Use the helmet.hidePoweredBy() middleware to remove the X-Powered-By header.

Challenge: Hide Potentially Dangerous Information Using helmet.hidePoweredBy()

Will it be against the terms and agreements of craft to remove those headers?

