AkamaiGHost
tcp/80
AmazonS3
tcp/443
Open service 92.123.104.64:443 · sysfos.northerntrust.com
2026-01-23 15:14
HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Tue, 13 Jan 2026 15:53:53 GMT
x-amz-version-id: 1XEfeO8SKn_NKe_sJFFA8H8NAXww0Wey
ETag: W/"a22dd2cbf5e51ee811b5afb2ffd264af"
Server: AmazonS3
Cache-Control: no-store
Expires: 0
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-FOS-URI: /index.html
X-Amz-Cf-Pop: JFK50-P3
X-Amz-Cf-Id: 46rrwbQLWo3WFmEjm6Z9_SOyeUUwnTXNPhJAHDJeAiSa1jpSKsokng==
Date: Fri, 23 Jan 2026 15:14:10 GMT
Content-Length: 6188
Connection: close
Set-Cookie: NTRS_VISIT_ID=a9a7291730ea3600429073699503000021070000; path=/; domain=.ntrs.com
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Page title: Front Office Solutions
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<meta http-equiv="X-UA-Compatible" content="ie=edge">
<title>Front Office Solutions</title>
<!--
Remove this if you only support browsers that support async/await.
This is needed by babel to share largeish helper code for compiling async/await in older
browsers. More information at https://github.com/single-spa/create-single-spa/issues/112
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/regenerator-runtime@0.14.1/runtime.min.js"></script> -->
<!--
This CSP allows any SSL-enabled host and for arbitrary eval(), but you should limit these directives further to increase your app's security.
Learn more about CSP policies at https://content-security-policy.com/#directive
-->
<meta
http-equiv="Content-Security-Policy"
content="
default-src 'self' https:;
script-src 'unsafe-inline' 'unsafe-eval' https:;
worker-src 'self' blob: https:;
connect-src https: wss://*.northerntrust.com wss://*.amzext.ntrs.com;
style-src 'unsafe-inline' https:;
object-src 'none';
font-src 'self' https: data:;
img-src 'self' https://*.northerntrust.com https://www.google-analytics.com https://www.googletagmanager.com data:;
frame-src 'self' https: com-okta-authenticator: about: data: blob:;
"
>
<!-- If you wish to turn off import-map-overrides for specific environments (prod), uncomment the line below -->
<!-- More info at https://github.com/joeldenning/import-map-overrides/blob/master/docs/configuration.md#domain-list -->
<!-- <meta name="import-map-overrides-domains" content="denylist:prod.example.com" /> -->
<!-- Shared dependencies go into this import map. Your shared dependencies must be of one of the following formats:
1. System.register (preferred when possible) - https://github.com/systemjs/systemjs/blob/master/docs/system-register.md
2. UMD - https://github.com/umdjs/umd
3. Global variable
More information about shared dependencies can be found at https://single-spa.js.org/docs/recommended-setup#sharing-with-import-maps.
-->
<link rel="preload" href="https://cdn.jsdelivr.net/npm/single-spa@6.0.3/lib/es2015/system/single-spa.min.js" as="script" crossorigin>
<link rel="preload" href="/apps/v2/fos-nav-bar/images/logo-fos-main.svg" as="image">
<!-- Add your organization's prod import map URL to this script's src -->
<!-- <script type="systemjs-importmap" src="/importmap.json"></script> -->
<meta name="importmap-type" content="systemjs-importmap" />
<script type="systemjs-importmap" src="/importmap.json"></script>
<!--
If you need to support Angular applications, uncomment the script tag below to ensure only one instance of ZoneJS is loaded
Learn more about why at https://single-spa.js.org/docs/ecosystem-angular/#zonejs
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/zone.js@0.11.3/dist/zone.min.js"></script> -->
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/system.min.js"></script>
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/extras/amd.min.js"></script>
<style>
body, html {
background-color: white;
}
single-spa-router {
height: 100vh;
display: flex;
flex-direction: column;
}
single-spa-router > nav > div:not(:empty) {
height: 48px;
}
single-spa-router > nav > div:empty {
display: none;
}
.root-error-page {
height: 100vh;
width: 100vw;
position: relative;
color: #4a4d4f;
display: flex;
align-items: center;
justify-content: center;
}
.root-error-container {
display: flex;
flex-direction: column;
align-items: center;
justify-content: center;
text-align: center;
transform: translateY(-50%);
}
.root-error-summary {
font-size: 1.8rem;
line-height: 2.
Open service 2.16.204.154:80 · sysfos.northerntrust.com
2026-01-21 17:51
HTTP/1.1 301 Moved Permanently Server: AkamaiGHost Content-Length: 0 Location: https://sysfos.northerntrust.com/ Date: Wed, 21 Jan 2026 17:52:22 GMT Connection: close Set-Cookie: NTRS_VISIT_ID=9a1d1002f04b1100561271693d010000b6030000; path=/; domain=.ntrs.com
Open service 2.16.204.147:443 · sysfos.northerntrust.com
2026-01-21 17:51
HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Tue, 13 Jan 2026 15:53:53 GMT
x-amz-version-id: 1XEfeO8SKn_NKe_sJFFA8H8NAXww0Wey
ETag: W/"a22dd2cbf5e51ee811b5afb2ffd264af"
Server: AmazonS3
Cache-Control: no-store
Expires: 0
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-FOS-URI: /index.html
X-Amz-Cf-Pop: JFK50-P3
X-Amz-Cf-Id: 79A7YOQ4PCHLqK1lN_7tnL1ocWoyrGjkLKO4fPns6SEWWRdB6UA5yA==
Date: Wed, 21 Jan 2026 17:52:00 GMT
Content-Length: 6188
Connection: close
Set-Cookie: NTRS_VISIT_ID=9a1d1002f04b110040127169250200001b020000; path=/; domain=.ntrs.com
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Page title: Front Office Solutions
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<meta http-equiv="X-UA-Compatible" content="ie=edge">
<title>Front Office Solutions</title>
<!--
Remove this if you only support browsers that support async/await.
This is needed by babel to share largeish helper code for compiling async/await in older
browsers. More information at https://github.com/single-spa/create-single-spa/issues/112
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/regenerator-runtime@0.14.1/runtime.min.js"></script> -->
<!--
This CSP allows any SSL-enabled host and for arbitrary eval(), but you should limit these directives further to increase your app's security.
Learn more about CSP policies at https://content-security-policy.com/#directive
-->
<meta
http-equiv="Content-Security-Policy"
content="
default-src 'self' https:;
script-src 'unsafe-inline' 'unsafe-eval' https:;
worker-src 'self' blob: https:;
connect-src https: wss://*.northerntrust.com wss://*.amzext.ntrs.com;
style-src 'unsafe-inline' https:;
object-src 'none';
font-src 'self' https: data:;
img-src 'self' https://*.northerntrust.com https://www.google-analytics.com https://www.googletagmanager.com data:;
frame-src 'self' https: com-okta-authenticator: about: data: blob:;
"
>
<!-- If you wish to turn off import-map-overrides for specific environments (prod), uncomment the line below -->
<!-- More info at https://github.com/joeldenning/import-map-overrides/blob/master/docs/configuration.md#domain-list -->
<!-- <meta name="import-map-overrides-domains" content="denylist:prod.example.com" /> -->
<!-- Shared dependencies go into this import map. Your shared dependencies must be of one of the following formats:
1. System.register (preferred when possible) - https://github.com/systemjs/systemjs/blob/master/docs/system-register.md
2. UMD - https://github.com/umdjs/umd
3. Global variable
More information about shared dependencies can be found at https://single-spa.js.org/docs/recommended-setup#sharing-with-import-maps.
-->
<link rel="preload" href="https://cdn.jsdelivr.net/npm/single-spa@6.0.3/lib/es2015/system/single-spa.min.js" as="script" crossorigin>
<link rel="preload" href="/apps/v2/fos-nav-bar/images/logo-fos-main.svg" as="image">
<!-- Add your organization's prod import map URL to this script's src -->
<!-- <script type="systemjs-importmap" src="/importmap.json"></script> -->
<meta name="importmap-type" content="systemjs-importmap" />
<script type="systemjs-importmap" src="/importmap.json"></script>
<!--
If you need to support Angular applications, uncomment the script tag below to ensure only one instance of ZoneJS is loaded
Learn more about why at https://single-spa.js.org/docs/ecosystem-angular/#zonejs
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/zone.js@0.11.3/dist/zone.min.js"></script> -->
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/system.min.js"></script>
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/extras/amd.min.js"></script>
<style>
body, html {
background-color: white;
}
single-spa-router {
height: 100vh;
display: flex;
flex-direction: column;
}
single-spa-router > nav > div:not(:empty) {
height: 48px;
}
single-spa-router > nav > div:empty {
display: none;
}
.root-error-page {
height: 100vh;
width: 100vw;
position: relative;
color: #4a4d4f;
display: flex;
align-items: center;
justify-content: center;
}
.root-error-container {
display: flex;
flex-direction: column;
align-items: center;
justify-content: center;
text-align: center;
transform: translateY(-50%);
}
.root-error-summary {
font-size: 1.8rem;
line-height: 2.
