HTTPS on by default, paid certificates when you need them.
Every hosting plan issues a free certificate automatically and renews it 30 days before expiry. Buy a paid certificate only when you need a warranty, a site seal or organisation validation.
Free
Let's Encrypt on every plan
30 days
Renewal lead time
Wildcard
Available with DNS-01
256-bit
Encryption throughout
DV SSL
Domain validated, issued in minutes
৳0/year
✓Single domain
✓Issued in minutes
✓256-bit encryption
✓Browser trusted
Wildcard SSL
Every subdomain, one certificate
৳0/year
✓Unlimited subdomains
✓OV validation
✓Site seal
✓$250,000 warranty
VAT is added at checkout where it applies. Upgrade at any time — we bill the difference pro rata.
Certificate comparison
Certificate
Validation
Covers
Warranty
Issued in
Annual price
AutoSSL
Domain
Domain + www
—
Minutes
Free
DV SSL
Domain
Single domain
—
Minutes
৳1,800
Wildcard SSL
Organisation
*.yourdomain
$250,000
1–3 days
৳9,800
What you get
On every plan.
⚙️
Issued at provisioning
The certificate is requested as a step of the provisioning job, so HTTPS works before you first log in.
🔁
Renewal that is watched
Renewal starts 30 days out. A failed challenge is re-queued and raised to a person, not left to lapse.
🌿
Wildcards via DNS-01
Because we run your DNS, a wildcard validates without you touching a TXT record.
🏢
OV and EV when required
For finance and government tenders that ask for organisation validation, we handle the vetting paperwork.
🧪
Mixed-content help
We show which assets still load over http:// so the padlock actually appears.
🔐
HSTS when you are ready
Available as a switch, deliberately not the default — HSTS is hard to undo.
Questions
Common questions.
If SSL is free, why sell certificates?+
Let's Encrypt issues domain-validated certificates, which is the right choice for most sites. A paid certificate adds organisation validation, a warranty and a site seal — things some tenders and payment processors require.
My certificate is valid but there is no padlock.+
Something on the page is still loading over http://. The browser console lists every blocked request; fixing the source URLs — usually old image paths in a database — restores the padlock.
Why did issuance fail?+
The two common causes are a CAA record that does not permit the issuer, and a domain that does not yet resolve to us. Both are named explicitly on the provisioning job rather than shown as a generic failure.
Do I need a wildcard?+
Only if you serve many subdomains or create them dynamically. For a handful of fixed names, a single certificate with SANs is simpler and free.
Already included.
Buy hosting and HTTPS is configured before you log in. Add a paid certificate only if you need one.