Cybersecurity & Digital Protection · Hardening

SSL Certificate Setup

HTTPS across every page, with renewals nobody has to remember

Buy now

$299USD one-off

One payment. Work starts once we have confirmed your requirements.

The four questions this page answers

  1. 1

    What you buy

    A one-off remote job that puts a valid certificate on your domain, sends every visitor to the secure address, and clears the leftovers that stop the padlock appearing.

  2. 2

    What you get

    5 deliverables, listed in full below

    • A valid certificate installed and serving on your domain and www variant
    • Automatic renewal configured and demonstrated, not merely enabled
    • Site-wide redirection to the secure address, with mixed content cleared
    + 2 more
  3. 3

    How it is delivered

    Remote Setup

    Carried out remotely by our team. Nothing is posted and no one visits.

    REMOTE SERVICE

  4. 4

    How long it takes

    2–3 business days from receipt of registrar and hosting access

    Measured from the point everything under “what we need from you” is with us, not from the moment you pay.

A valid certificate, an encrypted connection and every old link redirected to https — illustrative concept, not a screenshot of a client system
A valid certificate, an encrypted connection and every old link redirected to https. Illustrative interface concept — not a screenshot of a client deployment.

What is this, in plain English?

A one-off remote job that puts a valid certificate on your domain, sends every visitor to the secure address, and clears the leftovers that stop the padlock appearing.

The Cloud Setup Package covers certificates as one part of building new hosting. This is the standalone version for a site already running: issue and installation, automatic renewal that is actually tested, redirects from the insecure address, and the mixed-content tracing that is usually the real reason a browser still complains.

The problem it solves

Visitors see a warning before they see your site, the padlock is missing on some pages but not others, and the last certificate expired without anyone noticing until a customer said so.

If that does not describe you, this is probably the wrong product. Tell us and we will point you at a better fit rather than sell you the nearest one.

What you get

The concrete things that exist at the end and that you own.

5 deliverables

  • A valid certificate installed and serving on your domain and www variant
  • Automatic renewal configured and demonstrated, not merely enabled
  • Site-wide redirection to the secure address, with mixed content cleared
  • Expiry alerting to a contact of your choosing
  • A short written record of the certificate, its renewal method and where the alerting goes

What's included

The work covered by the figure in the buy box, at no extra cost.

  • One domain plus its www variant
  • Certificate issue and installation
  • Automatic renewal setup and a tested renewal
  • Redirect configuration and chain flattening
  • Mixed content tracing and correction
  • Expiry alerting and a written handover note

Not seeing something you expected? Check what you are not buying before you order.

What does it do?

Everything listed here is delivered as part of this product. Nothing on this list is aspirational.

  • Certificate issued and installed for your domain and its www variant
  • Automatic renewal configured, then tested by forcing a renewal rather than assuming one
  • Every insecure request redirected to the secure address, with redirect chains flattened
  • Mixed content traced through templates, page content and the database, then corrected
  • HTTP Strict Transport Security applied at a policy that can still be backed out of
  • Expiry alerting sent to an address you nominate, independent of the host
  • A post-change check of the certificate chain and negotiated protocols

How it works

The delivery sequence from order to handover.

  1. 1

    Check what exists

    We look at the current certificate, the DNS, the host’s capabilities and where insecure content is coming from.

  2. 2

    Issue and install

    The certificate is issued for the agreed names and installed, with the full chain served correctly.

  3. 3

    Force the secure address

    Redirects are set at server level, internal links updated, and the canonical address made consistent.

  4. 4

    Clear mixed content

    Insecure images, scripts and stylesheets are traced and fixed, including references stored in the database.

  5. 5

    Prove the renewal

    A renewal is triggered deliberately to confirm it works, and expiry alerting is pointed at your contact.

Delivery & fulfilment

Stream Edge Solutions ships nothing. Every package on this site is carried out and handed over remotely — this is exactly what happens after you order.

REMOTE SERVICEHow this is delivered
  1. 1We confirm requirementsWe read what you sent with the order, come back in writing with anything missing, and agree the scope before any chargeable work starts.
  2. 2We build and configure remotelySetup, configuration and testing are done by our team over a remote connection — on your systems or on ours, whichever the package specifies.
  3. 3We hand it overYou receive the working setup, the credentials, the documentation and a walkthrough. Everything built for you is yours at handover.

Carried out remotely by our team. Nothing is posted and no one visits. Typical turnaround: 2–3 business days from receipt of registrar and hosting access.

Delivery method
Remote Setup
Expected delivery time
2–3 business days from receipt of registrar and hosting access
Measured from the point everything under “what we need from you” is with us — not from the moment you pay.