Open service 2.16.204.154:443 · sysfos.northerntrust.com
2026-01-21 17:51
HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Tue, 13 Jan 2026 15:53:53 GMT
x-amz-version-id: 1XEfeO8SKn_NKe_sJFFA8H8NAXww0Wey
ETag: W/"a22dd2cbf5e51ee811b5afb2ffd264af"
Server: AmazonS3
Cache-Control: no-store
Expires: 0
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-FOS-URI: /index.html
X-Amz-Cf-Pop: JFK50-P3
X-Amz-Cf-Id: lB60LyMQeNvFpwfcVC8_5OAJObZnn-hUHrVHEX0jK-Q9FoWKjNmyUg==
Date: Wed, 21 Jan 2026 17:52:00 GMT
Content-Length: 6188
Connection: close
Set-Cookie: NTRS_VISIT_ID=931d1002eeed2a00401271691402000003070000; path=/; domain=.ntrs.com
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Page title: Front Office Solutions
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<meta http-equiv="X-UA-Compatible" content="ie=edge">
<title>Front Office Solutions</title>
<!--
Remove this if you only support browsers that support async/await.
This is needed by babel to share largeish helper code for compiling async/await in older
browsers. More information at https://github.com/single-spa/create-single-spa/issues/112
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/regenerator-runtime@0.14.1/runtime.min.js"></script> -->
<!--
This CSP allows any SSL-enabled host and for arbitrary eval(), but you should limit these directives further to increase your app's security.
Learn more about CSP policies at https://content-security-policy.com/#directive
-->
<meta
http-equiv="Content-Security-Policy"
content="
default-src 'self' https:;
script-src 'unsafe-inline' 'unsafe-eval' https:;
worker-src 'self' blob: https:;
connect-src https: wss://*.northerntrust.com wss://*.amzext.ntrs.com;
style-src 'unsafe-inline' https:;
object-src 'none';
font-src 'self' https: data:;
img-src 'self' https://*.northerntrust.com https://www.google-analytics.com https://www.googletagmanager.com data:;
frame-src 'self' https: com-okta-authenticator: about: data: blob:;
"
>
<!-- If you wish to turn off import-map-overrides for specific environments (prod), uncomment the line below -->
<!-- More info at https://github.com/joeldenning/import-map-overrides/blob/master/docs/configuration.md#domain-list -->
<!-- <meta name="import-map-overrides-domains" content="denylist:prod.example.com" /> -->
<!-- Shared dependencies go into this import map. Your shared dependencies must be of one of the following formats:
1. System.register (preferred when possible) - https://github.com/systemjs/systemjs/blob/master/docs/system-register.md
2. UMD - https://github.com/umdjs/umd
3. Global variable
More information about shared dependencies can be found at https://single-spa.js.org/docs/recommended-setup#sharing-with-import-maps.
-->
<link rel="preload" href="https://cdn.jsdelivr.net/npm/single-spa@6.0.3/lib/es2015/system/single-spa.min.js" as="script" crossorigin>
<link rel="preload" href="/apps/v2/fos-nav-bar/images/logo-fos-main.svg" as="image">
<!-- Add your organization's prod import map URL to this script's src -->
<!-- <script type="systemjs-importmap" src="/importmap.json"></script> -->
<meta name="importmap-type" content="systemjs-importmap" />
<script type="systemjs-importmap" src="/importmap.json"></script>
<!--
If you need to support Angular applications, uncomment the script tag below to ensure only one instance of ZoneJS is loaded
Learn more about why at https://single-spa.js.org/docs/ecosystem-angular/#zonejs
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/zone.js@0.11.3/dist/zone.min.js"></script> -->
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/system.min.js"></script>
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/extras/amd.min.js"></script>
<style>
body, html {
background-color: white;
}
single-spa-router {
height: 100vh;
display: flex;
flex-direction: column;
}
single-spa-router > nav > div:not(:empty) {
height: 48px;
}
single-spa-router > nav > div:empty {
display: none;
}
.root-error-page {
height: 100vh;
width: 100vw;
position: relative;
color: #4a4d4f;
display: flex;
align-items: center;
justify-content: center;
}
.root-error-container {
display: flex;
flex-direction: column;
align-items: center;
justify-content: center;
text-align: center;
transform: translateY(-50%);
}
.root-error-summary {
font-size: 1.8rem;
line-height: 2.
Open service 2.16.204.147:80 · sysfos.northerntrust.com
2026-01-21 17:51
HTTP/1.1 301 Moved Permanently Server: AkamaiGHost Content-Length: 0 Location: https://sysfos.northerntrust.com/ Date: Wed, 21 Jan 2026 17:52:21 GMT Connection: close Set-Cookie: NTRS_VISIT_ID=931d1002eeed2a0055127169d300000066080000; path=/; domain=.ntrs.com
Open service 2001:41a8:44:4::4f8c:5f48:80 · sysfos.northerntrust.com
2026-01-21 17:51
HTTP/1.1 301 Moved Permanently Server: AkamaiGHost Content-Length: 0 Location: https://sysfos.northerntrust.com/ Date: Wed, 21 Jan 2026 17:52:23 GMT Connection: close Set-Cookie: NTRS_VISIT_ID=445f8c4fd38e2b005712716901000000d30c0000; path=/; domain=.ntrs.com
Open service 2001:41a8:44:4::4f8c:5f81:443 · sysfos.northerntrust.com
2026-01-21 17:51
HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Tue, 13 Jan 2026 15:53:53 GMT
x-amz-version-id: 1XEfeO8SKn_NKe_sJFFA8H8NAXww0Wey
ETag: W/"a22dd2cbf5e51ee811b5afb2ffd264af"
Server: AmazonS3
Cache-Control: no-store
Expires: 0
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-FOS-URI: /index.html
X-Amz-Cf-Pop: JFK50-P3
X-Amz-Cf-Id: S39xkvrTRSxX9X1WsCu6dBLo5_pm8mZ8yv1-FGeOnCvRnrCVyFFe9A==
Date: Wed, 21 Jan 2026 17:52:00 GMT
Content-Length: 6188
Connection: close
Set-Cookie: NTRS_VISIT_ID=445f8c4fd38e2b0040127169cf010000aa0c0000; path=/; domain=.ntrs.com
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Page title: Front Office Solutions
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<meta http-equiv="X-UA-Compatible" content="ie=edge">
<title>Front Office Solutions</title>
<!--
Remove this if you only support browsers that support async/await.
This is needed by babel to share largeish helper code for compiling async/await in older
browsers. More information at https://github.com/single-spa/create-single-spa/issues/112
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/regenerator-runtime@0.14.1/runtime.min.js"></script> -->
<!--
This CSP allows any SSL-enabled host and for arbitrary eval(), but you should limit these directives further to increase your app's security.
Learn more about CSP policies at https://content-security-policy.com/#directive
-->
<meta
http-equiv="Content-Security-Policy"
content="
default-src 'self' https:;
script-src 'unsafe-inline' 'unsafe-eval' https:;
worker-src 'self' blob: https:;
connect-src https: wss://*.northerntrust.com wss://*.amzext.ntrs.com;
style-src 'unsafe-inline' https:;
object-src 'none';
font-src 'self' https: data:;
img-src 'self' https://*.northerntrust.com https://www.google-analytics.com https://www.googletagmanager.com data:;
frame-src 'self' https: com-okta-authenticator: about: data: blob:;
"
>
<!-- If you wish to turn off import-map-overrides for specific environments (prod), uncomment the line below -->
<!-- More info at https://github.com/joeldenning/import-map-overrides/blob/master/docs/configuration.md#domain-list -->
<!-- <meta name="import-map-overrides-domains" content="denylist:prod.example.com" /> -->
<!-- Shared dependencies go into this import map. Your shared dependencies must be of one of the following formats:
1. System.register (preferred when possible) - https://github.com/systemjs/systemjs/blob/master/docs/system-register.md
2. UMD - https://github.com/umdjs/umd
3. Global variable
More information about shared dependencies can be found at https://single-spa.js.org/docs/recommended-setup#sharing-with-import-maps.
-->
<link rel="preload" href="https://cdn.jsdelivr.net/npm/single-spa@6.0.3/lib/es2015/system/single-spa.min.js" as="script" crossorigin>
<link rel="preload" href="/apps/v2/fos-nav-bar/images/logo-fos-main.svg" as="image">
<!-- Add your organization's prod import map URL to this script's src -->
<!-- <script type="systemjs-importmap" src="/importmap.json"></script> -->
<meta name="importmap-type" content="systemjs-importmap" />
<script type="systemjs-importmap" src="/importmap.json"></script>
<!--
If you need to support Angular applications, uncomment the script tag below to ensure only one instance of ZoneJS is loaded
Learn more about why at https://single-spa.js.org/docs/ecosystem-angular/#zonejs
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/zone.js@0.11.3/dist/zone.min.js"></script> -->
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/system.min.js"></script>
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/extras/amd.min.js"></script>
<style>
body, html {
background-color: white;
}
single-spa-router {
height: 100vh;
display: flex;
flex-direction: column;
}
single-spa-router > nav > div:not(:empty) {
height: 48px;
}
single-spa-router > nav > div:empty {
display: none;
}
.root-error-page {
height: 100vh;
width: 100vw;
position: relative;
color: #4a4d4f;
display: flex;
align-items: center;
justify-content: center;
}
.root-error-container {
display: flex;
flex-direction: column;
align-items: center;
justify-content: center;
text-align: center;
transform: translateY(-50%);
}
.root-error-summary {
font-size: 1.8rem;
line-height: 2.
