Enterprise-Grade SSL (Cloudflare)
INTEGRATIONS · EXPERTINI ATS

Enterprise-Grade SSL (Cloudflare)

Enterprise-grade HTTPS for your custom careers domain — we partner with Cloudflare, who deploy your certificate across a global network of 335 cities and bring it online in minutes. Included with every package.

3 min de lectura · Actualizado en julio de 2026 · Redacción de Expertini

A branded careers site on your own domain loses its credibility the moment a browser flags it "Not secure" — and candidates notice before recruiters do. Most careers-site products either leave TLS as your problem, or price certificate management as an add-on. Expertini ATS treats HTTPS as part of the product: every custom careers domain gets an enterprise-grade SSL certificate, issued and served by Cloudflare, on every plan, and renewed automatically before it ever expires.

The whole flow is designed so a non-technical recruiter can complete it: point one CNAME record at Expertini from the Custom Domain app and verify it with one click. That is the entire process — there is no certificate to request. Issuance starts on its own for your exact hostname (a subdomain like careers.yourcompany.com, or your apex domain) and is usually live within minutes. You never buy a certificate, never upload one, and never touch a renewal again.

01How it works, end to end

Step one lives in the Custom Domain (DNS) app: add a CNAME record at your DNS provider (guides for Cloudflare, GoDaddy, Bluehost and any other provider are built into the app) pointing your chosen hostname at Expertini, then hit Verify. There is no step two. Verification registers your hostname with Cloudflare, which validates it, issues the certificate, deploys it across its global edge and renews it ahead of expiry — the same network that fronts Expertini itself. Minimum TLS 1.2, modern ciphers, and no action from you at any point.

02What it covers — and what it costs

The certificate covers exactly the hostname you verified — subdomains (careers.yourcompany.com, jobs.yourbrand.co.uk) and apex domains are both supported. The cost is zero: no issuance fee, no renewal fee, no per-domain add-on. Custom domains and their SSL are included from the Starter plan upward, in the same flat price as everything else — consistent with how we treat the rest of the platform: capabilities ship in the plan, not as an invoice line.

03Already on Cloudflare?

If your DNS runs through Cloudflare in Proxied mode, your visitors already see Cloudflare-issued HTTPS at the edge. Requesting the free certificate here as well is still the right move: it encrypts the connection between Cloudflare and Expertini too, letting you run Cloudflare's Full (strict) SSL mode — encrypted end to end, with no certificate warnings on either hop.

04Why this matters for hiring, not just security

Candidates increasingly reach careers sites from links in messaging apps and social posts, where browsers are most aggressive about flagging insecure pages. An HTTPS careers site on your own domain keeps your employer brand intact at the exact moment a candidate decides whether to apply — and because the site itself is the multi-page company site Expertini serves natively (jobs with search, services, about, contact), the entire branded, secure experience comes from one subscription with no web-agency invoice attached.

Notas de ingeniería

Arquitectura y operaciones de la plataforma

A1Connection architecture

The connection model for this integration is stated honestly on its card: where a public API exists it is used with your own account and consent, and where a vendor requires a partner agreement the page says so instead of showing a Connect button that cannot work.

Once available, credentials follow the platform standard: encrypted at rest, presence-flag display, immediate removal on disconnect.

A2Write semantics and data flow

Every data movement is an explicit action with a logged result. Writes happen on your click — or automatically only where you enabled a rule (auto-push on hire is off by default, per-provider). Reads — imports of people, accounts, or files — run when you press Import, deduplicate against what you already have (clients by name, people by email), skip rather than overwrite, and report created-versus-skipped honestly, which is why re-running any import is safe by design.

Each action writes a row to the app-activity journal (ats_app_activity): what ran, when, for which record, and the outcome — including the vendor's own error text verbatim when something fails. Usage reporting inside the ATS aggregates that same journal, so integration reporting and integration reality cannot diverge.

Anything that leaves the request path — notification fan-out, webhook delivery, activity journalling, mail — runs in fire-and-forget background threads. A slow external endpoint can never make the interface hang, and a failed side effect is logged rather than silently retried into inconsistency.

A3Operational considerations

Connections are organisation-level and gated to owner and admin roles; recruiters use the features a connection powers but cannot connect, disconnect, or reconfigure. Disconnecting removes stored credentials immediately and stops the dependent features visibly, not silently. Data already imported stays yours and editable.

