PCI Scan Vulnerability - HSTS Missing From HTTPS Server

After a PCI scan, a failure emerged that requires additional information. This information would confirm that port usage doesn't encompass credit card processing and isn't intended for public use, thus negating the need for HSTS headers.

Any suggestions on how to acquire this information? Can Shopify supply a statement to address this?