Open service 2001:41a8:44:4::4f8c:5f81:80 · sysfos.northerntrust.com
2026-01-21 17:51
HTTP/1.1 301 Moved Permanently Server: AkamaiGHost Content-Length: 0 Location: https://sysfos.northerntrust.com/ Date: Wed, 21 Jan 2026 17:52:21 GMT Connection: close Set-Cookie: NTRS_VISIT_ID=7d5f8c4ff88b3e00551271693d01000032000000; path=/; domain=.ntrs.com
Open service 2001:41a8:44:4::4f8c:5f48:443 · sysfos.northerntrust.com
2026-01-21 17:51
HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Tue, 13 Jan 2026 15:53:53 GMT
x-amz-version-id: 1XEfeO8SKn_NKe_sJFFA8H8NAXww0Wey
ETag: W/"a22dd2cbf5e51ee811b5afb2ffd264af"
Server: AmazonS3
Cache-Control: no-store
Expires: 0
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-FOS-URI: /index.html
X-Amz-Cf-Pop: JFK50-P3
X-Amz-Cf-Id: pbe5XGnFkjePsQM8N7PyneoMTjVmU3ins93eav1UxPazg-DNx8anjg==
Date: Wed, 21 Jan 2026 17:52:03 GMT
Content-Length: 6188
Connection: close
Set-Cookie: NTRS_VISIT_ID=7d5f8c4ff88b3e00431271698a02000029000000; path=/; domain=.ntrs.com
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Page title: Front Office Solutions
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<meta http-equiv="X-UA-Compatible" content="ie=edge">
<title>Front Office Solutions</title>
<!--
Remove this if you only support browsers that support async/await.
This is needed by babel to share largeish helper code for compiling async/await in older
browsers. More information at https://github.com/single-spa/create-single-spa/issues/112
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/regenerator-runtime@0.14.1/runtime.min.js"></script> -->
<!--
This CSP allows any SSL-enabled host and for arbitrary eval(), but you should limit these directives further to increase your app's security.
Learn more about CSP policies at https://content-security-policy.com/#directive
-->
<meta
http-equiv="Content-Security-Policy"
content="
default-src 'self' https:;
script-src 'unsafe-inline' 'unsafe-eval' https:;
worker-src 'self' blob: https:;
connect-src https: wss://*.northerntrust.com wss://*.amzext.ntrs.com;
style-src 'unsafe-inline' https:;
object-src 'none';
font-src 'self' https: data:;
img-src 'self' https://*.northerntrust.com https://www.google-analytics.com https://www.googletagmanager.com data:;
frame-src 'self' https: com-okta-authenticator: about: data: blob:;
"
>
<!-- If you wish to turn off import-map-overrides for specific environments (prod), uncomment the line below -->
<!-- More info at https://github.com/joeldenning/import-map-overrides/blob/master/docs/configuration.md#domain-list -->
<!-- <meta name="import-map-overrides-domains" content="denylist:prod.example.com" /> -->
<!-- Shared dependencies go into this import map. Your shared dependencies must be of one of the following formats:
1. System.register (preferred when possible) - https://github.com/systemjs/systemjs/blob/master/docs/system-register.md
2. UMD - https://github.com/umdjs/umd
3. Global variable
More information about shared dependencies can be found at https://single-spa.js.org/docs/recommended-setup#sharing-with-import-maps.
-->
<link rel="preload" href="https://cdn.jsdelivr.net/npm/single-spa@6.0.3/lib/es2015/system/single-spa.min.js" as="script" crossorigin>
<link rel="preload" href="/apps/v2/fos-nav-bar/images/logo-fos-main.svg" as="image">
<!-- Add your organization's prod import map URL to this script's src -->
<!-- <script type="systemjs-importmap" src="/importmap.json"></script> -->
<meta name="importmap-type" content="systemjs-importmap" />
<script type="systemjs-importmap" src="/importmap.json"></script>
<!--
If you need to support Angular applications, uncomment the script tag below to ensure only one instance of ZoneJS is loaded
Learn more about why at https://single-spa.js.org/docs/ecosystem-angular/#zonejs
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/zone.js@0.11.3/dist/zone.min.js"></script> -->
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/system.min.js"></script>
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/extras/amd.min.js"></script>
<style>
body, html {
background-color: white;
}
single-spa-router {
height: 100vh;
display: flex;
flex-direction: column;
}
single-spa-router > nav > div:not(:empty) {
height: 48px;
}
single-spa-router > nav > div:empty {
display: none;
}
.root-error-page {
height: 100vh;
width: 100vw;
position: relative;
color: #4a4d4f;
display: flex;
align-items: center;
justify-content: center;
}
.root-error-container {
display: flex;
flex-direction: column;
align-items: center;
justify-content: center;
text-align: center;
transform: translateY(-50%);
}
.root-error-summary {
font-size: 1.8rem;
line-height: 2.
Open service 92.123.104.64:443 · sysfos.northerntrust.com
2026-01-10 02:10
HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Mon, 15 Dec 2025 17:50:12 GMT
x-amz-version-id: apDmG1crYml.s4KaxmyAFDYmkEzCne4n
ETag: W/"4ee94b3d46fd7b76934c6e771763eb54"
Server: AmazonS3
Cache-Control: no-store
Expires: 0
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-FOS-URI: /index.html
X-Amz-Cf-Pop: JFK50-P3
X-Amz-Cf-Id: Z9DitkFirZuoYP-d9LGxBACaSmD4HD0s1m63Qs9mSwvPnWmvsjXBtA==
Date: Sat, 10 Jan 2026 02:10:03 GMT
Content-Length: 6146
Connection: close
Set-Cookie: NTRS_VISIT_ID=c0a72917977e0000fbb461699902000040170000; path=/; domain=.ntrs.com
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Page title: Front Office Solutions
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<meta http-equiv="X-UA-Compatible" content="ie=edge">
<title>Front Office Solutions</title>
<!--
Remove this if you only support browsers that support async/await.
This is needed by babel to share largeish helper code for compiling async/await in older
browsers. More information at https://github.com/single-spa/create-single-spa/issues/112
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/regenerator-runtime@0.14.1/runtime.min.js"></script> -->
<!--
This CSP allows any SSL-enabled host and for arbitrary eval(), but you should limit these directives further to increase your app's security.
Learn more about CSP policies at https://content-security-policy.com/#directive
-->
<meta
http-equiv="Content-Security-Policy"
content="
default-src 'self' https:;
script-src 'unsafe-inline' 'unsafe-eval' https:;
connect-src https: wss://*.northerntrust.com wss://*.amzext.ntrs.com;
style-src 'unsafe-inline' https:;
object-src 'none';
font-src 'self' https: data:;
img-src 'self' https://*.northerntrust.com https://www.google-analytics.com https://www.googletagmanager.com data:;
frame-src 'self' https: com-okta-authenticator: about: data: blob:;
"
>
<!-- If you wish to turn off import-map-overrides for specific environments (prod), uncomment the line below -->
<!-- More info at https://github.com/joeldenning/import-map-overrides/blob/master/docs/configuration.md#domain-list -->
<!-- <meta name="import-map-overrides-domains" content="denylist:prod.example.com" /> -->
<!-- Shared dependencies go into this import map. Your shared dependencies must be of one of the following formats:
1. System.register (preferred when possible) - https://github.com/systemjs/systemjs/blob/master/docs/system-register.md
2. UMD - https://github.com/umdjs/umd
3. Global variable
More information about shared dependencies can be found at https://single-spa.js.org/docs/recommended-setup#sharing-with-import-maps.
-->
<link rel="preload" href="https://cdn.jsdelivr.net/npm/single-spa@6.0.3/lib/es2015/system/single-spa.min.js" as="script" crossorigin>
<link rel="preload" href="/apps/v2/fos-nav-bar/images/logo-fos-main.svg" as="image">
<!-- Add your organization's prod import map URL to this script's src -->
<!-- <script type="systemjs-importmap" src="/importmap.json"></script> -->
<meta name="importmap-type" content="systemjs-importmap" />
<script type="systemjs-importmap" src="/importmap.json"></script>
<!--
If you need to support Angular applications, uncomment the script tag below to ensure only one instance of ZoneJS is loaded
Learn more about why at https://single-spa.js.org/docs/ecosystem-angular/#zonejs
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/zone.js@0.11.3/dist/zone.min.js"></script> -->
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/system.min.js"></script>
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/extras/amd.min.js"></script>
<style>
body, html {
background-color: white;
}
single-spa-router {
height: 100vh;
display: flex;
flex-direction: column;
}
single-spa-router > nav > div:not(:empty) {
height: 48px;
}
single-spa-router > nav > div:empty {
display: none;
}
.root-error-page {
height: 100vh;
width: 100vw;
position: relative;
color: #4a4d4f;
display: flex;
align-items: center;
justify-content: center;
}
.root-error-container {
display: flex;
flex-direction: column;
align-items: center;
justify-content: center;
text-align: center;
transform: translateY(-50%);
}
.root-error-summary {
font-size: 1.8rem;
line-height: 2.4rem;
margin-top: 2.5rem;
}
Open service 2.16.204.147:443 · sysfos.northerntrust.com
2026-01-07 13:34
HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Mon, 15 Dec 2025 17:50:12 GMT
x-amz-version-id: apDmG1crYml.s4KaxmyAFDYmkEzCne4n
ETag: W/"4ee94b3d46fd7b76934c6e771763eb54"
Server: AmazonS3
Cache-Control: no-store
Expires: 0
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-FOS-URI: /index.html
X-Amz-Cf-Pop: JFK50-P3
X-Amz-Cf-Id: lOFcPejLLXVr4wjoaffHAr8jkmqhbN56lpfISbKYI74oloMv4qqVpQ==
Date: Wed, 07 Jan 2026 13:34:19 GMT
Content-Length: 6146
Connection: close
Set-Cookie: NTRS_VISIT_ID=931d100214b92700db605e69a8030000610b0000; path=/; domain=.ntrs.com
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Page title: Front Office Solutions
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<meta http-equiv="X-UA-Compatible" content="ie=edge">
<title>Front Office Solutions</title>
<!--
Remove this if you only support browsers that support async/await.
