SSL Certificates
The padlock,
and what's behind it.
Free DV on every Kapsule hosting plan, auto-renewed forever. Step up to OV, EV, Wildcard, or Multi-Domain when you need company identity or broader coverage. We handle the CA dance for you.
Company identity verified: visitors see who they're trusting.
Free
Let's Encrypt DV included
Under 1 hr
OV issuance time
3-7 days
EV verification window
Auto
Renewed 30 days early
What buyers see
DV proves the domain. OV + EV prove the business.
Every modern cert encrypts the connection identically. The difference is the metadata shown in certificate details. For SaaS, ecommerce checkout, regulated industries, or anywhere a buyer is comparing you to an incumbent, that named company in the cert removes friction.
Same encryption strength across all tiers
TLS 1.3, AES-256, no compromise on security level
OV / EV stamps the cert with your registered company
Sectigo verifies your company against your state business registration and the public register
EV adds public-registry verification and a CA phone callback
Used by banks, payment processors, regulated industries
Browser certificate panel
Free DV / DV Branded
Padlock only. No company name in cert details.
OV Certificate
Issued to: Kapsule Group Limited
Company name verified by CA, shown in details.
EV Certificate
Verified: Kapsule Group Limited (NZ)
Highest tier. Identity + physical location verified.
Auto-install + auto-renew
Free DV SSL, deployed and renewed without you lifting a finger
Every Kapsule hosting plan ships with free Let's Encrypt DV certificates. Provisioned automatically when DNS points at us, renewed 30 days before expiry, redeployed across all your sites and subdomains in seconds. You never log in to a CA portal.
- Auto-provision on first DNS A-record pointing to your Kapsule site
- Auto-renewed 30 days before expiry, no human in the loop
- Redeployed to all configured domain aliases automatically
- Cipher suites and TLS versions maintained current by us
SSL automation log
Auto-renewed
acme.com · 90 days remaining
Auto-provisioned
shop.acme.com · subdomain detected
Auto-renewed
kapsulecloud.com · 90 days remaining
TLS upgraded
4 sites moved to TLS 1.3 only
Auto-renewed
webmail.kapsulecloud.com · 90 days
Zero touch. All sites on your account stay current automatically.
Wildcard coverage
*.acme.comOne renewal cycle. One expiry to track.
Covers 8 subdomains
+ any future subdomain, automatically covered
Wildcard + Multi-Domain
Subdomain sprawl, multi-brand portfolios: one cert, one renewal
When your site grows beyond a single hostname, you have two choices: a separate cert per subdomain or a Wildcard / SAN that covers everything. Wildcard covers *.yourdomain.com under one DV or OV. Multi-Domain (SAN) covers up to 5 distinct domains.
- Wildcard DV: unlimited subdomains under *.yourdomain.com
- Wildcard OV: same coverage with company-identity validation
- Multi-Domain SAN: up to 5 entirely different domains, one cert
- KPanel auto-assigns the cert across all matching sites
CA dance: handled
We project-manage Sectigo. You get a live padlock.
OV issues automatically once you order. EV would normally mean assembling a dossier, generating a CSR, fielding the CA phone callback, and installing the chain. We do all of it. You confirm a few details, sign the EV subscriber agreement, take one call from the CA, and the cert lands installed across every site you own.
- Business registration + articles + business phone verification, packaged for the CA
- We submit, follow up, and project-manage to issuance
- You take ONE 5-minute call with the CA (EV only)
- Cert auto-installs across all sites within 60 seconds of issuance
CA dance: handled
How issuance works
Order to live padlock in three steps.
You order
Order any certificate directly in KPanel, just confirm the domain. DV, Wildcard, Multi-Domain, and OV all issue automatically. EV is self-serve to order too; the CA then runs its own vetting before it issues.
We verify
DV: automated email or DNS challenge, minutes. OV: automatic once DNS validates, live within minutes to an hour. EV: the CA verifies you on the public register (your state business registration), calls you back, and needs a signed subscriber agreement, typically 3-7 business days. We project-manage the entire process so you only deal with the CA once.
We install
Cert lands in KPanel. If you are on Kapsule hosting, it auto-deploys across all matching sites within 60 seconds. If you are hosting elsewhere, you get CRT + KEY + chain files to install yourself.
The seven tiers
Pick the certificate, we'll handle the rest.
Free Let's Encrypt DV is auto-installed on every Kapsule hosting plan. Paid tiers add named CA brand, company-identity validation, wildcard subdomain coverage, or multi-domain support.
| Certificate | Price | Validation | Company shown | Issuance | |
|---|---|---|---|---|---|
Free DV Included on all hosting | US$0/year | Domain | – | Minutes | See Hosting Plans |
DV Branded | US$15/year | Domain | – | Minutes | Order DV Branded |
OV CertificateMost popular | US$90/year | Organization | Minutes to an hour | Order OV | |
EV Certificate | US$210/year | Extended | 3-7 business days | Order EV | |
Wildcard DV | US$114/year | Domain | – | Minutes | Order Wildcard DV |
Wildcard OV | US$198/year | Organization | Minutes to an hour | Order Wildcard OV | |
Multi-Domain (SAN) | US$150/year | Domain | – | Minutes | Order Multi-Domain |
Bundled with every tier
What you get without thinking about it.
The tools that make SSL on Kapsule operationally invisible. From CSR generation to HSTS preload assist, the boring stuff is automated.
Auto CSR + key gen
Auto 30-day renewals
KPanel cert manager
TLS 1.3 enforced
HSTS preload assist
Chain + intermediate auto-install
Multi-domain bind
Company-name display (OV/EV)
FAQ
Frequently asked questions
More from Kapsule Protect
The rest of the stack.
Start with free. Upgrade when you need to.
Every Kapsule hosting plan includes free DV SSL. Wildcard, Multi-Domain, and OV are self-serve to order and issue automatically; EV is self-serve to order too, then the CA runs its vetting.