I just checked the logs for a simple HTTP request to their top level site and it defined a content security policy for 92 separate domains.
Including a lot of fun ones with names like "sandbox.company.egg" and "debugging.company.egg" and "embedded.demo.company.egg" and "debug-preview.company.egg"
all of which is pretty questionable when you already defined a *.company.egg policy!