Skip to main content
vly uses Let’s Encrypt for SSL — automatic provisioning, automatic renewal, no manual cert management.

Automatic provisioning

When DNS for a custom domain resolves correctly to vly, an SSL request fires automatically. Typical timing:
  • DNS propagation: 1–60 minutes
  • SSL issuance: ~10 seconds after DNS is verified
  • SSL renewal: 30 days before expiry, automatic
The status flow in vly’s domain settings:

Custom certificates

For Enterprise customers using a corporate CA or extended-validation cert:
1

Settings → Domains → [domain] → Certificate → Use custom

Toggle to custom mode.
2

Paste the full cert chain

Including intermediate certs. Format: PEM.
3

Paste the private key

Format: PEM.
4

Set a renewal reminder

vly doesn’t auto-renew custom certs. Calendar a reminder 30 days before expiry.

TLS versions

vly serves TLS 1.2+ by default; TLS 1.3 preferred. TLS 1.0 / 1.1 are disabled (deprecated by all major browsers).

HSTS

Strict-Transport-Security is sent by default with max-age=31536000 (1 year). To preload, request inclusion via hstspreload.org after confirming HTTPS works.

Troubleshooting

Let’s Encrypt rate-limited. Wait 1 hour, then click “Retry SSL”.
Cert not yet provisioned, or your browser cached an old cert. Try incognito.
Some asset on the page is http://. Search code; switch to https:// or protocol-relative //.

Custom domains

Domain setup.

DNS setup

DNS provider guides.

Security overview

Broader security model.
Last modified on April 18, 2026