There are no X-Frame-Options in the HTTP header from Kiwi Syslog. It is thus vulnerable to clickjacking. You cannot configure UltiDev Web Server / Kiwi Syslog to add this HTTP header. Tried to edit web.config, but it does not recognize httpProtocol/customHeaders.