SSL

SSL certificates

Paid DV when you need an invoice, a trust seal and a warranty. The free one is right next to it, one click away.

Check your site

A real connection to the server, not a record in someone’s database: “issued” and “a working certificate is installed” are different things.

Check the certificate

Four states, not “has SSL or doesn’t”

HTTPS isn’t working

Red only if the domain actually responds on port 80. We don’t scare a parked domain or a mail-only domain.

Our free certificate, active

Renews itself. Nothing for you to do.

Certificate from another provider

The certificate works. We can watch its expiry for free.

Certificate problem

Expiring soon, name mismatch, incomplete chain or an outdated TLS version: a specific button for a specific reason.

Which certificate to choose

People buy paid DV for the invoice their accounts need, the trust seal on the payment page, the certificate authority’s warranty and support that answers for the expiry date. The encryption is the same, and we say so plainly: if you need none of that, the free one is enough.

First subscription year price; after that, standard rates apply. Prices exclude VAT.

DV

—

first subscription year

We reissue the certificate automatically — nothing for you to do.

Same encryption as the free one.

Confirms the domain is yours.

  • An invoice, a contract and a delivery note for your accounts.
  • A trust seal for your payment page.
  • A certificate authority warranty.
  • Support that answers for the expiry date.

When you don’t need it: if your free one works.

OV

—

first subscription year

We reissue the certificate automatically — nothing for you to do.

The certificate contains your verified organisation name. Verification takes 3–5 business days.

O = Kava LLC, Kyiv, UA

Your organisation details are already filled in from your profile and the state register. Each year you just confirm, nothing to re-enter.

When you don’t need it: if visitors don’t care to see the company name in the certificate.

EV

—

first subscription year

We reissue the certificate automatically — nothing for you to do.

Extended organisation validation. Nothing changes visually in the browser.

Needed if a regulator or a counterparty requires it.

Let’s Encrypt

Free

Included by default. Issued and reissued automatically, wildcard included, when the domain uses our NS.

We reissue the certificate automatically — nothing for you to do.

If that is enough for you, take the free one — that is fine.

Installation and lifetime

Common questions

Is the free certificate really the same as a paid one?

The encryption — yes, identical. A paid one differs in the certificate authority warranty, organisation representation (OV/EV) and compatibility with older systems.

Does a paid certificate protect better?

No. We never say “a higher class of protection”. That’s technically wrong. A paid one gives a certificate authority warranty, an organisation name in the certificate (OV/EV) or compatibility with older systems, not stronger encryption.

People say a free certificate is worse for Google. Is that true?

No. Google treats HTTPS as a lightweight ranking factor and does not use it for indexing at all, and the type or price of the certificate makes no difference to rankings — DV, OV and EV are equal in search. We do not sell a paid certificate as a way to rank higher. What does affect search is an expired certificate: the browser shows a warning and the site loses visitors. That is exactly why we reissue it automatically.

I have several subdomains. Do I need a wildcard?

Most often the free Let’s Encrypt wildcard is enough: it’s automatic when the domain is on our NS. A paid wildcard makes sense only for the same reason as a paid DV.

I already have a certificate from another provider. What happens?

We see it during the check and can watch its expiry for free, without changing anything.