Spatial Regal
20 named services.
When you create an account, Zipper provisions every service automatically. You can pause a service; you do not have to set one up by hand.
Delivery
delivery
The Crown
Global content delivery
The Crown is Zipper’s content delivery network. It terminates TLS at the edge, caches static and negotiated assets, and routes visitors across an anycast network so pages load quickly worldwide.
- Anycast points of presence
- Stale-while-revalidate
- Origin shielding
- HTTP/3 and TLS 1.3
delivery
The Drawbridge
Load balancing
The Drawbridge steers traffic across origin pools. Unhealthy backends are taken out of rotation automatically. Weighted pools and sticky sessions are built in.
- Active health checks
- Weighted pools
- Session affinity
- Automatic failover
delivery
The Gallery
Image optimization
The Gallery resizes, converts, and compresses images at the edge — AVIF, WebP, and quality ladders without changing files on your origin.
- AVIF and WebP
- On-the-fly crop
- Quality ladders
- Hotlink protection
delivery
The Archives
Object storage
The Archives hold cached and stored objects with instant purge, signed URLs, and per-workspace isolation so one account cannot read another’s files.
- Instant purge
- Signed URLs
- Versioned objects
- Tenant isolation
delivery
Video Delivery
Adaptive streaming
Video Delivery encodes uploads into adaptive ladders and serves HLS from The Crown. Watermarks, signed playback, and caption tracks are first-class.
- Adaptive HLS
- Signed playback
- Captions
- Origin-less delivery
Security
security
The Keep
Web application firewall
The Keep evaluates managed and custom WAF rules for SQL injection, XSS, protocol abuse, and your own signatures. Every workspace gets a hardened baseline as soon as you add a hostname.
- OWASP baseline
- Custom rule groups
- Bot score hints
- Challenge or block actions
security
Portcullis
Human verification
Portcullis is Zipper’s CAPTCHA alternative. It checks browser signals, solves a short proof-of-work, and issues a one-time token. Embed a site key, collect the token, and confirm it with Siteverify. Managed, non-interactive, and invisible modes.
- Animated widget
- Proof-of-work and signals
- One-time tokens
- Siteverify API
security
The Moat
DDoS mitigation
The Moat filters volumetric and protocol floods at the network edge. Automatic mitigation starts when traffic leaves the normal baseline for that workspace.
- Layer 3 and 4 absorb
- Adaptive thresholds
- Always-on baseline
- Attack history
security
The Scepter
API shield and rate limits
The Scepter rate-limits, authenticates, and validates your APIs at the edge. Pair it with Portcullis to keep credential stuffing off login routes.
- Token auth
- Per-route quotas
- Schema validation
- Abuse lists
security
Visitor Queue
Surge protection
Visitor Queue parks excess sessions when a path exceeds its budget. Estimated wait, bypass for signed-in teammates, and a branded holding page keep origin inside its limits.
- Session budget
- Estimated wait
- Bypass cookies
- Origin protection
Compute & AI
compute
Edge Functions
Serverless at the edge
Edge Functions is Zipper’s isolate runtime. Deploy request handlers that sit in front of origin, rewrite responses, or run on a cron. CPU is billed per invocation; memory is capped per isolate.
- V8 isolates
- Scheduled runs
- Service bindings
- No cold-start tax
compute
Site Hosting
Git-connected sites
Site Hosting builds from your repository. Each branch gets a preview hostname. Production attaches to The Crown automatically, with rollback to the last healthy build.
- Git deploys
- Preview hostnames
- Functions on routes
- Instant rollback
compute
Job Queues
Background work
Job Queues pull work off the request path. Producers enqueue payloads from functions or origins; consumers retry with backoff. Poison messages land in a dead-letter queue.
- At-least-once delivery
- Dead-letter queues
- Backoff retries
- Function consumers
compute
Edge AI
Inference at the edge
Edge AI hosts Zipper’s inference catalog. Call language, embedding, and classification models from Edge Functions without standing up a GPU fleet. Tokens are billed per workspace, and prompts can be redacted before they hit logs.
- Language models
- Embeddings
- Prompt redaction
- Per-workspace quotas
Identity
identity
The Herald
Authoritative DNS
The Herald is authoritative DNS with DNSSEC, geo steering, and instant record updates. Zones you create in the dashboard are published automatically.
- DNSSEC
- Geo steering
- API-first records
- Low-TTL cutovers
identity
The Vault
TLS certificates
The Vault issues and renews certificates for each zone, enforces modern cipher suites, and stores private keys outside the tenant control plane.
- Auto-renewal
- Custom certificates
- HSTS helpers
- Key isolation
identity
Emails
Routing, inboxes, and mail
Emails receives mail for the zone, stores it in workspace inboxes, and routes copies to a mailbox, a webhook, or an Edge Function. Outbound mail is DKIM-signed. Catch-all, aliases, and per-address inboxes live here.
- Inboxes and stored mail
- Catch-all aliases
- DKIM signing
- Function destinations
Observability
Access
access
The Throne Room
Zero-trust access
The Throne Room publishes private applications behind Zipper identity. Only signed-in teammates can reach them; the public internet never sees the origin.
- Identity-aware proxy
- Device posture hooks
- Short-lived grants
- Audit trail
access
Origin Connect
Private origin links
Origin Connect keeps the origin off the public internet. A small connector in your network dials Zipper outbound; The Throne Room and The Crown then publish the hostname. No public IP and no inbound firewall holes.
- Outbound-only connector
- Hostname routing
- Private origins
- Heartbeat health