This is needed by babel to share largeish helper code for compiling async/await in older
browsers. More information at https://github.com/single-spa/create-single-spa/issues/112
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/regenerator-runtime@0.14.1/runtime.min.js"></script> -->
<!--
This CSP allows any SSL-enabled host and for arbitrary eval(), but you should limit these directives further to increase your app's security.
Learn more about CSP policies at https://content-security-policy.com/#directive
-->
<meta
http-equiv="Content-Security-Policy"
content="
default-src 'self' https:;
script-src 'unsafe-inline' 'unsafe-eval' https:;
connect-src https: wss://*.northerntrust.com wss://*.amzext.ntrs.com;
style-src 'unsafe-inline' https:;
object-src 'none';
font-src 'self' https: data:;
img-src 'self' https://*.northerntrust.com https://www.google-analytics.com https://www.googletagmanager.com data:;
frame-src 'self' https: com-okta-authenticator: about: data: blob:;
"
>
<!-- If you wish to turn off import-map-overrides for specific environments (prod), uncomment the line below -->
<!-- More info at https://github.com/joeldenning/import-map-overrides/blob/master/docs/configuration.md#domain-list -->
<!-- <meta name="import-map-overrides-domains" content="denylist:prod.example.com" /> -->
<!-- Shared dependencies go into this import map. Your shared dependencies must be of one of the following formats:
1. System.register (preferred when possible) - https://github.com/systemjs/systemjs/blob/master/docs/system-register.md
2. UMD - https://github.com/umdjs/umd
3. Global variable
More information about shared dependencies can be found at https://single-spa.js.org/docs/recommended-setup#sharing-with-import-maps.
-->
<link rel="preload" href="https://cdn.jsdelivr.net/npm/single-spa@6.0.3/lib/es2015/system/single-spa.min.js" as="script" crossorigin>
<link rel="preload" href="/apps/v2/fos-nav-bar/images/logo-fos-main.svg" as="image">
<!-- Add your organization's prod import map URL to this script's src -->
<!-- <script type="systemjs-importmap" src="/importmap.json"></script> -->
<meta name="importmap-type" content="systemjs-importmap" />
<script type="systemjs-importmap" src="/importmap.json"></script>
<!--
If you need to support Angular applications, uncomment the script tag below to ensure only one instance of ZoneJS is loaded
Learn more about why at https://single-spa.js.org/docs/ecosystem-angular/#zonejs
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/zone.js@0.11.3/dist/zone.min.js"></script> -->
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/system.min.js"></script>
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/extras/amd.min.js"></script>
<style>
body, html {
background-color: white;
}
single-spa-router {
height: 100vh;
display: flex;
flex-direction: column;
}
single-spa-router > nav > div:not(:empty) {
height: 48px;
}
single-spa-router > nav > div:empty {
display: none;
}
.root-error-page {
height: 100vh;
width: 100vw;
position: relative;
color: #4a4d4f;
display: flex;
align-items: center;
justify-content: center;
}
.root-error-container {
display: flex;
flex-direction: column;
align-items: center;
justify-content: center;
text-align: center;
transform: translateY(-50%);
}
.root-error-summary {
font-size: 1.8rem;
line-height: 2.4rem;
margin-top: 2.5rem;
}
Open service 2a02:26f0:3500:14::1724:a255:80 · sysfos.northerntrust.com
2026-01-07 13:34
HTTP/1.1 301 Moved Permanently Server: AkamaiGHost Content-Length: 0 Location: https://sysfos.northerntrust.com/ Date: Wed, 07 Jan 2026 13:34:56 GMT Connection: close Set-Cookie: NTRS_VISIT_ID=15a024176437240000615e6956010000bf0f0000; path=/; domain=.ntrs.com
Open service 2.16.204.154:443 · sysfos.northerntrust.com
2026-01-07 13:34
HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Mon, 15 Dec 2025 17:50:12 GMT
x-amz-version-id: apDmG1crYml.s4KaxmyAFDYmkEzCne4n
ETag: W/"4ee94b3d46fd7b76934c6e771763eb54"
Server: AmazonS3
Cache-Control: no-store
Expires: 0
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-FOS-URI: /index.html
X-Amz-Cf-Pop: JFK50-P3
X-Amz-Cf-Id: Fr6CRIeZd0FNNZyaq8JNmByP7JMqh93wXAkZsbNOzVgsC_vcWCjQZw==
Date: Wed, 07 Jan 2026 13:34:19 GMT
Content-Length: 6146
Connection: close
Set-Cookie: NTRS_VISIT_ID=9a1d100236742100db605e6936020000b2040000; path=/; domain=.ntrs.com
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Page title: Front Office Solutions
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<meta http-equiv="X-UA-Compatible" content="ie=edge">
<title>Front Office Solutions</title>
<!--
Remove this if you only support browsers that support async/await.
This is needed by babel to share largeish helper code for compiling async/await in older
browsers. More information at https://github.com/single-spa/create-single-spa/issues/112
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/regenerator-runtime@0.14.1/runtime.min.js"></script> -->
<!--
This CSP allows any SSL-enabled host and for arbitrary eval(), but you should limit these directives further to increase your app's security.
Learn more about CSP policies at https://content-security-policy.com/#directive
-->
<meta
http-equiv="Content-Security-Policy"
content="
default-src 'self' https:;
script-src 'unsafe-inline' 'unsafe-eval' https:;
connect-src https: wss://*.northerntrust.com wss://*.amzext.ntrs.com;
style-src 'unsafe-inline' https:;
object-src 'none';
font-src 'self' https: data:;
img-src 'self' https://*.northerntrust.com https://www.google-analytics.com https://www.googletagmanager.com data:;
frame-src 'self' https: com-okta-authenticator: about: data: blob:;
"
>
<!-- If you wish to turn off import-map-overrides for specific environments (prod), uncomment the line below -->
<!-- More info at https://github.com/joeldenning/import-map-overrides/blob/master/docs/configuration.md#domain-list -->
<!-- <meta name="import-map-overrides-domains" content="denylist:prod.example.com" /> -->
<!-- Shared dependencies go into this import map. Your shared dependencies must be of one of the following formats:
1. System.register (preferred when possible) - https://github.com/systemjs/systemjs/blob/master/docs/system-register.md
2. UMD - https://github.com/umdjs/umd
3. Global variable
More information about shared dependencies can be found at https://single-spa.js.org/docs/recommended-setup#sharing-with-import-maps.
-->
<link rel="preload" href="https://cdn.jsdelivr.net/npm/single-spa@6.0.3/lib/es2015/system/single-spa.min.js" as="script" crossorigin>
<link rel="preload" href="/apps/v2/fos-nav-bar/images/logo-fos-main.svg" as="image">
<!-- Add your organization's prod import map URL to this script's src -->
<!-- <script type="systemjs-importmap" src="/importmap.json"></script> -->
<meta name="importmap-type" content="systemjs-importmap" />
<script type="systemjs-importmap" src="/importmap.json"></script>
<!--
If you need to support Angular applications, uncomment the script tag below to ensure only one instance of ZoneJS is loaded
Learn more about why at https://single-spa.js.org/docs/ecosystem-angular/#zonejs
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/zone.js@0.11.3/dist/zone.min.js"></script> -->
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/system.min.js"></script>
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/extras/amd.min.js"></script>
<style>
body, html {
background-color: white;
}
single-spa-router {
height: 100vh;
display: flex;
flex-direction: column;
}
single-spa-router > nav > div:not(:empty) {
height: 48px;
}
single-spa-router > nav > div:empty {
display: none;
}
.root-error-page {
height: 100vh;
width: 100vw;
position: relative;
color: #4a4d4f;
display: flex;
align-items: center;
justify-content: center;
}
.root-error-container {
display: flex;
flex-direction: column;
align-items: center;
justify-content: center;
text-align: center;
transform: translateY(-50%);
}
.root-error-summary {
font-size: 1.8rem;
line-height: 2.4rem;
margin-top: 2.5rem;
}
Open service 2a02:26f0:3500:14::1724:a247:443 · sysfos.northerntrust.com
2026-01-07 13:34
HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Mon, 15 Dec 2025 17:50:12 GMT
x-amz-version-id: apDmG1crYml.s4KaxmyAFDYmkEzCne4n
ETag: W/"4ee94b3d46fd7b76934c6e771763eb54"
Server: AmazonS3
Cache-Control: no-store
Expires: 0
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-FOS-URI: /index.html
X-Amz-Cf-Pop: JFK50-P3
X-Amz-Cf-Id: Ta3SgDtH-k4aI1iYlrNkrOTSJVot0pa_dBv5y4XvVqwn0W5RT6JBZw==
Date: Wed, 07 Jan 2026 13:34:19 GMT
Content-Length: 6146
Connection: close
Set-Cookie: NTRS_VISIT_ID=07a024172fe23300db605e6958030000ae030000; path=/; domain=.ntrs.com
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Page title: Front Office Solutions
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<meta http-equiv="X-UA-Compatible" content="ie=edge">
<title>Front Office Solutions</title>
<!--
Remove this if you only support browsers that support async/await.
