| CARVIEW |
Select Language
HTTP/2 307
date: Tue, 27 Jan 2026 22:16:51 GMT
location: /en
set-cookie: language=en; Path=/; Expires=Thu, 26 Feb 2026 22:16:51 GMT; Max-Age=2592000; Secure; HttpOnly; SameSite=Strict
x-content-type-options: nosniff
x-frame-options: DENY
x-xss-protection: 1; mode=block
referrer-policy: strict-origin-when-cross-origin
permissions-policy: camera=(), microphone=(), geolocation=(self), interest-cohort=(), payment=(self), usb=(), magnetometer=(), gyroscope=(), accelerometer=()
content-security-policy: default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://analytics.google.com/ https://www.googletagmanager.com https://www.google-analytics.com https://maps.googleapis.com https://cdn.jsdelivr.net https://unpkg.com https://*.tawk.to https://embed.tawk.to https://va.tawk.to https://www.googletagmanager.com https://www.google-analytics.com https://connect.facebook.net https://googleads.g.doubleclick.net https://www.google.com https://www.youtube.com https://www.gstatic.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://*.tawk.to; img-src 'self' data: blob: https:;; font-src 'self' data: http: https://fonts.gstatic.com https://*.tawk.to https://*.bracbank.com ; connect-src 'self' https://analytics.google.com/ https://brac-backend.singularitybd.net https://www.googletagmanager.com https://www.google-analytics.com https://cdn.jsdelivr.net/npm/antd/dist/antd.min.css.map https://maps.googleapis.com https://*.bracbank.com https://devapi.bracbank.com:* https://*.tawk.to wss://*.tawk.to https://www.google-analytics.com https://api.bracbank.com https://*.amazonaws.com https://*.cloudfront.net https://www.googletagmanager.com https://*.doubleclick.net https://connect.facebook.net https://facebook.com https://www.facebook.com https://www.google.com; frame-src 'self' https://analytics.google.com/ https://*.amazonaws.com https://*.bracbank.com https://www.youtube.com https://www.google.com https://www.googletagmanager.com https://*.tawk.to https://maps.googleapis.com; media-src 'self' https: data:; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests
strict-transport-security: max-age=63072000; includeSubDomains; preload
cross-origin-embedder-policy: unsafe-none
cross-origin-opener-policy: same-origin-allow-popups
cross-origin-resource-policy: cross-origin
x-cache: Miss from cloudfront
via: 1.1 5872fbe51a27cfccc81ebb3630f75e08.cloudfront.net (CloudFront)
x-amz-cf-pop: BOM78-P11
alt-svc: h3=":443"; ma=86400
x-amz-cf-id: NLVqFNtjpToG1l1QzOCfsVXlLpXbUfD45XkkCyMqHUvVWswKJzAdgQ==
HTTP/2 200
content-type: text/html; charset=utf-8
date: Tue, 27 Jan 2026 22:16:51 GMT
cache-control: private, no-cache, no-store, max-age=0, must-revalidate
content-encoding: gzip
x-content-type-options: nosniff
x-frame-options: DENY
x-xss-protection: 1; mode=block
referrer-policy: strict-origin-when-cross-origin
permissions-policy: camera=(), microphone=(), geolocation=(self), interest-cohort=(), payment=(self), usb=(), magnetometer=(), gyroscope=(), accelerometer=()
content-security-policy: default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://analytics.google.com/ https://www.googletagmanager.com https://www.google-analytics.com https://maps.googleapis.com https://cdn.jsdelivr.net https://unpkg.com https://*.tawk.to https://embed.tawk.to https://va.tawk.to https://www.googletagmanager.com https://www.google-analytics.com https://connect.facebook.net https://googleads.g.doubleclick.net https://www.google.com https://www.youtube.com https://www.gstatic.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://*.tawk.to; img-src 'self' data: blob: https:;; font-src 'self' data: http: https://fonts.gstatic.com https://*.tawk.to https://*.bracbank.com ; connect-src 'self' https://analytics.google.com/ https://brac-backend.singularitybd.net https://www.googletagmanager.com https://www.google-analytics.com https://cdn.jsdelivr.net/npm/antd/dist/antd.min.css.map https://maps.googleapis.com https://*.bracbank.com https://devapi.bracbank.com:* https://*.tawk.to wss://*.tawk.to https://www.google-analytics.com https://api.bracbank.com https://*.amazonaws.com https://*.cloudfront.net https://www.googletagmanager.com https://*.doubleclick.net https://connect.facebook.net https://facebook.com https://www.facebook.com https://www.google.com; frame-src 'self' https://analytics.google.com/ https://*.amazonaws.com https://*.bracbank.com https://www.youtube.com https://www.google.com https://www.googletagmanager.com https://*.tawk.to https://maps.googleapis.com; media-src 'self' https: data:; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests
strict-transport-security: max-age=63072000; includeSubDomains; preload
cross-origin-embedder-policy: unsafe-none
cross-origin-opener-policy: same-origin-allow-popups
cross-origin-resource-policy: cross-origin
link: ; rel=preload; as="style", ; rel=preload; as="style"
vary: Accept-Encoding
x-cache: Miss from cloudfront
via: 1.1 5872fbe51a27cfccc81ebb3630f75e08.cloudfront.net (CloudFront)
x-amz-cf-pop: BOM78-P11
alt-svc: h3=":443"; ma=86400
x-amz-cf-id: A_LY_ZV_K8e_RrLvOg2bVq_wt1nGuHrlaIJWTPDEWLSoKIXdkjEGYw==
BRAC Bank | Leading Private Commercial Bank in Bangladesh 






















