update site/.htaccess
diff --git a/site/.htaccess b/site/.htaccess
index de377bf..188ce4c 100644
--- a/site/.htaccess
+++ b/site/.htaccess
@@ -1 +1,4 @@
 ErrorDocument 404 /404.html
+<IfModule mod_headers.c>
+  Header set Content-Security-Policy "default-src 'self'; connect-src 'self' https://*.algolia.net https://*.algolianet.com https://*.algolia.io; script-src 'self' https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com;"
+</IfModule>