This is needed by babel to share largeish helper code for compiling async/await in older
browsers. More information at https://github.com/single-spa/create-single-spa/issues/112
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/regenerator-runtime@0.14.1/runtime.min.js"></script> -->
<!--
This CSP allows any SSL-enabled host and for arbitrary eval(), but you should limit these directives further to increase your app's security.
Learn more about CSP policies at https://content-security-policy.com/#directive
-->
<meta
http-equiv="Content-Security-Policy"
content="
default-src 'self' https:;
script-src 'unsafe-inline' 'unsafe-eval' https:;
connect-src https: wss://*.northerntrust.com wss://*.amzext.ntrs.com;
style-src 'unsafe-inline' https:;
object-src 'none';
font-src 'self' https: data:;
img-src 'self' https://*.northerntrust.com https://www.google-analytics.com https://www.googletagmanager.com data:;
frame-src 'self' https: com-okta-authenticator: about: data: blob:;
"
>
<!-- If you wish to turn off import-map-overrides for specific environments (prod), uncomment the line below -->
<!-- More info at https://github.com/joeldenning/import-map-overrides/blob/master/docs/configuration.md#domain-list -->
<!-- <meta name="import-map-overrides-domains" content="denylist:prod.example.com" /> -->
<!-- Shared dependencies go into this import map. Your shared dependencies must be of one of the following formats:
1. System.register (preferred when possible) - https://github.com/systemjs/systemjs/blob/master/docs/system-register.md
2. UMD - https://github.com/umdjs/umd
3. Global variable
More information about shared dependencies can be found at https://single-spa.js.org/docs/recommended-setup#sharing-with-import-maps.
-->
<link rel="preload" href="https://cdn.jsdelivr.net/npm/single-spa@6.0.3/lib/es2015/system/single-spa.min.js" as="script" crossorigin>
<link rel="preload" href="/apps/v2/fos-nav-bar/images/logo-fos-main.svg" as="image">
<!-- Add your organization's prod import map URL to this script's src -->
<!-- <script type="systemjs-importmap" src="/importmap.json"></script> -->
<meta name="importmap-type" content="systemjs-importmap" />
<script type="systemjs-importmap" src="/importmap.json"></script>
<!--
If you need to support Angular applications, uncomment the script tag below to ensure only one instance of ZoneJS is loaded
Learn more about why at https://single-spa.js.org/docs/ecosystem-angular/#zonejs
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/zone.js@0.11.3/dist/zone.min.js"></script> -->
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/system.min.js"></script>
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/extras/amd.min.js"></script>
<style>
body, html {
background-color: white;
}
single-spa-router {
height: 100vh;
display: flex;
flex-direction: column;
}
single-spa-router > nav > div:not(:empty) {
height: 48px;
}
single-spa-router > nav > div:empty {
display: none;
}
.root-error-page {
height: 100vh;
width: 100vw;
position: relative;
color: #4a4d4f;
display: flex;
align-items: center;
justify-content: center;
}
.root-error-container {
display: flex;
flex-direction: column;
align-items: center;
justify-content: center;
text-align: center;
transform: translateY(-50%);
}
.root-error-summary {
font-size: 1.8rem;
line-height: 2.4rem;
margin-top: 2.5rem;
}
Open service 2.16.204.147:80 · sysfos.northerntrust.com
2026-01-07 13:34
HTTP/1.1 301 Moved Permanently Server: AkamaiGHost Content-Length: 0 Location: https://sysfos.northerntrust.com/ Date: Wed, 07 Jan 2026 13:34:59 GMT Connection: close Set-Cookie: NTRS_VISIT_ID=931d100214b9270003615e6971010000530c0000; path=/; domain=.ntrs.com
Open service 2.16.204.154:80 · sysfos.northerntrust.com
2026-01-07 13:34
HTTP/1.1 301 Moved Permanently Server: AkamaiGHost Content-Length: 0 Location: https://sysfos.northerntrust.com/ Date: Wed, 07 Jan 2026 13:34:59 GMT Connection: close Set-Cookie: NTRS_VISIT_ID=9a1d10023674210003615e6967010000a0050000; path=/; domain=.ntrs.com
Open service 2a02:26f0:3500:14::1724:a247:80 · sysfos.northerntrust.com
2026-01-07 13:34
HTTP/1.1 301 Moved Permanently Server: AkamaiGHost Content-Length: 0 Location: https://sysfos.northerntrust.com/ Date: Wed, 07 Jan 2026 13:34:59 GMT Connection: close Set-Cookie: NTRS_VISIT_ID=07a024172fe2330003615e6987000000b3030000; path=/; domain=.ntrs.com
Open service 2a02:26f0:3500:14::1724:a255:443 · sysfos.northerntrust.com
2026-01-07 13:34
HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Mon, 15 Dec 2025 17:50:12 GMT
x-amz-version-id: apDmG1crYml.s4KaxmyAFDYmkEzCne4n
ETag: W/"4ee94b3d46fd7b76934c6e771763eb54"
Server: AmazonS3
Cache-Control: no-store
Expires: 0
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-FOS-URI: /index.html
X-Amz-Cf-Pop: JFK50-P3
X-Amz-Cf-Id: qQwgH-KAIErt23i8pCHHHQwwCFAAWnkXYwafXzCgoVu2lm7iQJRPHg==
Date: Wed, 07 Jan 2026 13:34:19 GMT
Content-Length: 6146
Connection: close
Set-Cookie: NTRS_VISIT_ID=15a0241764372400db605e6995010000b20f0000; path=/; domain=.ntrs.com
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Page title: Front Office Solutions
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<meta http-equiv="X-UA-Compatible" content="ie=edge">
<title>Front Office Solutions</title>
<!--
Remove this if you only support browsers that support async/await.
This is needed by babel to share largeish helper code for compiling async/await in older
browsers. More information at https://github.com/single-spa/create-single-spa/issues/112
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/regenerator-runtime@0.14.1/runtime.min.js"></script> -->
<!--
This CSP allows any SSL-enabled host and for arbitrary eval(), but you should limit these directives further to increase your app's security.
Learn more about CSP policies at https://content-security-policy.com/#directive
-->
<meta
http-equiv="Content-Security-Policy"
content="
default-src 'self' https:;
script-src 'unsafe-inline' 'unsafe-eval' https:;
connect-src https: wss://*.northerntrust.com wss://*.amzext.ntrs.com;
style-src 'unsafe-inline' https:;
object-src 'none';
font-src 'self' https: data:;
img-src 'self' https://*.northerntrust.com https://www.google-analytics.com https://www.googletagmanager.com data:;
frame-src 'self' https: com-okta-authenticator: about: data: blob:;
"
>
<!-- If you wish to turn off import-map-overrides for specific environments (prod), uncomment the line below -->
<!-- More info at https://github.com/joeldenning/import-map-overrides/blob/master/docs/configuration.md#domain-list -->
<!-- <meta name="import-map-overrides-domains" content="denylist:prod.example.com" /> -->
<!-- Shared dependencies go into this import map. Your shared dependencies must be of one of the following formats:
1. System.register (preferred when possible) - https://github.com/systemjs/systemjs/blob/master/docs/system-register.md
2. UMD - https://github.com/umdjs/umd
3. Global variable
More information about shared dependencies can be found at https://single-spa.js.org/docs/recommended-setup#sharing-with-import-maps.
