All of your organization's sites are protected from a single panel. SSL certificates are obtained and renewed automatically, attacks stop before they reach your site, and every request is logged in line with Law 5651. Your site stays on your own server. Only the DNS record changes.
NetSSL is a security and publishing layer that runs in front of websites. Visitors reach the site through NetSSL. On the way, the connection is encrypted with SSL, attacks are stopped and every request is logged in line with Law No. 5651.
It is designed for municipalities, public institutions and companies. Traffic and logs are processed and stored in our own facility in Ankara and are not transferred abroad.
NetSSL sits in front of your site. Your site, your server and your software stay as they are.
Enter the site's address and your target server. You can add many sites in bulk.
Add the single record the panel shows to your domain. The panel checks the record itself.
Once the record is visible, SSL is obtained and protection and logging begin. If you like, we can do the setup together with you on screen.
Each protection has its own switch for each site. The preview next to each setting shows in advance what visitors will see.
The certificate for every address you add is obtained automatically and renewed before it expires. A small agent installs the wildcard certificate on your organization's Windows and Linux servers during the night. Certificates of addresses that do not go through NetSSL, such as a VPN or a mail server, are monitored too, and you are notified before they expire.

Requests are inspected before they reach your server. NetSSL stops SQL injection, file scanning, brute-force login attempts, malicious bots and sources on the malicious address list of USOM, Türkiye's national cyber incident response center. An address that attacks one organization is also stopped at the other organizations on NetSSL. You can watch a new rule in test mode first, without blocking anyone.

A full-screen view for a TV or a second monitor shows how many people are on your sites right now, attacks stopped second by second, an attack map and the status of your sites. The screen opens with a secret link that needs no login and allows viewing only.

Every request to your sites is logged without sampling. For municipalities and public institutions, logs are kept for 2 years. They are sealed with a timestamp every day and chained from one day to the next. For a request from a prosecutor or a court, you prepare the export with an official report in a few steps.

The privacy notice is prepared to match your site's actual situation, and each version is kept. Citizen requests are tracked against the 30-day legal deadline. The cookie consent banner does not run tracking code until consent is given. The panel also finds which foreign services your site sends visitor data to.

The official site badge in the corner of your site opens a page that confirms the site belongs to your organization. If someone copies the badge onto a fake site, it turns into a red warning there and you are notified. The fake site takedown assistant collects the evidence and prepares the reports to send to USOM and the companies involved.

If the main server stops responding, traffic switches to the backup server and returns once the main server recovers. The Always On feature shows visitors the last copy of the pages. For peak days such as exam results or a tax deadline, measures are scheduled in advance. During a sudden rush, visitors see a queue number instead of an error.

NetSSL places the accessibility toolbar on your pages itself. Your site's software is not touched, no external script is loaded and no separate license is needed.
The toolbar makes things easier for visitors. Problems in your site's code are fixed on your site, based on the scan results. The panel lists these problems page by page.
Web accessibility guideEach one is explained in the Knowledge Base with screenshots.
NetSSL helps you meet these obligations. Your organization remains responsible for compliance.
| Legislation | What the organization must do | How NetSSL covers it |
|---|---|---|
| Law No. 5651 | Store access logs, protect their accuracy and integrity, and hand them over on request | 2-year retention, daily timestamp, SHA-256 chain, integrity checks, official request export with a formal report |
| KVKK (Personal Data Protection Law No. 6698) | Inform people about data processing, answer requests within 30 days, know where data is transferred abroad | Privacy notice, request form and deadline tracking, cookieless statistics, cookie consent banner, scan for transfers abroad |
| Presidential Circular No. 2025/10 | Websites that meet WCAG 2.2 and the Ministry checklist | Accessibility toolbar, WCAG pre-scan, checklist, accessibility statement |
| Information and Communication Security Guide | Measures for web applications, log management, authentication and encryption | Compliance report with evidence (PDF), two-factor authentication, up-to-date TLS, security headers, attack protection |
| USOM / CSIRT | Report cyber incidents and block malicious addresses | USOM malicious address list, incident report, SIEM export, ready-made report text for fake sites |
How do the tasks your IT team faces every day change?
| Topic | Without NetSSL | With NetSSL |
|---|---|---|
| SSL certificate | Each site has its own renewal date. If one is forgotten, the site stops opening. | Certificates are obtained and renewed automatically. Wildcard SSL is installed on servers overnight. |
| VPN and mail certificates | You notice only after it expires. | You get a warning 30, 14 and 7 days before expiry. |
| Attacks | There is no protection in front of the server, or you need an expensive appliance. | Attacks stop before they reach the site. The USOM list is applied automatically. |
| Law 5651 logs | Logs are compiled by hand from server records. | Logs are kept for 2 years with timestamps. An official request is ready in a few steps. |
| KVKK requests | Requests can get lost in an email inbox. | Requests are tracked, and you are warned about the 30-day deadline. |
| Accessibility | You need a separate plugin and a separate scan. | The toolbar and the scan are in the same panel. |
| Fake sites | You find out from citizen complaints. | Lookalike domains are monitored, the badge raises a warning, and the takedown assistant prepares the report. |
| The IT team's morning | Six different screens to check. | A single list: "Needs attention". |
For any organization with addresses such as a corporate site, e-municipality services, appointment booking, an EDMS or e-tendering.
In 21 guides, you can see what each screen does and how to use it, with screenshots.
How it works, your first site and the DNS record.
Read the guideProtection levels, extra rules and test mode.
Read the guideCertificates and overnight installation on servers.
Read the guideLog package, timestamp and official report.
Read the guidePrivacy notice, requests and the cookie banner.
Read the guideThe toolbar, scanning and the checklist.
Read the guideIf you can't find what you're looking for, we're just a phone call away.
We will show you the panel live with sample data. If you like, we can set up your first site together on screen. The price is set by quote, based on the number of sites and the log retention period.
We use cookies to improve your experience, analyse traffic and measure ad performance. Details in our Privacy Policy.