Visitors want to see that your site is secure — that little padlock in the browser's address bar. Obelisk arranges that automatically with a valid security certificate, so every connection to your site is encrypted and trusted.
Nothing to look after
You do not have to install or renew anything yourself. As soon as your domain points to Obelisk, the certificate is requested, and afterwards it renews itself well in time. Expiring certificates and those scary 'not secure' warnings in the browser are a thing of the past.
Why it matters
A secure site builds trust with your visitors — especially when they fill in a form or place an order — and it counts towards your ranking in Google. It is a small detail with a big effect on how seriously people take your site.
What do you need?
The certificate takes care of itself once your domain name points to Obelisk. That pointing (the so-called DNS settings) is the only thing that needs to be set up correctly. Ster Software sets up that domain and those settings for you — get in touch.
Why HTTPS is no longer optional
Modern browsers actively warn visitors when a site is not secure, and that warning alone is enough to make people leave before they have read a word. A valid certificate keeps that warning from ever appearing.
It matters most on pages where visitors share personal details, such as a form or a login — an unencrypted connection there is a real risk, not just a cosmetic one.
A common use case: launching a new website on a fresh domain. The certificate is requested automatically as soon as the domain points to Obelisk, so there is no separate step to remember before going live.
Practical tip: if you later move the site to a different domain, double-check that a redirect is in place — a missing certificate on the new domain is a common cause of a broken launch.
Why "good enough" security still matters for small sites
It's tempting to assume a simple brochure site with no login and no payments doesn't need to worry much about certificates, since there's nothing sensitive being transmitted. But browsers don't make that distinction — an unencrypted connection triggers the same warning regardless of what the page actually does, and that warning alone damages trust before a visitor reads a word of content. Encryption on every site, not just ones handling sensitive data, is simply the baseline visitors now expect.
There's also a subtler reason it matters even for simple sites: an unencrypted connection can be intercepted or modified in transit on an untrusted network, such as public wifi — something a visitor has no way of knowing is happening, which is exactly why browsers warn so aggressively.
SSL certificates across different kinds of sites
An e-commerce site handling payments has the most obvious need — a missing or expired certificate there doesn't just look bad, it can make a checkout provider refuse to process transactions at all. A membership site with a login area needs it just as much, since credentials are exactly the kind of data an unencrypted connection would expose.
Custom integrations, such as a payment provider connected through a custom app, depend on it just as directly. Even a purely informational site benefits, since search engines factor certificate status into rankings, tying it to SEO rather than being a purely cosmetic concern.
Common misconceptions
A frequent misconception is that a certificate is a one-time purchase rather than something needing ongoing renewal — historically a real source of outages when a certificate quietly expired and nobody noticed until visitors started seeing warnings. Obelisk removes that risk with automatic renewal well before expiry, but it's worth understanding why that automation matters if you've been burned by it elsewhere before.
Another misconception is that a certificate alone makes a site "secure" in every sense. It encrypts the connection between a visitor's browser and the server, which is essential, but it says nothing about how well a submitted form validates its input or how a password is stored — those are separate concerns a certificate doesn't cover. For the technical detail behind how submitted data is handled once it reaches the server, see forms and validation.
How to ask the assistant
Make sure mysite.com gets a valid security certificate.