Full detail of how work is handed over, what happens if requirements are outstanding and how order records are kept is in the Delivery & Fulfilment Policy.

What we need from you

Nothing starts until these are in place, and the turnaround above is measured from that point — not from the moment you pay.

  • Access to your domain registrar or DNS provider
  • Hosting or server access sufficient to install a certificate
  • A decision on whether a free automated certificate or a paid one is wanted
  • A short maintenance window, since redirects change how every page is served

Who this is for

  • Businesses whose certificate has expired or was never installed
  • Sites showing a browser warning or a partial padlock
  • Owners who moved host and lost their certificate in the process
  • Anyone collecting form submissions or logins over an insecure connection

Business needs this addresses: Build an online presence, Improve IT infrastructure

What's not included

Just as plainly as the list above: the things this package is not.

  • The cost of a paid, wildcard or extended-validation certificate, which you buy from the issuer directly
  • Hosting plans that do not permit a custom certificate; if yours does not, we tell you before taking payment
  • Third-party embeds that only offer an insecure version, which their vendor must fix
  • The wider hardening work; a certificate protects data in transit and nothing else
  • Ongoing certificate management after handover, which the support plans cover

Anything outside the scope above is quoted separately, in writing, before it is carried out. Nothing is added to your bill without your agreement.

FAQs

Do we need to pay for a certificate?

For most business sites, no. A free automated certificate gives the same encryption and the same padlock as a paid one, and renews itself. Paid certificates are worth it mainly when you need a wildcard across many subdomains or a warranty for contractual reasons, and we will tell you which case you are in before you spend anything.

Will the padlock definitely appear on every page?

On everything we control, yes. The exception is a third-party embed that only publishes an insecure version, such as an old booking widget or a map from a vendor who has not updated. We identify those, tell you which vendor to chase, and offer the option of removing or replacing the embed as separate work.

Does HTTPS mean our site is secure?

No. It encrypts the connection between the visitor and the server, which stops someone on the same network reading or altering the traffic. It does nothing about weak passwords, out-of-date plugins or an exposed admin area. Treat it as one necessary control among several.

What if our host cannot support this?

A small number of very old shared hosting plans block custom certificates or the automated renewal process. We check that during the first step, before any work is billed. If the host cannot support it, we say so and either refund you or, if you prefer, quote the move to a host that can.

Refund & cancellation

What happens if you change your mind, and what happens to money already paid.

Cooling-off before work starts
You have 7 days after ordering to cancel while work has not yet begun. Up to 25% may be retained to cover scoping and scheduling already carried out.
Work already done
Once delivery has started, refunds are assessed against the work completed and the deliverables already handed over — the list under “what you get” above is what that assessment is made against. Approved refunds are processed within 14 days.
If we cannot deliver what is described here
You are refunded. The scope on this page is the scope we are held to, which is exactly why the exclusions above are stated before you buy rather than after.

The full terms, item type by item type, are in the Refund & Cancellation Policy. How the work reaches you is covered by the Delivery & Fulfilment Policy.

Not sure this is the right product?

We would rather point you at the right thing than sell you the nearest one. Ask us before you buy — no obligation.

Related products

Others that solve nearby problems, in case this is not quite the right fit.

  • A hardening pass taking every configuration check from failing to passing — illustrative concept, not a screenshot of a client system
    REMOTE SERVICEBuy now

    Security · Hardening

    Security Hardening

    The fixing job: headers, permissions, versions and configuration put right

    Starting from

    $499one-off

    How it is delivered
    Remote Setup
    Turnaround
    5–8 business days from agreement of the scope list and a maintenance window
  • Mail authentication: every message checked at SPF, DKIM and DMARC before delivery — illustrative concept, not a screenshot of a client system
    REMOTE SERVICEBuy now

    Security · Hardening

    Email Security Setup

    SPF, DKIM and DMARC published, monitored, then moved to enforcement safely

    Price

    $399one-off

    How it is delivered
    Remote Setup
    Turnaround
    Records published within 2–3 business days; the enforcement step follows 30 days of monitoring
  • An audit report: findings grouped into severity bands with an owner for each — illustrative concept, not a screenshot of a client system
    REMOTE SERVICEBuy now

    Security · Assessment

    Website Security Audit

    A read-only review of one website and its hosting, written up and ranked by risk

    Price

    $349one-off

    How it is delivered
    Remote Setup
    Turnaround
    5–7 business days from receipt of access, with the walkthrough call booked once the report is sent

Or see all 11 in Cybersecurity & Digital Protection.

Contact us