The 3 pages the PEN testers highlighted were
- ufsmain - we've checked and they are present so we are checking with the PEN testers.
uploader - this pages uses "cache-control private". I'm looking at what the difference is.
ufsajax - no cache control nor pragma headers. We can of course turn ajax off for specific forms (not that we want to).
Thanks