-->
<link rel="preload" href="https://cdn.jsdelivr.net/npm/single-spa@6.0.3/lib/es2015/system/single-spa.min.js" as="script" crossorigin>
<link rel="preload" href="/apps/v2/fos-nav-bar/images/logo-fos-main.svg" as="image">
<!-- Add your organization's prod import map URL to this script's src -->
<!-- <script type="systemjs-importmap" src="/importmap.json"></script> -->
<meta name="importmap-type" content="systemjs-importmap" />
<script type="systemjs-importmap" src="/importmap.json"></script>
<!--
If you need to support Angular applications, uncomment the script tag below to ensure only one instance of ZoneJS is loaded
Learn more about why at https://single-spa.js.org/docs/ecosystem-angular/#zonejs
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/zone.js@0.11.3/dist/zone.min.js"></script> -->
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/system.min.js"></script>
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/extras/amd.min.js"></script>
<style>
body, html {
background-color: white;
}
single-spa-router {
height: 100vh;
display: flex;
flex-direction: column;
}
single-spa-router > nav > div:not(:empty) {
height: 48px;
}
single-spa-router > nav > div:empty {
display: none;
}
.root-error-page {
height: 100vh;
width: 100vw;
position: relative;
color: #4a4d4f;
display: flex;
align-items: center;
justify-content: center;
}
.root-error-container {
display: flex;
flex-direction: column;
align-items: center;
justify-content: center;
text-align: center;
transform: translateY(-50%);
}
.root-error-summary {
font-size: 1.8rem;
line-height: 2.4rem;
margin-top: 2.5rem;
}
Open service 92.123.104.64:443 · sysfos.northerntrust.com
2026-01-03 00:24
HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Mon, 15 Dec 2025 17:50:12 GMT
x-amz-version-id: apDmG1crYml.s4KaxmyAFDYmkEzCne4n
ETag: W/"4ee94b3d46fd7b76934c6e771763eb54"
Server: AmazonS3
Cache-Control: no-store
Expires: 0
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-FOS-URI: /index.html
X-Amz-Cf-Pop: JFK50-P3
X-Amz-Cf-Id: BuNlJZ1I8ALJYCGbxWDzxXH1Zm-brdHbce2Ktm0ecFygcsZ6l_zY_w==
Date: Sat, 03 Jan 2026 00:24:42 GMT
Content-Length: 6146
Connection: close
Set-Cookie: NTRS_VISIT_ID=a9a7291737cb1b00ca615869f400000010000000; path=/; domain=.ntrs.com
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Page title: Front Office Solutions
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<meta http-equiv="X-UA-Compatible" content="ie=edge">
<title>Front Office Solutions</title>
<!--
Remove this if you only support browsers that support async/await.
This is needed by babel to share largeish helper code for compiling async/await in older
browsers. More information at https://github.com/single-spa/create-single-spa/issues/112
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/regenerator-runtime@0.14.1/runtime.min.js"></script> -->
<!--
This CSP allows any SSL-enabled host and for arbitrary eval(), but you should limit these directives further to increase your app's security.
Learn more about CSP policies at https://content-security-policy.com/#directive
-->
<meta
http-equiv="Content-Security-Policy"
content="
default-src 'self' https:;
script-src 'unsafe-inline' 'unsafe-eval' https:;
connect-src https: wss://*.northerntrust.com wss://*.amzext.ntrs.com;
style-src 'unsafe-inline' https:;
object-src 'none';
font-src 'self' https: data:;
img-src 'self' https://*.northerntrust.com https://www.google-analytics.com https://www.googletagmanager.com data:;
frame-src 'self' https: com-okta-authenticator: about: data: blob:;
"
>
<!-- If you wish to turn off import-map-overrides for specific environments (prod), uncomment the line below -->
<!-- More info at https://github.com/joeldenning/import-map-overrides/blob/master/docs/configuration.md#domain-list -->
<!-- <meta name="import-map-overrides-domains" content="denylist:prod.example.com" /> -->
<!-- Shared dependencies go into this import map. Your shared dependencies must be of one of the following formats:
1. System.register (preferred when possible) - https://github.com/systemjs/systemjs/blob/master/docs/system-register.md
2. UMD - https://github.com/umdjs/umd
3. Global variable
More information about shared dependencies can be found at https://single-spa.js.org/docs/recommended-setup#sharing-with-import-maps.
-->
<link rel="preload" href="https://cdn.jsdelivr.net/npm/single-spa@6.0.3/lib/es2015/system/single-spa.min.js" as="script" crossorigin>
<link rel="preload" href="/apps/v2/fos-nav-bar/images/logo-fos-main.svg" as="image">
<!-- Add your organization's prod import map URL to this script's src -->
<!-- <script type="systemjs-importmap" src="/importmap.json"></script> -->
<meta name="importmap-type" content="systemjs-importmap" />
<script type="systemjs-importmap" src="/importmap.json"></script>
<!--
If you need to support Angular applications, uncomment the script tag below to ensure only one instance of ZoneJS is loaded
Learn more about why at https://single-spa.js.org/docs/ecosystem-angular/#zonejs
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/zone.js@0.11.3/dist/zone.min.js"></script> -->
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/system.min.js"></script>
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/extras/amd.min.js"></script>
<style>
body, html {
background-color: white;
}
single-spa-router {
height: 100vh;
display: flex;
flex-direction: column;
}
single-spa-router > nav > div:not(:empty) {
height: 48px;
}
single-spa-router > nav > div:empty {
display: none;
}
.root-error-page {
height: 100vh;
width: 100vw;
position: relative;
color: #4a4d4f;
display: flex;
align-items: center;
justify-content: center;
}
.root-error-container {
display: flex;
flex-direction: column;
align-items: center;
justify-content: center;
text-align: center;
transform: translateY(-50%);
}
.root-error-summary {
font-size: 1.8rem;
line-height: 2.4rem;
margin-top: 2.5rem;
}
Open service 2.16.204.147:443 · sysfos.northerntrust.com
2025-12-23 16:41
HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Mon, 15 Dec 2025 17:50:12 GMT
x-amz-version-id: apDmG1crYml.s4KaxmyAFDYmkEzCne4n
ETag: W/"4ee94b3d46fd7b76934c6e771763eb54"
Server: AmazonS3
Cache-Control: no-store
Expires: 0
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-FOS-URI: /index.html
X-Amz-Cf-Pop: JFK50-P3
X-Amz-Cf-Id: X6bnJoS3H06cYmiz35Mi5lz5OZCsOoyVqN-Y-1rSoyevSb4lMy6gpQ==
Date: Tue, 23 Dec 2025 16:41:38 GMT
Content-Length: 6146
Connection: close
Set-Cookie: NTRS_VISIT_ID=931d100214b9270042c64a693603000020060000; path=/; domain=.ntrs.com
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Page title: Front Office Solutions
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<meta http-equiv="X-UA-Compatible" content="ie=edge">
<title>Front Office Solutions</title>
<!--
Remove this if you only support browsers that support async/await.
This is needed by babel to share largeish helper code for compiling async/await in older
browsers. More information at https://github.com/single-spa/create-single-spa/issues/112
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/regenerator-runtime@0.14.1/runtime.min.js"></script> -->
<!--
This CSP allows any SSL-enabled host and for arbitrary eval(), but you should limit these directives further to increase your app's security.
Learn more about CSP policies at https://content-security-policy.com/#directive
-->
<meta
http-equiv="Content-Security-Policy"
content="
default-src 'self' https:;
script-src 'unsafe-inline' 'unsafe-eval' https:;
connect-src https: wss://*.northerntrust.com wss://*.amzext.ntrs.com;
style-src 'unsafe-inline' https:;
object-src 'none';
font-src 'self' https: data:;
img-src 'self' https://*.northerntrust.com https://www.google-analytics.com https://www.googletagmanager.com data:;
frame-src 'self' https: com-okta-authenticator: about: data: blob:;
"
>
<!-- If you wish to turn off import-map-overrides for specific environments (prod), uncomment the line below -->
<!-- More info at https://github.com/joeldenning/import-map-overrides/blob/master/docs/configuration.md#domain-list -->
<!-- <meta name="import-map-overrides-domains" content="denylist:prod.example.com" /> -->
<!-- Shared dependencies go into this import map. Your shared dependencies must be of one of the following formats:
1. System.register (preferred when possible) - https://github.com/systemjs/systemjs/blob/master/docs/system-register.md
2. UMD - https://github.com/umdjs/umd
3. Global variable
More information about shared dependencies can be found at https://single-spa.js.org/docs/recommended-setup#sharing-with-import-maps.
-->
<link rel="preload" href="https://cdn.jsdelivr.net/npm/single-spa@6.0.3/lib/es2015/system/single-spa.min.js" as="script" crossorigin>
<link rel="preload" href="/apps/v2/fos-nav-bar/images/logo-fos-main.svg" as="image">
<!-- Add your organization's prod import map URL to this script's src -->
<!-- <script type="systemjs-importmap" src="/importmap.json"></script> -->
<meta name="importmap-type" content="systemjs-importmap" />
<script type="systemjs-importmap" src="/importmap.json"></script>
<!--
If you need to support Angular applications, uncomment the script tag below to ensure only one instance of ZoneJS is loaded
Learn more about why at https://single-spa.js.org/docs/ecosystem-angular/#zonejs
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/zone.js@0.11.3/dist/zone.min.js"></script> -->
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/system.min.js"></script>
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/extras/amd.min.js"></script>
<style>
body, html {
background-color: white;
}
single-spa-router {
height: 100vh;
display: flex;
flex-direction: column;
}
single-spa-router > nav > div:not(:empty) {
height: 48px;
}
single-spa-router > nav > div:empty {
display: none;
}
.root-error-page {
height: 100vh;
width: 100vw;
position: relative;
color: #4a4d4f;
display: flex;
align-items: center;
justify-content: center;
}
.root-error-container {
display: flex;
flex-direction: column;
align-items: center;
justify-content: center;
text-align: center;
transform: translateY(-50%);
}
.root-error-summary {
font-size: 1.8rem;
line-height: 2.4rem;
margin-top: 2.5rem;
}
Open service 2.16.204.147:80 · sysfos.northerntrust.com
2025-12-23 16:41
HTTP/1.1 301 Moved Permanently Server: AkamaiGHost Content-Length: 0 Location: https://sysfos.northerntrust.com/ Date: Tue, 23 Dec 2025 16:41:41 GMT Connection: close Set-Cookie: NTRS_VISIT_ID=931d100214b9270045c64a692800000065060000; path=/; domain=.ntrs.com
Open service 2a02:26f0:3500:14::1724:a247:443 · sysfos.northerntrust.com
2025-12-23 16:41
HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Mon, 15 Dec 2025 17:50:12 GMT
x-amz-version-id: apDmG1crYml.s4KaxmyAFDYmkEzCne4n
ETag: W/"4ee94b3d46fd7b76934c6e771763eb54"
Server: AmazonS3
Cache-Control: no-store
Expires: 0
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-FOS-URI: /index.html
X-Amz-Cf-Pop: JFK50-P3
X-Amz-Cf-Id: 930iLxauSEFECh5nXjFGsjDCcC12lwkSUEG-1nXheBUZyGmZXOTbdw==
Date: Tue, 23 Dec 2025 16:41:38 GMT
Content-Length: 6146
Connection: close
Set-Cookie: NTRS_VISIT_ID=15a024176437240042c64a698102000034070000; path=/; domain=.ntrs.com
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Page title: Front Office Solutions
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<meta http-equiv="X-UA-Compatible" content="ie=edge">
<title>Front Office Solutions</title>
<!--
Remove this if you only support browsers that support async/await.
