Certificates
SSL that renews itself, and tells you if it doesn't.
Issuance, renewal and expiry monitoring for every domain on your account. The part that usually breaks — nobody noticing a certificate lapsed — is the part we watch.
What we handle for you
Issued at provisioning
A certificate exists before your first visitor arrives. Nothing to request or install.
Renewed automatically
Renewal runs 30 days ahead of expiry, with retries, so a single failure is not fatal.
Expiry monitoring
Every certificate on the account is checked daily and surfaced on the portal timeline.
Alerts that reach you
Warnings at 30, 14 and 7 days, and immediately if an automated renewal fails.
Wildcard and multi-domain
One certificate covering every subdomain, or several names on one certificate.
Modern TLS only
TLS 1.2 and 1.3 with a hardened cipher suite. Legacy protocols are disabled by default.
HSTS and OCSP stapling
Both enabled by default, with a preload path when you are ready for it.
Auditable history
Every issuance and renewal is recorded with its date, so you can prove continuity.
Bundled cover
Longer registrations carry longer certificates
Every domain registration includes a certificate period at no extra cost. Beyond that, renewal is billed monthly and shown on the same timeline as everything else.
Certificates on hosting accounts are included for the life of the account at no charge.
Why certificates lapse
In our experience an expired certificate is almost never a billing problem. It is one of these:
- The renewal email went to a mailbox nobody reads We surface it in the console as well, where you are already looking.
- A DNS change broke domain validation We re-check validation records daily and warn before renewal is attempted.
- The automated renewal failed once and never retried Ours retries on a backoff for 30 days and escalates to a human if it keeps failing.
Stop thinking about certificates.
Every domain and hosting account we manage carries one, renewed and monitored.