Imported people arrive marked as imported with conservative privacy defaults — no consent is assumed for anyone who never filled in your application form, and retention defaults apply. Everything written is yours to take: CSV exports and the Data Export app cover the same stores the product itself reads. The exit is as open as the entrance — by design, not concession.

A4Placement in the integration topology

This integration is live in the registry today. One connection per provider unlocks every feature it powers, and the topology grid below shows the neighbouring connectors in the same capability area — statuses come from the same registry that drives the in-app hub, so this page can never claim more than the product does. For anything the catalogue does not cover, Webhooks and Zapier are the generic, documented escape hatch.

Mapa de dependencias

Connection typestated per-vendor on the card
Secrets at restencrypted; UI shows presence flags, never values
Action journalats_app_activity — one row per action, vendor errors verbatim
Auto-push rulesoff by default, per-provider, every run logged
Registry statuslive

Esquema de interfaz de

Esquema estructural de la interfaz: paneles, jerarquía y posibilidades de interacción. Un contrato, no una captura de pantalla.
Tarjeta de conexión
● conectado — indicador de presencia
permisos: mínimo requerido desconectar
Acciones
envío — clic explícitoimportación — desduplicada
Diario de actividad
Fig. 1 — Enterprise-Grade SSL (Cloudflare): esquema estructural de la interfaz. Los paneles y estados constituyen el contrato; los datos mostrados son provisionales.

Flujo de interacción: estados, validaciones, comentarios

Cada estado a continuación se aplica en el servidor; la interfaz lo reporta, no lo decide.
Connectowner/admin clicks Connect on the Connectors page
Vendor consentthe vendor's own screen lists the exact scopes
Token exchangeserver-side callback; secrets never touch the browser
Connectedencrypted store; card flips with presence flag
Explicit actionspush / import / schedule — each one journalled
Consent denied → the vendor's error code surfaces in a toast, namedPlatform keys missing → honest setup pointer, not a silent bounceToken expired → automatic refresh at the chokepointRefresh rejected → visible reconnect prompt, features never break silentlyPlan below minimum → lock card names the exact plan
Fig. 2 — flujo de interacción: azul marino = estados, dorado = validaciones aplicadas por el servidor, verde = resultados confirmados; las etiquetas enumeran los casos especiales y sus respuestas.

Preguntas frecuentes

Is SSL included in my plan?
It is included with every package rather than sold separately — issuance, deployment and automatic renewal, on every plan including Starter. We treat HTTPS as part of the product rather than an add-on: a careers site a browser flags as insecure is not a careers site we would want our name on.
How long does it take to go live?
Usually within minutes of your CNAME verifying — the HTTPS page shows live status, and a notification appears when it goes active. The domain must be CNAME-verified first, since the certificate is issued for the exact verified hostname.
Do I need to renew it?
Never. Cloudflare renews ahead of expiry with no interruption — expiry warnings are our problem, not yours.
Can I use my apex domain instead of a subdomain?
Yes — most DNS providers need an ALIAS/ANAME record instead of a CNAME at the apex; the Custom Domain app's provider guides cover it, and the certificate works the same way.
What if I leave Expertini?
Point your DNS elsewhere and the domain is yours as it always was — and the Data Export app gives you your full hiring data as one file. No part of the domain or certificate setup locks you in.

De un vistazo

  • Enterprise-grade SSL — issued and served through our Cloudflare partnership
  • No request to make — issuance starts by itself the moment your CNAME verifies
  • Usually live within minutes, with live status on the HTTPS page
  • Automatic renewal forever — nothing to buy, upload, or remember
  • Subdomains and apex domains both supported
  • Deployed across Cloudflare's global network of 335 cities — HTTPS online in minutes
  • Included with every package — not an add-on, and never billed separately

Vea enterprise-grade ssl (cloudflare) en su propia contratación.

Traiga una descripción de puesto real a una demostración de 30 minutos; prueba gratuita incluida.

Solicitar una demostración
Expertini inteligente
En línea ahora
¡Hola! Soy el especialista inteligente de producto de Expertini. Pregúnteme lo que desee sobre nuestras soluciones, obtenga orientación sobre cualquiera de nuestras herramientas de contratación o simplemente dígame qué desea hacer: le orientaré en la dirección correcta. Para problemas específicos de su cuenta, escriba a support@expertini.com.