Account · SSL & Security
4 certificates, all auto-renewing.
Free wildcard SSL, DDoS mitigation, and account-wide two-factor.
4
Certificates
100%
Auto-renew
2FA
Enforced
0
Open findings
| Domain | Type | Status | Expires |
|---|---|---|---|
| yourbrand.com | Wildcard | Valid | Jul 18, 2027 |
| studio.co | Single host | Valid | Sep 30, 2026 |
| tallgrass.records | Wildcard | Valid | Mar 22, 2027 |
| nordlys.studio | Single host | Valid | Dec 04, 2026 |
DDoS mitigation
Volumetric and application-layer filtering on every plan.
Auto-renewal
Certificates renew 30 days before expiry with rollback.
Two-factor
TOTP and hardware keys enforced across every seat.
Seats & roles
| Member | Role | MFA | Last active |
|---|---|---|---|
| alex@yourbrand.com | Owner | YubiKey | 2m ago |
| jules@yourbrand.com | Admin | YubiKey | 1h ago |
| ops@yourbrand.com | Deployer | TOTP | Today |
| billing@yourbrand.com | Read-only | TOTP | 3d ago |
Recent security events
2h ago
SSL auto-renewed
yourbrand.com wildcard · valid through Jul 18, 2027
Yesterday
Sign-in from new device
Approved from MacBook · San Antonio, TX
4d ago
Recovery codes regenerated
10 new codes issued to owner account
9d ago
Vulnerability scan complete
0 critical · 0 high · 2 informational
// audit.stream
Signed audit trail, always on
Every sign-in, permission change, DNS write, and mailbox creation is captured, signed, and forwarded to your SIEM by the platform. Nothing to wire up — the gateway ships it for you.

DDoS mitigation
Volumetric and application-layer filtering up to 500 Gbps on every plan.
Auto-renewal
Certificates renew 30 days before expiry with rollback if the new cert fails ACME.
Hardware keys
WebAuthn/FIDO2 enforced per role — YubiKey, Titan, Passkeys supported.
Vulnerability scans
Weekly external scans of every site with severity-scored findings.
IP allow-lists
Restrict panel and SSH access to named CIDR ranges per team.
Role-based access
Owner, Admin, Deployer, Billing, Read-only — with per-product overrides.
How are certificates issued?+
Let's Encrypt via ACME by default, ZeroSSL as an automatic fallback. Bring your own paid EV cert if compliance requires it.
Do you support SSO?+
Yes. SAML 2.0 and OIDC with Google Workspace, Okta, Microsoft Entra, JumpCloud, and generic providers. SCIM 2.0 for user provisioning.
What logs are retained?+
Sign-in and admin events for 400 days, DNS writes for 90 days, mail delivery events for 30 days. Longer retention available on Enterprise.
Can I enforce recovery-code print-outs?+
Yes. Admins can require recovery-code confirmation before enabling any privileged role and revoke the codes at will.