SSL certificates
The padlock, installed and never expired.
We issue the certificate, install it, move every visitor onto HTTPS and renew it long before the date - on any site and any server.
Get a quoteWhat "installed properly" means
A certificate on the server is the start. These are the parts that make visitors, browsers and search engines trust the site.
- Every address coveredThe domain with and without www, and every subdomain with a wildcard certificate.
- HTTPS forcedOld http links redirect to the secure address, once, without a loop.
- No mixed contentImages and scripts loading over http are found and fixed, so the padlock does not break on some pages.
- Modern encryptionOld protocols switched off and a strict HTTPS policy sent, so browsers never fall back.
- Renewed on timeRenewal runs by itself weeks ahead, and a daily check tells us if it ever fails.
- Any serverSites we host get it as standard; we install it on yours, wherever it runs.
Which kind of certificate fits
Certificates differ in how much is checked before they are signed and in which names they cover. The encryption is the same in all of them; what changes is the proof behind the padlock.
| What you want to know | DVDomain validated | OVOrganisation validated | EVExtended validation | WildcardEvery subdomain at one level | Multi-domainSeveral names in one certificate |
|---|---|---|---|---|---|
| What is checked | Control of the domain name | Domain control, plus the legal organisation and its address | Domain control, plus the strictest documented vetting of the legal entity | Control of the domain, proven with a DNS record | Control of every name on the list, each checked on its own |
| Names covered | The names listed on it | The names listed on it | The names listed on it | Any subdomain at one level, such as shop or blog; the bare domain is listed beside it | Several different names and domains in one certificate |
| Typical time to issue | Minutes, fully automated | Hours to days, people review documents | Days, the longest manual review | As quick as its validation level, once the DNS record is in place | Set by its strictest name to validate |
| Same encryption strength | Yes | Yes | Yes | Yes | Yes |
| Organisation named in the certificate | No | Yes | Yes | Depends on its validation level | Depends on its validation level |
| Best for | Websites, shops, blogs and APIs; the everyday choice | Companies that want their verified name inside the certificate | Regulated or high-trust organisations; browsers no longer give it a special address-bar display | Sites with many subdomains, or ones added often | A few related sites under one certificate |
Wildcard and multi-domain say which names a certificate covers. DV, OV and EV say how much was checked about who asked for it. The two choices are made separately. Not sure which one fits? Send us the address.
General facts, from the CA/Browser Forum Baseline Requirements and the Let's Encrypt documentation. Which type your site needs, we confirm when we quote it.
The life of a certificate, start to end
A certificate is not installed once and forgotten. It has a beginning, a working life and an end, and every stage has someone watching it. This is the order things happen in.
-
Day one
Issue
The certificate authority checks that the domain is really yours, with a file on the site or a DNS record for a wildcard, and then signs the certificate. We handle the request.
-
Day one
Install
We place it on the server, cover the domain with and without www, send old http links to the secure address and fix anything still loading over http.
-
Weeks before expiry
Renew
Renewal runs by itself, 30 days before the certificate expires, so one slow day never turns into an expired padlock.
-
Every day
Expiry alert
A daily check reads the expiry date. If a renewal ever fails, we hear about it weeks before any visitor would see a warning.
-
Only if needed
Revoke
If the private key is exposed or the certificate was issued for the wrong details, the authority marks it untrusted before its date. A new certificate is then issued and installed the same way as the first.
The CA/Browser Forum limits how long a public certificate may last: 200 days since March 2026, 100 days from March 2027 and 47 days from March 2029. The shorter the life, the more often this cycle repeats, and a date kept by hand is a date waiting to be missed.
See how the server around the certificate is protected
Send us the address
Tell us the domain and where the site runs. We will tell you what it needs and quote it the same day.
Get a quoteQuestions and answers
Do the sites you host get SSL included?
Yes. Sites we host get a certificate as standard, renewed automatically. We also install and renew certificates on sites that run elsewhere.
When are certificates renewed?
Renewal runs by itself 30 days before a certificate expires, and a daily check of the expiry date tells us if a renewal ever fails.
Can one certificate cover all my subdomains?
Yes. A wildcard certificate covers every subdomain. The certificate authority checks a DNS record on the domain before it signs one.
What is the difference between DV, OV and EV?
How much the authority checks about who asked for the certificate. The encryption is the same in all of them; what changes is the proof behind the padlock.