Certificates that renew themselves.

Issuance, renewal and expiry monitoring across every endpoint — the outage class that simply stops existing.

Auto-renewalWildcard & SANExpiry alerts
Capabilities

Certificate lifecycle, closed

Automate issuance and renewal. Eliminate gaps, reduce risk.

Auto-issuanceCertificates appear with the service — no ticket, no CSR ritual.Certs in minutes
Auto-renewalRenewals happen weeks early and verify before cutover.Expiry outages retired
Wildcard & SANSingle-name, wildcard and multi-domain certificates managed alike.
One cert, many names
Estate visibilityOne inventory of every certificate, everywhere, with expiry alerts.
Every endpoint inventoried
Private PKIAn issuing CA for internal services and mTLS.
Internal trust, managed
EV & OV optionsValidated certificates where the brand requires them.
Assurance when it matters
API issuanceIssue and revoke from pipelines and Terraform.
Certs as code
Cipher postureWeak protocols and ciphers reported estate-wide.
TLS hygiene visible
Deployment hooksRenewals push to balancers and CDN automatically.
Renewed and live
Revocation on demandCompromised keys are revoked and replaced within minutes.
Contained fast
Compare the certificates

Public, private, or watched

Issuance, renewal and expiry monitoring throughout — the difference is which trust chain the certificate belongs to.

ProductionEdgeComing soon
TIER 01Most common
Public Certificates
For everything on the internet

Publicly trusted certificates issued and renewed automatically for every public endpoint, with deployment handled at the load balancer.

Best for
Public web & APIsCustomer portalsMail and service endpoints
Where it runs
Dubai AZ1Dubai AZ2RiyadhBahrainMumbaiSingaporeAbu DhabiMilanFrankfurtNairobi
TIER 02
Private PKI
Internal trust, managed

A private certificate authority for internal services and mTLS, so east-west encryption stops depending on self-signed certificates.

Best for
Service-to-service mTLSInternal portalsDevice identity
Where it runs
Dubai AZ1Dubai AZ2RiyadhBahrainMumbaiAbu DhabiFrankfurtNairobi
TIER 03
Estate Watch
Certificates you did not issue

Discovery and expiry monitoring across every endpoint in the estate, including certificates issued elsewhere by someone who has since left.

Best for
Legacy estatesPost-acquisition sprawlAudit preparation
Where it runs
Dubai AZ1RiyadhBahrainMumbaiDubai AZ2Nairobi
Two ways to run it

Automated issuance, or managed lifecycle

Both remove the expiry outage. The difference is who owns the inventory.

Automated IssuanceSelf-serviceYour team requests certificates through the API and console; renewal and deployment happen automatically.
API-driven issuance and renewal
Automatic deployment at the edge
Expiry alerting to your channels
Best for:Teams already automating
Explore Automated Issuance plans
OR
Managed LifecycleWe own the inventorySecurity Operations holds the certificate inventory, renews everything and reports on posture across the estate.
Inventory maintained across all endpoints
Renewals executed and evidenced
Cipher and chain posture reporting
Best for:Estates that have had an expiry outage
Explore Managed Lifecycle plans
Who decides, who runs it

What each group gets from SSL

Four groups shape a cloud decision. Pick the one you belong to — the platform reads differently from each seat.

An embarrassing outage class disappeared

Certificate expiry stops being a recurring, avoidable and very public failure mode.

GovernedSovereignPredictable

FAQs

Are certificates included in the fee?
Yes — issuance and renewal are part of the service, not a separate purchase per hostname.
Do you support wildcards and SANs?
Yes, on the Plus plans, along with EV certificates where your brand requires them.
Can we issue internal certificates?
Yes — Private PKI gives you an issuing CA with API issuance and revocation for mTLS.
What about certificates issued before you arrived?
Estate Watch discovers them, monitors expiry and reports weak chains and ciphers.
How are private keys protected?
Keys are held in platform key management, with HSM-backed roots available on Private CA Plus.
How is the flat fee different from public cloud pricing?
Everything inside the plan you opt for is included — no additional charge for the components that make it up. Public clouds meter each component on consumption, so the bill moves with usage. Here the plan is reserved for you and the figure you agreed is the figure you pay.
Can we drive it from Terraform and CI?
Yes. Every operation is exposed through the REST API, CLI and a maintained Terraform provider, with scoped API keys per team. If the console can do it, your pipeline can do it.
How do limits and quotas work?
Quotas are yours to shape — carve capacity per team or project and delegate inside it. Hard ceilings are a conversation, not a wall; the estate re-baselines at thresholds you approve.
Better together

Build more around every trusted connection.

Connect SSL to the compute, networking, delivery and security services that make every digital interaction trusted.

At the core
SSL

Managed certificates become a complete trust layer when applications, traffic protection, endpoint security and governance work around them.

EncryptValidateRenewGovern
One digital trust path
IdentityEncryptionProtectionVisibilityEvidence
Noura
Noura — AI Cloud Experience Guide

Two ways Noura gets you moving

Choose the way that fits you best — Noura makes every step simple.

Not sure where to start?
Start the conversation

Describe the workload in plain language — Noura works out the tiers, sizes and protection with you.

Plain language input
Smart sizing & protection
No commitment. Just clarity.
Talk to Noura
Want to see it working?
Experience it in the marketplace

Explore CloudSouq experiences built on these services — see SSL working inside real solutions before you commit to anything.

Try real solutions
See it work in action
Commit with confidence
Explore CloudSouq
Noura is your guide at every stepfrom first question to final success.Intelligent
Guidance
Secure &
Trusted
Human
Simplicity