Index: README.md
===================================================================
--- README.md	(revision 81bb9c588cda25bc4e200a46e001bf780d57c10f)
+++ README.md	(revision 897c33b994240165ec071824cfd3be00f63ffa3e)
@@ -162,4 +162,5 @@
 | `KLONKT_DEFAULT_LANG` | — | Default language for visitors (`en`/`nl`/`de`) |
 | `KLONKT_AUDIO` | — | `off` = lite mode (no audio/ffmpeg) |
+| `HSTS_STRICT` | — | `1` = stricter HTTPS header (`includeSubDomains` + `preload`). Only set this if Klonkt owns the **whole** domain and all its subdomains are HTTPS — it forces every subdomain to HTTPS and can bake your domain into browsers near-permanently. Leave unset otherwise; the default is already safe. |
 
 ## Stack
