xss protection in AEM
Is AEM completely xss secure. I know using HTL makes sure that you're protected from xss. But what about ajax calls? Responses returned from Servlets?
In other words, are there areas or flows where it's up to the site developer to implement xss protection mechanisms?
Thanks.