Everything it takes to never think about certificates again
Every plan includes every feature. Plans only differ in how many certificates and hosts you manage.
Issue and renew
Let's Encrypt via DNS-01
No inbound ports needed, works for internal-only names, and supports wildcards and multi-name (SAN) certificates.
Daily renewal check
Renews inside the window you choose (for example 30 days before expiry) at the time of day you choose.
Checks DNS before it asks
Confirms the challenge record is visible on the authoritative name servers before validating, so split DNS doesn't cause failures.
Revocation and export
Revoke a certificate at the CA, or download it as a password-protected PFX when you need it somewhere by hand.
Deploy
Windows push
Installs into the machine store over WMI on domain or workgroup servers, then updates IIS bindings by site and port.
Pull agents
A small Windows service or Linux agent (Apache, HAProxy SNI folders, or your own script) fetches its certificates over HTTPS. Nothing has to reach in.
Several certificates per host
One HAProxy or Apache box can carry many certificates, each going to the right place.
Appliances and apps
OPNsense HAProxy over its API, Veeam Cloud Connect, Exchange, and the web console's own certificate.
Secure and manageable
Your server, your database
Runs on Windows Server with SQL Server (Express is fine). Secrets are encrypted at rest.
Single sign-on and MFA
SAML 2.0 with Entra ID, Okta, Google and others, plus authenticator-app MFA for password sign-ins.
Alerts that matter
Email when an issue, renewal or deployment fails, and not when everything worked.
One installer
Sets up the console, the service and optional SQL Express, and upgrades in place without losing settings.
System requirements
Windows Server 2016 or later for the console and service (tested on 2022 and 2025); SQL Server, or the SQL Express the installer can set up; outbound HTTPS to Let's Encrypt, your DNS provider and our license server. Linux agent: x86_64 with systemd (bash fallback for older systems).