SSL Certificates
The padlock,
and what’s behind it.
Free DV on every Kapsule hosting plan, auto-renewed forever. Step up to OV, EV, Wildcard, or Multi-Domain when you need company identity or broader coverage. We handle the CA dance for you.
Company identity verified: visitors see who they’re trusting.
Free
Let's Encrypt DV included
1-3 days
OV issuance time
3-7 days
EV verification window
Auto
Renewed 30 days early
What buyers see
DV proves the domain. OV + EV prove the business.
Every modern cert encrypts the connection identically. The difference is the metadata shown in certificate details. For SaaS, ecommerce checkout, regulated industries, or anywhere a buyer is comparing you to an incumbent, that named company in the cert removes friction.
Same encryption strength across all tiers
TLS 1.3, AES-256, no compromise on security level
OV / EV stamps the cert with your registered company
Sectigo confirms NZBN, calls a public business directory
EV adds a video verification call with the CA
Used by banks, payment processors, regulated industries
Browser certificate panel
Free DV / DV Branded
Padlock only. No company name in cert details.
OV Certificate
Issued to: Kapsule Group Limited
Company name verified by CA, shown in details.
EV Certificate
Verified: Kapsule Group Limited (NZ)
Highest tier. Identity + physical location verified.
Auto-install + auto-renew
Free DV SSL, deployed and renewed without you lifting a finger
Every Kapsule hosting plan ships with free Let's Encrypt DV certificates. Provisioned automatically when DNS points at us, renewed 30 days before expiry, redeployed across all your sites and subdomains in seconds. You never log in to a CA portal.
- Auto-provision on first DNS A-record pointing to your Kapsule site
- Auto-renewed 30 days before expiry, no human in the loop
- Redeployed to all configured domain aliases automatically
- Cipher suites and TLS versions maintained current by us
SSL automation log
Auto-renewed
acme.co.nz · 90 days remaining
Auto-provisioned
shop.acme.co.nz · subdomain detected
Auto-renewed
kapsulecloud.com · 90 days remaining
TLS upgraded
4 sites moved to TLS 1.3 only
Auto-renewed
webmail.kapsulecloud.com · 90 days
Zero touch. All sites on your account stay current automatically.
Wildcard coverage
*.acme.co.nzOne renewal cycle. One expiry to track.
Covers 8 subdomains
+ any future subdomain, automatically covered
Wildcard + Multi-Domain
Subdomain sprawl, multi-brand portfolios: one cert, one renewal
When your site grows beyond a single hostname, you have two choices: a separate cert per subdomain (more renewals, more to track) or a Wildcard / SAN that covers everything. Wildcard covers *.yourdomain.com under one DV or OV. Multi-Domain (SAN) covers up to 5 distinct domains. Either way: one renewal, one expiry to track.
- Wildcard DV: unlimited subdomains under *.yourdomain.com
- Wildcard OV: same coverage with company-identity validation
- Multi-Domain SAN: up to 5 entirely different domains, one cert
- KPanel auto-assigns the cert across all matching sites
CA dance: handled
We project-manage Sectigo. You get a live padlock.
OV / EV would normally mean assembling a dossier, generating a CSR, scheduling a CA verification call, and installing the chain. We do all of it. You confirm a few details, take one phone call, and the cert lands installed across every site you own.
- NZBN + articles + business phone verification, packaged for the CA
- We submit, follow up, and project-manage to issuance
- You take ONE 5-minute call with the CA (EV only)
- Cert auto-installs across all sites within 60 seconds of issuance
CA dance: handled
How issuance works
Order to live padlock in three steps.
You order
Pick a tier in KPanel or hit one of the order buttons. For OV / EV we send you a one-page document checklist (NZBN, articles, business phone). For DV: nothing, just confirm the domain.
We verify
DV: automated email or DNS challenge, minutes. OV: CA calls your business phone, 1-3 business days. EV: video call with the CA, 3-7 business days. We project-manage the entire process so you only deal with the CA once.
We install
Cert lands in KPanel. If you are on Kapsule hosting, it auto-deploys across all matching sites within 60 seconds. If you are hosting elsewhere, you get CRT + KEY + chain files to install yourself.
The seven tiers
Pick the certificate, we’ll handle the rest.
Free Let's Encrypt DV is auto-installed on every Kapsule hosting plan. Paid tiers add named CA brand, company-identity validation, wildcard subdomain coverage, or multi-domain support.
| Certificate | Price | Validation | Company shown | Issuance | |
|---|---|---|---|---|---|
Free DV Included on all hosting | $0/year | Domain | – | Minutes | See Hosting Plans |
DV Branded | $25/year | Domain | – | Minutes | Order DV Branded |
OV CertificateMost popular | $149/year | Organisation | 1-3 business days | Order OV | |
EV Certificate | $349/year | Extended | 3-7 business days | Order EV | |
Wildcard DV | $189/year | Domain | – | Minutes | Order Wildcard DV |
Wildcard OV | $329/year | Organisation | 1-3 business days | Order Wildcard OV | |
Multi-Domain (SAN) | $249/year | Domain | – | Minutes | Order Multi-Domain |
Bundled with every tier
What you get without thinking about it.
The tools that make SSL on Kapsule operationally invisible. From CSR generation to HSTS preload assist, the boring stuff is automated.
Auto CSR + key gen
Auto 30-day renewals
KPanel cert manager
TLS 1.3 enforced
HSTS preload assist
Chain + intermediate auto-install
Multi-domain bind
Company-name display (OV/EV)
FAQ
Frequently asked questions
More from Kapsule Protect
The rest of the stack.
Free SSL on every hosting plan.
Let's Encrypt DV SSL is auto-installed and auto-renewed on every Kapsule hosting plan. Order paid tiers from $25/year when you need named CA, OV, EV, Wildcard, or Multi-Domain.