deliberate security policy. Europol explicitly prohibits browsers from sending data to advertising networks, via both CSP and Permissions-Policy.

webtools.europa.eu

The only external dependency is webtools.europa.eu, a centralized European Commission service. It loads shared CSS themes and JavaScript utilities for EU institution websites. This is not a third-party tracker — it is the Union’s internal infrastructure. Data stays within europa.eu.

Conclusion

An agency dealing in cybercrime understands what proper web infrastructure looks like. Zero external trackers, zero cookies, a full set of security headers including a Permissions-Policy blocking FLoC. Two domains — both europa.eu. A benchmark result.

Evidence
Original (audit)
HAR file: eu/europol-europa-eu-2026-05-13.har
SHA-256: e553f6e8204713baf425706dfee227cd6f601361197c5009fce4b454a72a3101
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.