Step 1: Go to API Manager in Anypoint platform and select the API where HSTS header property needs to be added.
Step 2: Select policies from the left navigation panel and click on “Apply new policy”.
Step 3: Select “Header Injection” from the policy categories, select latest version of the policy available and then click “Configure Policy”.
Step 4: Add below key value pair in the “Outbound Header Map” and then click Apply.
Key: "Strict-Transport-Security
Value: “max-age=86400; includeSubDomains”
Please note that the value “max-age=86400; includeSubDomains” is just an example value, this can be set to any desired value based on the actual requirement.
Header injection policy details https://docs.mulesoft.com/api-manager/2.x/header-injection-policy
Broader article on HTTP Strict Transport Security
001120272

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.