Zipper
ServicesPlansDocsSupport
Sign inCreate account

Spatial Regal

20 named services.

When you create an account, Zipper provisions every service automatically. You can pause a service; you do not have to set one up by hand.

Delivery

delivery

The Crown

Global content delivery

The Crown is Zipper’s content delivery network. It terminates TLS at the edge, caches static and negotiated assets, and routes visitors across an anycast network so pages load quickly worldwide.

  • Anycast points of presence
  • Stale-while-revalidate
  • Origin shielding
  • HTTP/3 and TLS 1.3

delivery

The Drawbridge

Load balancing

The Drawbridge steers traffic across origin pools. Unhealthy backends are taken out of rotation automatically. Weighted pools and sticky sessions are built in.

  • Active health checks
  • Weighted pools
  • Session affinity
  • Automatic failover

delivery

The Gallery

Image optimization

The Gallery resizes, converts, and compresses images at the edge — AVIF, WebP, and quality ladders without changing files on your origin.

  • AVIF and WebP
  • On-the-fly crop
  • Quality ladders
  • Hotlink protection

delivery

The Archives

Object storage

The Archives hold cached and stored objects with instant purge, signed URLs, and per-workspace isolation so one account cannot read another’s files.

  • Instant purge
  • Signed URLs
  • Versioned objects
  • Tenant isolation

delivery

Video Delivery

Adaptive streaming

Video Delivery encodes uploads into adaptive ladders and serves HLS from The Crown. Watermarks, signed playback, and caption tracks are first-class.

  • Adaptive HLS
  • Signed playback
  • Captions
  • Origin-less delivery

Security

security

The Keep

Web application firewall

The Keep evaluates managed and custom WAF rules for SQL injection, XSS, protocol abuse, and your own signatures. Every workspace gets a hardened baseline as soon as you add a hostname.

  • OWASP baseline
  • Custom rule groups
  • Bot score hints
  • Challenge or block actions

security

Portcullis

Human verification

Portcullis is Zipper’s CAPTCHA alternative. It checks browser signals, solves a short proof-of-work, and issues a one-time token. Embed a site key, collect the token, and confirm it with Siteverify. Managed, non-interactive, and invisible modes.

  • Animated widget
  • Proof-of-work and signals
  • One-time tokens
  • Siteverify API

security

The Moat

DDoS mitigation

The Moat filters volumetric and protocol floods at the network edge. Automatic mitigation starts when traffic leaves the normal baseline for that workspace.

  • Layer 3 and 4 absorb
  • Adaptive thresholds
  • Always-on baseline
  • Attack history

security

The Scepter

API shield and rate limits

The Scepter rate-limits, authenticates, and validates your APIs at the edge. Pair it with Portcullis to keep credential stuffing off login routes.

  • Token auth
  • Per-route quotas
  • Schema validation
  • Abuse lists

security

Visitor Queue

Surge protection

Visitor Queue parks excess sessions when a path exceeds its budget. Estimated wait, bypass for signed-in teammates, and a branded holding page keep origin inside its limits.

  • Session budget
  • Estimated wait
  • Bypass cookies
  • Origin protection

Compute & AI

compute

Edge Functions

Serverless at the edge

Edge Functions is Zipper’s isolate runtime. Deploy request handlers that sit in front of origin, rewrite responses, or run on a cron. CPU is billed per invocation; memory is capped per isolate.

  • V8 isolates
  • Scheduled runs
  • Service bindings
  • No cold-start tax

compute

Site Hosting

Git-connected sites

Site Hosting builds from your repository. Each branch gets a preview hostname. Production attaches to The Crown automatically, with rollback to the last healthy build.

  • Git deploys
  • Preview hostnames
  • Functions on routes
  • Instant rollback

compute

Job Queues

Background work

Job Queues pull work off the request path. Producers enqueue payloads from functions or origins; consumers retry with backoff. Poison messages land in a dead-letter queue.

  • At-least-once delivery
  • Dead-letter queues
  • Backoff retries
  • Function consumers

compute

Edge AI

Inference at the edge

Edge AI hosts Zipper’s inference catalog. Call language, embedding, and classification models from Edge Functions without standing up a GPU fleet. Tokens are billed per workspace, and prompts can be redacted before they hit logs.

  • Language models
  • Embeddings
  • Prompt redaction
  • Per-workspace quotas

Identity

identity

The Herald

Authoritative DNS

The Herald is authoritative DNS with DNSSEC, geo steering, and instant record updates. Zones you create in the dashboard are published automatically.

  • DNSSEC
  • Geo steering
  • API-first records
  • Low-TTL cutovers

identity

The Vault

TLS certificates

The Vault issues and renews certificates for each zone, enforces modern cipher suites, and stores private keys outside the tenant control plane.

  • Auto-renewal
  • Custom certificates
  • HSTS helpers
  • Key isolation

identity

Emails

Routing, inboxes, and mail

Emails receives mail for the zone, stores it in workspace inboxes, and routes copies to a mailbox, a webhook, or an Edge Function. Outbound mail is DKIM-signed. Catch-all, aliases, and per-address inboxes live here.

  • Inboxes and stored mail
  • Catch-all aliases
  • DKIM signing
  • Function destinations

Observability

observability

The Watchtower

Analytics and logs

The Watchtower records edge telemetry: cache hit ratio, WAF actions, DDoS events, and Portcullis results — scoped strictly to your workspace.

  • Live request log
  • Threat timeline
  • CSV export
  • Workspace-scoped access

Access

access

The Throne Room

Zero-trust access

The Throne Room publishes private applications behind Zipper identity. Only signed-in teammates can reach them; the public internet never sees the origin.

  • Identity-aware proxy
  • Device posture hooks
  • Short-lived grants
  • Audit trail

access

Origin Connect

Private origin links

Origin Connect keeps the origin off the public internet. A small connector in your network dials Zipper outbound; The Throne Room and The Crown then publish the hostname. No public IP and no inbound firewall holes.

  • Outbound-only connector
  • Hostname routing
  • Private origins
  • Heartbeat health
Zipper

An affordable Cloudflare alternative: CDN, WAF, edge compute, and bot checks. A Spatial Regal Technology platform by Spatial Regal Digital Ltd.

Product

  • Services
  • Pricing
  • Docs
  • vs Cloudflare
  • Cloudflare alternative
  • Workers alternative
  • Turnstile alternative
  • Create account
  • Support

Services

  • The Crown
  • The Keep
  • Portcullis
  • The Moat
  • The Herald
  • The Vault
  • The Scepter
  • The Watchtower

Legal

  • Terms
  • Privacy
  • Cookies
  • AUP
  • DPA
  • Security
  • Subprocessors
  • Billing
  • DMCA

© 2026 Spatial Regal Digital Ltd. Zipper is part of Spatial Regal Technology.

Powered by Spatial Regal · tinyzipper.com