The site frameworks now include additional content security policy headers.
In the subsite settings you can enable framing, and add a list of URLs which will appear as sources in the site's CSP frame-ancestors (opens new window) header. The report-to directive has also been added which will be recorded in our hosting logs.