These APIs handle money, identity, keys and process isolation, so nearly all require a secure context (The Web Platform APIs) and a user gesture for sensitive calls. Security covers the HTML and header side (CSP, Permissions-Policy, sandbox, Trusted Types) and Sanitization and XSS Defence sanitization; this section adds the JavaScript and reporting side.