Force SSL/TLS in your app.
Strict-Transport-Security
gem install rack-ssl
require 'rack/ssl' use Rack::SSL