This is needed by babel to share largeish helper code for compiling async/await in older
browsers. More information at https://github.com/single-spa/create-single-spa/issues/112
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/regenerator-runtime@0.14.1/runtime.min.js"></script> -->
<!--
This CSP allows any SSL-enabled host and for arbitrary eval(), but you should limit these directives further to increase your app's security.
Learn more about CSP policies at https://content-security-policy.com/#directive
-->
<meta
http-equiv="Content-Security-Policy"
content="
default-src 'self' https:;
script-src 'unsafe-inline' 'unsafe-eval' https:;
connect-src https: wss://*.northerntrust.com wss://*.amzext.ntrs.com;
style-src 'unsafe-inline' https:;
object-src 'none';
font-src 'self' https: data:;
img-src 'self' https://*.northerntrust.com https://www.google-analytics.com https://www.googletagmanager.com data:;
frame-src 'self' https: com-okta-authenticator: about: data: blob:;
"
>
<!-- If you wish to turn off import-map-overrides for specific environments (prod), uncomment the line below -->
<!-- More info at https://github.com/joeldenning/import-map-overrides/blob/master/docs/configuration.md#domain-list -->
<!-- <meta name="import-map-overrides-domains" content="denylist:prod.example.com" /> -->
<!-- Shared dependencies go into this import map. Your shared dependencies must be of one of the following formats:
1. System.register (preferred when possible) - https://github.com/systemjs/systemjs/blob/master/docs/system-register.md
2. UMD - https://github.com/umdjs/umd
3. Global variable
More information about shared dependencies can be found at https://single-spa.js.org/docs/recommended-setup#sharing-with-import-maps.
-->
<link rel="preload" href="https://cdn.jsdelivr.net/npm/single-spa@6.0.3/lib/es2015/system/single-spa.min.js" as="script" crossorigin>
<link rel="preload" href="/apps/v2/fos-nav-bar/images/logo-fos-main.svg" as="image">
<!-- Add your organization's prod import map URL to this script's src -->
<!-- <script type="systemjs-importmap" src="/importmap.json"></script> -->
<meta name="importmap-type" content="systemjs-importmap" />
<script type="systemjs-importmap" src="/importmap.json"></script>
<!--
If you need to support Angular applications, uncomment the script tag below to ensure only one instance of ZoneJS is loaded
Learn more about why at https://single-spa.js.org/docs/ecosystem-angular/#zonejs
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/zone.js@0.11.3/dist/zone.min.js"></script> -->
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/system.min.js"></script>
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/extras/amd.min.js"></script>
<style>
body, html {
background-color: white;
}
single-spa-router {
height: 100vh;
display: flex;
flex-direction: column;
}
single-spa-router > nav > div:not(:empty) {
height: 48px;
}
single-spa-router > nav > div:empty {
display: none;
}
.root-error-page {
height: 100vh;
width: 100vw;
position: relative;
color: #4a4d4f;
display: flex;
align-items: center;
justify-content: center;
}
.root-error-container {
display: flex;
flex-direction: column;
align-items: center;
justify-content: center;
text-align: center;
transform: translateY(-50%);
}
.root-error-summary {
font-size: 1.8rem;
line-height: 2.4rem;
margin-top: 2.5rem;
}
Open service 2a02:26f0:3500:14::1724:a255:80 · sysfos.northerntrust.com
2025-12-23 16:41
HTTP/1.1 301 Moved Permanently Server: AkamaiGHost Content-Length: 0 Location: https://sysfos.northerntrust.com/ Date: Tue, 23 Dec 2025 16:41:40 GMT Connection: close Set-Cookie: NTRS_VISIT_ID=15a024176437240044c64a696e0200004c070000; path=/; domain=.ntrs.com
Open service 2a02:26f0:3500:14::1724:a247:80 · sysfos.northerntrust.com
2025-12-23 16:41
HTTP/1.1 301 Moved Permanently Server: AkamaiGHost Content-Length: 0 Location: https://sysfos.northerntrust.com/ Date: Tue, 23 Dec 2025 16:41:40 GMT Connection: close Set-Cookie: NTRS_VISIT_ID=07a024172fe2330044c64a6954020000f2000000; path=/; domain=.ntrs.com
Open service 2.16.204.154:80 · sysfos.northerntrust.com
2025-12-23 16:41
HTTP/1.1 301 Moved Permanently Server: AkamaiGHost Content-Length: 0 Location: https://sysfos.northerntrust.com/ Date: Tue, 23 Dec 2025 16:41:40 GMT Connection: close Set-Cookie: NTRS_VISIT_ID=9a1d10023674210044c64a6990020000a8000000; path=/; domain=.ntrs.com
Open service 2a02:26f0:3500:14::1724:a255:443 · sysfos.northerntrust.com
2025-12-23 16:41
HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Mon, 15 Dec 2025 17:50:12 GMT
x-amz-version-id: apDmG1crYml.s4KaxmyAFDYmkEzCne4n
ETag: W/"4ee94b3d46fd7b76934c6e771763eb54"
Server: AmazonS3
Cache-Control: no-store
Expires: 0
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-FOS-URI: /index.html
X-Amz-Cf-Pop: JFK50-P3
X-Amz-Cf-Id: MFj5e82u1HCam2ZvhbQEr__Z2rKsKLjJZLvdRBJo_FTtTGpJF63UZw==
Date: Tue, 23 Dec 2025 16:41:38 GMT
Content-Length: 6146
Connection: close
Set-Cookie: NTRS_VISIT_ID=07a024172fe2330042c64a69fe000000d9000000; path=/; domain=.ntrs.com
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Page title: Front Office Solutions
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<meta http-equiv="X-UA-Compatible" content="ie=edge">
<title>Front Office Solutions</title>
<!--
Remove this if you only support browsers that support async/await.
This is needed by babel to share largeish helper code for compiling async/await in older
browsers. More information at https://github.com/single-spa/create-single-spa/issues/112
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/regenerator-runtime@0.14.1/runtime.min.js"></script> -->
<!--
This CSP allows any SSL-enabled host and for arbitrary eval(), but you should limit these directives further to increase your app's security.
Learn more about CSP policies at https://content-security-policy.com/#directive
-->
<meta
http-equiv="Content-Security-Policy"
content="
default-src 'self' https:;
script-src 'unsafe-inline' 'unsafe-eval' https:;
connect-src https: wss://*.northerntrust.com wss://*.amzext.ntrs.com;
style-src 'unsafe-inline' https:;
object-src 'none';
font-src 'self' https: data:;
img-src 'self' https://*.northerntrust.com https://www.google-analytics.com https://www.googletagmanager.com data:;
frame-src 'self' https: com-okta-authenticator: about: data: blob:;
"
>
<!-- If you wish to turn off import-map-overrides for specific environments (prod), uncomment the line below -->
<!-- More info at https://github.com/joeldenning/import-map-overrides/blob/master/docs/configuration.md#domain-list -->
<!-- <meta name="import-map-overrides-domains" content="denylist:prod.example.com" /> -->
<!-- Shared dependencies go into this import map. Your shared dependencies must be of one of the following formats:
1. System.register (preferred when possible) - https://github.com/systemjs/systemjs/blob/master/docs/system-register.md
2. UMD - https://github.com/umdjs/umd
3. Global variable
More information about shared dependencies can be found at https://single-spa.js.org/docs/recommended-setup#sharing-with-import-maps.
