Features
Everything UnifySSL does.
A complete control plane for SSL and edge routing — from a single domain to a multi-region, multi-tenant fleet.
TLS & certificates
Certificates for every hostname, automatically.
UnifySSL issues and renews TLS for apex domains, wildcards, and customers' BYO hostnames — with a shared certificate store across your whole fleet.
- On-demand issuance, gated to verified domains
- Wildcard certificates via DNS challenge
- Let's Encrypt and ZeroSSL issuers
- Renewals and expiry alerts handled for you
Routing
Reverse-proxy and redirects, point and click.
Build host-matched routing in the dashboard. UnifySSL compiles it to native Caddy JSON — there is never a hand-edited Caddyfile.
- Reverse-proxy to any upstream, HTTP or HTTPS
- Path-matched redirects
- Per-site host and node targeting
- A raw-JSON escape hatch for the long tail
Security
Access control that ships with your routing.
Block bad actors and protect upstreams with rules that evaluate before any proxying happens.
- Block by IP / CIDR, user-agent, or path
- IP allow-lists
- Per-client rate limiting
- A cross-site view of every active control
Fleet & deploys
One validated config, pushed to every node.
Postgres is the source of truth. Each node pulls and applies the exact config it should be running — and a bad config never lands.
- Validate every config against Caddy before staging
- Agent re-validates before it applies
- Config-drift visibility per node
- Append-only revision history with one-click rollback
Multi-tenancy
Built for many customers, not just one team.
Organizations, teams, and roles let each tenant manage only their own domains and routing — with their own admins and invites.
- Org → team → app access control
- Open signup, invite-only, or platform-provisioned onboarding
- Email verification, password reset, rate limiting
- Globally-unique hostnames across tenants
Observability
Know what your edge is doing.
Synthetic probes, shipped access logs, and traffic analytics give you a live picture of health and abuse — scoped per tenant.
- Per-domain uptime + latency probes
- Searchable access logs
- Top domains, endpoints, and client IPs
- Prometheus metrics export