The live site is now running the full type-safe TLS stack all the way down to the TCP/IP stack and Xen device drivers. If it feels a little sluggish from your browser, this is because TLS session resumption hasn't been merged in yet (but is available to test at
https://github.com/mirleft/ocaml-tls/pull/283)