A site with a strict Content Security Policy (no 'unsafe-eval') loads the Braze web SDK through Google Tag Manager, one of Braze's recommended methods. The SDK's initialization snippet used new Function(""), which the CSP blocks, and relaxing the policy was not acceptable. Nonces cannot be used because the script is injected via GTM.