About
Certificates should renew themselves. So we made them.
DelegatedSSL exists to delete one specific, recurring failure mode: the expired certificate on a domain you manage for someone else. The fix — delegate validation once through a stable CNAME — is old idea, done properly, for the people who feel the pain most.
For the teams who hold the pager.
Agencies, MSPs and hosting resellers don't own their clients' DNS — but they own the consequences when a certificate lapses. Classic ACME forces a fresh proof of control on every renewal, which means every domain is a recurring ticket, a chased email, or an outage waiting to be noticed by a browser warning.
DelegatedSSL turns that recurring proof into a one-time delegation. The client publishes a single _acme-challenge CNAME; issuance and renewal handle themselves from there. You get a clean console, an API to automate on, and a page you can hand to a client under your own brand.
We hold no private keys and store no plaintext secrets. When something isn't verified, we say so — we never manufacture a green checkmark.
Delegate, don't babysit
The whole product exists to remove a recurring chore. Configure trust once; let the machine keep it green.
Fail closed, always
Missing config, an unverified domain, a placeholder secret — every one is treated as not-ready. We never fake an 'active' state.
API-first
Everything the console does, the API does. Agencies automate their own onboarding on top of DelegatedSSL.
Your brand, not ours
The people your clients see should be you. White-label is a first-class surface, not an upsell afterthought.
Built by Pcnaid Inc.
Part of a family of infrastructure products for operators.
DelegatedSSL is built and operated by Pcnaid Inc. — the same team behind a portfolio of production tools for agencies, merchants and platform teams. We build software we'd want to run on a pager ourselves.