Index: README.md
===================================================================
--- README.md	(revision 196e1beeaf1cadfc95f285a77f5d56a75b1a91c0)
+++ README.md	(revision 1ff004363790da4fd47e4c572ebaa3bb8663d228)
@@ -162,4 +162,5 @@
 | `KLONKT_DEFAULT_LANG` | — | Default language for visitors (`en`/`nl`/`de`) |
 | `KLONKT_AUDIO` | — | `off` = lite mode (no audio/ffmpeg) |
+| `HSTS_STRICT` | — | `1` = stricter HTTPS header (`includeSubDomains` + `preload`). Only set this if Klonkt owns the **whole** domain and all its subdomains are HTTPS — it forces every subdomain to HTTPS and can bake your domain into browsers near-permanently. Leave unset otherwise; the default is already safe. |
 
 ## Stack
