UnifySSL
A control plane for a fleet of domains — automatic SSL and edge routing managed from one place, with a built-in edge firewall, rate limiting and bot scoring protecting every site behind it.
- 17M+
- threats blocked at the edge
- Automatic SSL
- issued and renewed across the fleet
- Edge firewall
- IP, network, country, path and bot rules
The problem
Run a lot of apps and you end up with a lot of domains — each needing a security certificate, renewals, routing, and protection from the constant background noise of bad traffic. Keeping all of that configured by hand across many servers is error-prone and doesn't scale. UnifySSL turns it into one place you manage it all from, with a real security layer built in rather than bolted on.
What it does
Add a domain and its certificate is issued and kept renewed automatically, with its traffic routing handled for you — nothing edited by hand on a server. Change one setting in one place and it takes effect across every edge server, and a bad change can be rolled back in a click.
Every site behind it sits behind an edge firewall you control: block or allow traffic by IP address, network range, whole network operator, or country; rate-limit abusive callers; and stop requests to paths that should never be public. It scores incoming requests for how bot-like they look and can challenge or block the suspicious ones.
It goes beyond certificates into running the fleet: buy a domain and manage its DNS from the same console, provision new edge servers across more than one cloud, migrate a site from one server to another, and adopt an existing domain into the system and standardize how it's configured. Everything is role-based, and every change is written to an audit log.
Key features
Certificates that renew themselves
Certificates issue and renew automatically across the whole fleet, so nothing expires by surprise and takes a site down at the worst moment.
An edge firewall you actually control
Block or allow traffic by IP, network range, network operator or country, and shut off requests to paths that should never be public — so a site isn't defenceless against the obvious bad actors.
Rate limiting and bot scoring
Abusive callers are throttled and each request is scored for how bot-like it looks, so a small site gets a real filter against automated abuse without running its own security stack.
Only serve the paths you meant to
It can learn the paths a site is actually supposed to expose and treat anything outside that set as suspect — a positive-security approach that closes off routes an attacker probes for, rather than chasing each one.
Manage the whole fleet — and its DNS — from one place
Domains, routing, certificates, even buying a domain and editing its DNS happen centrally rather than server by server, so a growing fleet doesn't become a config-file archaeology project.
One-click rollback
A bad change can be undone instantly across every edge server — with rollback for routing, for a server's whole configuration, and for a migration that went wrong — instead of racing to fix each machine by hand.
Roles, audit, and multi-tenant scoping
Team members get scoped roles, outside customers see only their own domains, and every change is written to an audit trail — so it's a real product serving more than one organisation, not a private script.
Where it stands
Honest about its edges: it's an edge firewall and rate limiter, not a volumetric DDoS-mitigation service or a deep payload-inspecting WAF, and it doesn't run CAPTCHAs. Operational alerting is available but off by default. The security value is in the controls it does enforce — network, geography, path, rate and bot rules — applied consistently across a whole fleet.
Under the hood — for the technically-minded
How it's built
A central control plane is the single source of truth for every domain, certificate, routing rule and firewall policy. Edge servers pull their configuration from it, so operators manage the whole fleet from one place rather than touching each machine — and can roll a bad change back across all of them at once.
The protective layer lives at the edge, where traffic actually arrives: request filtering, rate limiting, network- and geography-based rules, path controls and bot scoring are applied before a request reaches the app behind it. The learned path-allowlist is checked with active self-test probes, so the system verifies its own rules rather than trusting them blindly.
The heavy lifting is underneath the UI: custom-built components let certificates, routing and policy live in a database and be applied consistently across the fleet, with domain registration, DNS and multi-cloud server provisioning wired into the same console.
The hard problems
One change across a whole fleet
Operators change one record centrally; every edge server picks it up and applies it, and certificates issue and renew on their own — instead of editing configuration machine by machine and hoping it stays in sync. Three distinct rollback paths (routing, full server config, and migration) mean a mistake at any level is reversible.
Security that's positive, not just reactive
Beyond blocklists, it learns the set of paths a site is meant to serve and treats the rest as suspect, backed by active self-test probes that check the rules hold — so it closes off what an attacker looks for rather than only reacting to what they've already tried.
Certificates only for domains you actually own
Automatic issuance is convenient but easy to abuse. Here it's gated: a server only obtains a certificate for a domain that's been verified as belonging to a real tenant — safe by default.
Built with
- Remix
- Go
- Postgres
- Redis
Building something in this space?
Work with us →