You are viewing this page over HTTPS, but the backend virtual machine behind it speaks only plain HTTP on port 80. The encryption you just negotiated was handled entirely by the xit network load balancer using a publicly-trusted Let's Encrypt certificate it issued and serves itself.
The certificate was provisioned through xit's ACM-compatible API, validated automatically via DNS-01, and pushed to the load balancer host — no certificate ever lived on the backend VM.
demo.elb.xit-1.xit.dev · xit XCompute + XNet + XLB · a live demo on spot-backed compute