Skip to content

About

Certificates should renew themselves. So we made them.

DelegatedSSL exists to delete one specific, recurring failure mode: the expired certificate on a domain you manage for someone else. The fix — delegate validation once through a stable CNAME — is old idea, done properly, for the people who feel the pain most.

For the teams who hold the pager.

Agencies, MSPs and hosting resellers don't own their clients' DNS — but they own the consequences when a certificate lapses. Classic ACME forces a fresh proof of control on every renewal, which means every domain is a recurring ticket, a chased email, or an outage waiting to be noticed by a browser warning.

DelegatedSSL turns that recurring proof into a one-time delegation. The client publishes a single _acme-challenge CNAME; issuance and renewal handle themselves from there. You get a clean console, an API to automate on, and a page you can hand to a client under your own brand.

We hold no private keys and store no plaintext secrets. When something isn't verified, we say so — we never manufacture a green checkmark.

Delegate, don't babysit

The whole product exists to remove a recurring chore. Configure trust once; let the machine keep it green.

Fail closed, always

Missing config, an unverified domain, a placeholder secret — every one is treated as not-ready. We never fake an 'active' state.

API-first

Everything the console does, the API does. Agencies automate their own onboarding on top of DelegatedSSL.

Your brand, not ours

The people your clients see should be you. White-label is a first-class surface, not an upsell afterthought.

Built by Pcnaid Inc.

Part of a family of infrastructure products for operators.

DelegatedSSL is built and operated by Pcnaid Inc. — the same team behind a portfolio of production tools for agencies, merchants and platform teams. We build software we'd want to run on a pager ourselves.