Let's Encrypt, on autopilot

Every certificate issued, renewed and installed. Automatically.

NeverLapse gets free Let's Encrypt certificates through your DNS, renews them before they expire, and puts them where they belong: IIS, Exchange, Windows services, Apache, HAProxy, OPNsense and Veeam. One web console for all of it, on your own server.

30 days free. No credit card. Installs on Windows Server in minutes.
Why

Certificate lifetimes keep getting shorter

Public certificates are heading to 47-day lifetimes. Renewing by hand every few weeks across dozens of servers isn't a plan. Let a service do it, the same way every time, and tell you only when something needs you.

Hands-off renewals

A Windows service checks every certificate daily, renews inside your window and redeploys everywhere it's used.

Deploys where it's used

Pushes to Windows and IIS, or lets lightweight pull agents fetch it on Windows and Linux, even behind firewalls.

Stays on your network

Runs on your own server with your own SQL database. Private keys never leave your environment.

Works with

The DNS and servers you already run

DNS-01 validation means no open ports and wildcard certificates out of the box. Point it at your DNS provider and choose where each certificate goes.

All features
DNS providers
Cloudflare GoDaddy Windows DNS / Active Directory BIND (RFC 2136 + TSIG)
Deployment targets
Windows (domain or workgroup) IIS site bindings Exchange Linux Apache HAProxy (SNI folders) OPNsense HAProxy Veeam Cloud Connect Your own script
Getting started

Up and running in an afternoon

Start a trial

Enter your email; the license key and download link arrive right away.

Install

One installer on Windows Server sets up the web console, the service and (optionally) SQL Express.

Add a domain

Pick the DNS provider, add the names and wildcards. Issue it once with a click.

Point it at servers

Add hosts or install an agent. From then on renewals and deployments happen by themselves.