GuidesContact
Guides

What 'Not Secure' next to your business name means

CloudBuilder AI · 1 min read

If your site has HTTPS problems, some visitors see the words Not Secure in the address bar beside your name. Many visitors read it as a warning about the business itself.

What HTTPS actually protects

HTTPS encrypts the connection between a visitor and your site, so what they type, a contact form, a phone number, a booking, can't be read by whoever runs the network they are on. Without it, on public wifi, someone on the same network could intercept that traffic.

The HSTS setting many sites skip

Many sites have HTTPS but skip a setting called HSTS, which tells browsers to always connect securely from the first instant. Without it, the very first hop of a visit can happen unencrypted before switching over. The window is brief, but on public wifi it still exposes traffic.

What it costs beyond security

Browsers warn visitors away from insecure pages, and Google factors security into how it treats a site. The label can turn away a customer who was ready to book; the fix is a settings change.

What fixing it involves

Certificates themselves are free these days; the work is in the configuration, redirects, the HSTS policy, and finding pages that still load insecure content. These are exactly the items our $40 tune-up fixes when your setup allows it.

Related

Common questions

My site shows a padlock. Am I done?
Probably mostly. The padlock covers the basics; the free check also looks for the always-secure policy and mixed insecure content, which the padlock alone doesn't prove.
Do certificates cost money?
The certificates themselves are free from your hosting provider in nearly all modern setups. If someone is charging you for the certificate alone, ask what else the fee covers.