Skip to main content

Security and transfers

Strict HTTPS for your connected domain, and moving a website to a different organization.

Your website's Domain page controls Strict HTTPS for its connected domain. The owner can change which organization owns the website from Settings.

Strict HTTPS (HSTS)

Every website here is served over HTTPS, with the certificate managed for you. HSTS goes one step further: it tells browsers to only ever load your domain over HTTPS, so a visitor who types http:// or follows an old insecure link is never sent unencrypted, not even for the first request that would normally redirect.

It also makes your domain eligible for the browsers' HSTS preload list.

The catch worth understanding: HSTS applies to your whole domain, including every subdomain of it. If you run other subdomains that are not on HTTPS — an old mail interface, a legacy tool — those will stop loading for anyone who has visited your website. Switch it off if that describes you; leave it on otherwise.

The setting only affects a connected custom domain. Your free address is already served over HTTPS by the platform.

Find Strict HTTPS (HSTS) below the three checks in the My domain card. Before you connect a domain, the same control appears in the Security section of the Domain page.

Transferring a website to another organization

A website belongs to one organization, and its plan is what pays for it. Moving it to another organization moves that cost with it — which is why both sides are gated.

  • Only the owner of the organization the website is in may transfer it out. Giving a website away is the owner's call alone, not an administrator's.
  • You may only transfer it into an organization you own or administer, since arriving adds a billed website there.
  • The destination needs room. If the target organization is on the Free plan and already holds its allowance of websites, you are sent to its billing page to upgrade first.

The transfer takes the website with everything on it — its pages, its versions, its media, its conversations, its domain. Its URL in the dashboard changes to sit under the new organization; the website's own addresses do not change.

What happens when you press the button

The move is immediate, whatever the website's size. Pressing Transfer this website takes you straight to the website under its new organization, where it is listed in the dashboard and the website switcher from that moment. Nothing about the website itself changes — its pages, versions, media and conversations are exactly as they were, and your free address and any connected domain keep serving throughout. Both organizations' bills are adjusted at once.

If Max is in the middle of a change, or a save is in progress, the transfer waits a moment for it and otherwise tells you the website is being updated elsewhere, beside the field. Try again once it is idle; nothing has moved.

Access follows the destination organization. Site-specific access and pending invitation access from the previous organization are removed. The destination organization's owner and administrators can grant access to its members after the move.

Deleting a website

Deleting is on the same page, and it is worth reading about before you use it — it releases your free address and cannot be undone from inside the app. See Deleting a website.

Next

  • Organizations — what an organization is and why websites live in one.
  • Deleting a website — what is removed, what is kept, and what happens to your bill.