How it works

How BrandSSL works.

On demand SSL secures the domains your customers point at your platform. Connect writes the DNS for them at their registrar. Pick a product to see it end to end.

Secure your customers' vanity domains automatically.

BrandSSL uses a globally distributed reverse proxy to watch for unsecured traffic and issue SSL certificates at the edge. A customer may want their own domain, for example shop.acme.com, to point to your application app.saas.com.

Whenever insecure traffic is detected on the network, BrandSSL begins issuing a certificate and routes the request to your endpoint, switching from HTTP to HTTPS once the process is complete.

$ point any domain at 142.93.54.52 or my.brandssl.io
shop.acme.com
Your customer's domain
HTTP
BrandSSL edge validates and issues
shop.acme.com
Secured and routed to your application
HTTPS · TLS 1.3

Five minutes to live

After creating an account, you provide your application endpoint, the place we send your customer requests to, for example app.saas.com. You also provide a CNAME record your customers will point to, for example ssl.saas.com.

Once that is set up, we supply you with an IP address for your end customers, so they can point to your application with an A record.

Full control of every certificate

Manage your SSL certificates and customize your settings. Change your application endpoint, set a default certificate authority, and configure Cloudflare settings when your CNAME is proxied.

Append multiple custom headers with dynamic values to your traffic, along with URL rewrites.

Performance and reliability as a standard

Our globally distributed infrastructure is designed for reliability, delivering the highest standard of SSL security every minute of the day.

500k+
Custom domains secured
Millions
Of requests served daily
99.99%
Service uptime

Frequently asked questions

Have a question not covered here? Reach out to sales@brandssl.io

All certificates are validated and issued within a few seconds.
Yes, as long as the domain owner adds a DNS entry pointing to the service. Apex (root) and subdomains are secured automatically.
Namecheap, GoDaddy, Hostinger and more, with new registrars added regularly. Domains at any other provider can be connected by adding the records manually.
Yes. With BrandSSL's Custom SSL feature you can upload your own certificates. See our API documentation for instructions on how to upload, update and remove them.
Yes. As part of signing up we ask you to point a CNAME at our service, for example app.yourdomain.com to a BrandSSL domain. The app.yourdomain.com is what your clients use and add to their DNS.
No. While BrandSSL is provisioning the service we send the traffic as HTTP and then transition to HTTPS once the SSL certificate is in place.
BrandSSL automatically renews and manages the SSL certificates.

Ready to secure your customers' domains?

Try BrandSSL free for three days. Cancel anytime.

Start Free Trial