-->
<link rel="preload" href="https://cdn.jsdelivr.net/npm/single-spa@6.0.3/lib/es2015/system/single-spa.min.js" as="script" crossorigin>
<link rel="preload" href="/apps/v2/fos-nav-bar/images/logo-fos-main.svg" as="image">
<!-- Add your organization's prod import map URL to this script's src -->
<!-- <script type="systemjs-importmap" src="/importmap.json"></script> -->
<meta name="importmap-type" content="systemjs-importmap" />
<script type="systemjs-importmap" src="/importmap.json"></script>
<!--
If you need to support Angular applications, uncomment the script tag below to ensure only one instance of ZoneJS is loaded
Learn more about why at https://single-spa.js.org/docs/ecosystem-angular/#zonejs
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/zone.js@0.11.3/dist/zone.min.js"></script> -->
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/system.min.js"></script>
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/extras/amd.min.js"></script>
<style>
body, html {
background-color: white;
}
single-spa-router {
height: 100vh;
display: flex;
flex-direction: column;
}
single-spa-router > nav > div:not(:empty) {
height: 48px;
}
single-spa-router > nav > div:empty {
display: none;
}
.root-error-page {
height: 100vh;
width: 100vw;
position: relative;
color: #4a4d4f;
display: flex;
align-items: center;
justify-content: center;
}
.root-error-container {
display: flex;
flex-direction: column;
align-items: center;
justify-content: center;
text-align: center;
transform: translateY(-50%);
}
.root-error-summary {
font-size: 1.8rem;
line-height: 2.4rem;
margin-top: 2.5rem;
}
Open service 2.16.204.154:443 · sysfos.northerntrust.com
2025-12-23 16:41
HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Mon, 15 Dec 2025 17:50:12 GMT
x-amz-version-id: apDmG1crYml.s4KaxmyAFDYmkEzCne4n
ETag: W/"4ee94b3d46fd7b76934c6e771763eb54"
Server: AmazonS3
Cache-Control: no-store
Expires: 0
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-FOS-URI: /index.html
X-Amz-Cf-Pop: JFK50-P3
X-Amz-Cf-Id: _Fzk6GJ_sMSUQBMHtx3x0X7iHGqcbDp2U1pCfCRn-vTv_Fb-e8-iog==
Date: Tue, 23 Dec 2025 16:41:38 GMT
Content-Length: 6146
Connection: close
Set-Cookie: NTRS_VISIT_ID=9a1d10023674210042c64a69660100006b000000; path=/; domain=.ntrs.com
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Page title: Front Office Solutions
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<meta http-equiv="X-UA-Compatible" content="ie=edge">
<title>Front Office Solutions</title>
<!--
Remove this if you only support browsers that support async/await.
This is needed by babel to share largeish helper code for compiling async/await in older
browsers. More information at https://github.com/single-spa/create-single-spa/issues/112
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/regenerator-runtime@0.14.1/runtime.min.js"></script> -->
<!--
This CSP allows any SSL-enabled host and for arbitrary eval(), but you should limit these directives further to increase your app's security.
Learn more about CSP policies at https://content-security-policy.com/#directive
-->
<meta
http-equiv="Content-Security-Policy"
content="
default-src 'self' https:;
script-src 'unsafe-inline' 'unsafe-eval' https:;
connect-src https: wss://*.northerntrust.com wss://*.amzext.ntrs.com;
style-src 'unsafe-inline' https:;
object-src 'none';
font-src 'self' https: data:;
img-src 'self' https://*.northerntrust.com https://www.google-analytics.com https://www.googletagmanager.com data:;
frame-src 'self' https: com-okta-authenticator: about: data: blob:;
"
>
<!-- If you wish to turn off import-map-overrides for specific environments (prod), uncomment the line below -->
<!-- More info at https://github.com/joeldenning/import-map-overrides/blob/master/docs/configuration.md#domain-list -->
<!-- <meta name="import-map-overrides-domains" content="denylist:prod.example.com" /> -->
<!-- Shared dependencies go into this import map. Your shared dependencies must be of one of the following formats:
1. System.register (preferred when possible) - https://github.com/systemjs/systemjs/blob/master/docs/system-register.md
2. UMD - https://github.com/umdjs/umd
3. Global variable
More information about shared dependencies can be found at https://single-spa.js.org/docs/recommended-setup#sharing-with-import-maps.
-->
<link rel="preload" href="https://cdn.jsdelivr.net/npm/single-spa@6.0.3/lib/es2015/system/single-spa.min.js" as="script" crossorigin>
<link rel="preload" href="/apps/v2/fos-nav-bar/images/logo-fos-main.svg" as="image">
<!-- Add your organization's prod import map URL to this script's src -->
<!-- <script type="systemjs-importmap" src="/importmap.json"></script> -->
<meta name="importmap-type" content="systemjs-importmap" />
<script type="systemjs-importmap" src="/importmap.json"></script>
<!--
If you need to support Angular applications, uncomment the script tag below to ensure only one instance of ZoneJS is loaded
Learn more about why at https://single-spa.js.org/docs/ecosystem-angular/#zonejs
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/zone.js@0.11.3/dist/zone.min.js"></script> -->
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/system.min.js"></script>
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/extras/amd.min.js"></script>
<style>
body, html {
background-color: white;
}
single-spa-router {
height: 100vh;
display: flex;
flex-direction: column;
}
single-spa-router > nav > div:not(:empty) {
height: 48px;
}
single-spa-router > nav > div:empty {
display: none;
}
.root-error-page {
height: 100vh;
width: 100vw;
position: relative;
color: #4a4d4f;
display: flex;
align-items: center;
justify-content: center;
}
.root-error-container {
display: flex;
flex-direction: column;
align-items: center;
justify-content: center;
text-align: center;
transform: translateY(-50%);
}
.root-error-summary {
font-size: 1.8rem;
line-height: 2.4rem;
margin-top: 2.5rem;
}
Open service 92.123.104.64:443 · sysfos.northerntrust.com
2025-12-22 15:50
HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Mon, 15 Dec 2025 17:50:12 GMT
x-amz-version-id: apDmG1crYml.s4KaxmyAFDYmkEzCne4n
ETag: W/"4ee94b3d46fd7b76934c6e771763eb54"
Server: AmazonS3
Cache-Control: no-store
Expires: 0
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-FOS-URI: /index.html
X-Amz-Cf-Pop: JFK50-P3
X-Amz-Cf-Id: 69LCCQv1QjHlDRe4GABPEiirAqWcMeAHNiifMCYwHj0rXFdHHGG_WQ==
Date: Mon, 22 Dec 2025 15:50:20 GMT
Content-Length: 6146
Connection: close
Set-Cookie: NTRS_VISIT_ID=a9a72917447d2200bc68496931000000ae030000; path=/; domain=.ntrs.com
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Page title: Front Office Solutions
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<meta http-equiv="X-UA-Compatible" content="ie=edge">
<title>Front Office Solutions</title>
<!--
Remove this if you only support browsers that support async/await.
This is needed by babel to share largeish helper code for compiling async/await in older
browsers. More information at https://github.com/single-spa/create-single-spa/issues/112
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/regenerator-runtime@0.14.1/runtime.min.js"></script> -->
<!--
This CSP allows any SSL-enabled host and for arbitrary eval(), but you should limit these directives further to increase your app's security.
Learn more about CSP policies at https://content-security-policy.com/#directive
-->
<meta
http-equiv="Content-Security-Policy"
content="
default-src 'self' https:;
script-src 'unsafe-inline' 'unsafe-eval' https:;
connect-src https: wss://*.northerntrust.com wss://*.amzext.ntrs.com;
style-src 'unsafe-inline' https:;
object-src 'none';
font-src 'self' https: data:;
img-src 'self' https://*.northerntrust.com https://www.google-analytics.com https://www.googletagmanager.com data:;
frame-src 'self' https: com-okta-authenticator: about: data: blob:;
"
>
<!-- If you wish to turn off import-map-overrides for specific environments (prod), uncomment the line below -->
<!-- More info at https://github.com/joeldenning/import-map-overrides/blob/master/docs/configuration.md#domain-list -->
<!-- <meta name="import-map-overrides-domains" content="denylist:prod.example.com" /> -->
<!-- Shared dependencies go into this import map. Your shared dependencies must be of one of the following formats:
1. System.register (preferred when possible) - https://github.com/systemjs/systemjs/blob/master/docs/system-register.md
2. UMD - https://github.com/umdjs/umd
3. Global variable
More information about shared dependencies can be found at https://single-spa.js.org/docs/recommended-setup#sharing-with-import-maps.
-->
<link rel="preload" href="https://cdn.jsdelivr.net/npm/single-spa@6.0.3/lib/es2015/system/single-spa.min.js" as="script" crossorigin>
<link rel="preload" href="/apps/v2/fos-nav-bar/images/logo-fos-main.svg" as="image">
<!-- Add your organization's prod import map URL to this script's src -->
<!-- <script type="systemjs-importmap" src="/importmap.json"></script> -->
<meta name="importmap-type" content="systemjs-importmap" />
<script type="systemjs-importmap" src="/importmap.json"></script>
<!--
If you need to support Angular applications, uncomment the script tag below to ensure only one instance of ZoneJS is loaded
Learn more about why at https://single-spa.js.org/docs/ecosystem-angular/#zonejs
-->
<!-- <script src="https://cdn.jsdelivr.net/npm/zone.js@0.11.3/dist/zone.min.js"></script> -->
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/system.min.js"></script>
<script src="https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/extras/amd.min.js"></script>
<style>
body, html {
background-color: white;
}
single-spa-router {
height: 100vh;
display: flex;
flex-direction: column;
}
single-spa-router > nav > div:not(:empty) {
height: 48px;
}
single-spa-router > nav > div:empty {
display: none;
}
.root-error-page {
height: 100vh;
width: 100vw;
position: relative;
color: #4a4d4f;
display: flex;
align-items: center;
justify-content: center;
}
.root-error-container {
display: flex;
flex-direction: column;
align-items: center;
justify-content: center;
text-align: center;
transform: translateY(-50%);
}
.root-error-summary {
font-size: 1.8rem;
line-height: 2.4rem;
margin-top: 2.5rem;
}