Docs
Every service, explained.
Zipper (TinyZipper) is Spatial Regal Technology’s Cloudflare-shaped edge at tinyzipper.com. Honest production on multi-layered Global Server nodes: application-layer DDoS and WAF, in-process cache, DNS-JSON, image delivery, Edge Functions, Site Hosting, Portcullis, Palace Guard, Zipper Mail (transactional email + webmail), Zipper Pilot, The Armory, and The Cellar (world’s first sealed Postgres) — 25 named services, priced per workspace, not per domain. Start with getting started, then jump to the service you need. Each page has use cases and a working API example.
Type a Cloudflare product or a Zipper service name.
Start
Honest production
What Zipper actually runs: multi-layered Global Server nodes, application-layer DDoS and WAF, in-process cache, DNS-JSON, and original-byte image delivery.
What is not Cloudflare or Neon scale
Named services map Cloudflare- and Neon-shaped jobs onto multi-layered Global Server nodes. This page is the substrate catalog: what those nodes do not run, will not fake, and could still ship without claiming Cloudflare or Neon scale.
Cloudflare in front of Zipper
Optional rented anycast for a website: orange-cloud the web hostname, Zipper stays the origin. Grey-cloud The Cellar. Zipper stays the origin on Global Server nodes.
Getting started
Create a Zipper account, add a hostname, point DNS, and put The Crown in front of origin — the simple Cloudflare alternative path.
Quickstart in ten minutes
The shortest path from signup to a proxied hostname and a working Portcullis widget.
What to use Zipper for
Practical use cases: SaaS apps, media sites, internal tools, and launches — a cheaper Cloudflare alternative for real workloads.
Plans and quotas
What each Zipper plan includes. Every plan has all named services; quotas and extras (SSO, log push, dedicated IPs) scale with the plan.
Migrate from Cloudflare
Move DNS, CDN, WAF, Workers, Pages, Turnstile, Tunnel, Email Routing, and Waiting Room to Zipper without a dual-running tax.
Migrate from Vercel
Move Next.js (and other) projects from Vercel to Zipper Site Hosting: git deploys, preview URLs, env vars, redirects, and instant rollback — on the same workspace bill as CDN and WAF.
Auth, tokens, and SSO
How Zipper workspace login, API tokens, Portcullis, SSO, and SCIM fit together.
Control plane API
Bearer tokens, idempotency, plan limits, and every v1 endpoint for Zipper — the Cloudflare API alternative for CDN, WAF, functions, and mail.
Using The Armory
How to use Zipper’s warrant mesh: create an app, sign someone in, spend a write cartridge, mint the next one. Spent warrants, hatch-bound sessions, musters, kit, and the roll — not a JWT farm.
Delivery
The Crown
The Crown remembers recent pages and files in Zipper’s own process. If a visitor asks for something we already have, they get it from memory. If not, Zipper fetches it from your site (or from object storage) and keeps a copy for a while. This is in-process cache on multi-layered Global Server nodes. This is a Cloudflare Cloudflare CDN / Caching alternative included on every Zipper plan.
The Drawbridge
The Drawbridge is a list of your origin servers. Zipper checks they answer. If one is sick, traffic goes to the others. You can weight them and keep a visitor on the same origin. This is a Cloudflare Cloudflare Load Balancing alternative included on every Zipper plan.
The Gallery
The Gallery stores the image you uploaded and sends those same bytes. The Crown may cache them. You can block other sites from hotlinking. Zipper does not resize, convert to AVIF/WebP, strip EXIF, or transcode. This is a Cloudflare Cloudflare Images (delivery only — not Polish) alternative included on every Zipper plan.
The Archives
The Archives keep files for your workspace. Metadata lives on Zipper; bytes sit in object storage. Every object is AES-256-GCM. You can give a time-limited signed URL, and you can purge a path from The Crown’s cache. Encryption cannot be turned off. This is a Cloudflare Cloudflare R2 + cache purge alternative included on every Zipper plan.
Video Delivery
Video Delivery stores the file you PUT and plays those bytes. Playback links can expire. The file is AES-256-GCM. Zipper does not encode, transcode, watermark, or build adaptive HLS. This is a Cloudflare Cloudflare Stream (storage + play — not encode) alternative included on every Zipper plan.
Security
The Keep
The Keep looks at HTTP requests on Zipper. It blocks common attacks (SQL injection, script tricks, odd protocols) and your own rules. Your origin only sees what passes. This is an application-layer WAF, not a packet filter. This is a Cloudflare Cloudflare WAF alternative included on every Zipper plan.
Portcullis
Portcullis is Zipper’s own human check. Visitors see a short widget. Zipper looks at the browser, does a small puzzle, and hands your page a one-time token. You send that token to Siteverify. It is not a third-party CAPTCHA network. This is a Cloudflare Cloudflare Turnstile alternative included on every Zipper plan.
The Moat
The Moat is application-layer DDoS on Zipper. If one IP sends too many HTTP requests, Zipper answers 429. It does not swallow raw network packets. This is a Cloudflare Cloudflare DDoS (HTTP only — not Magic Transit) alternative included on every Zipper plan.
The Scepter
The Scepter sits in front of your APIs. It counts requests, checks a token, and can refuse a body that does not match a schema. Use it with Portcullis on login so password guessing is slower. This is a Cloudflare Cloudflare API Shield / Rate Limiting alternative included on every Zipper plan.
Visitor Queue
Visitor Queue holds people on a waiting page when a path is over its limit. They see an estimated wait. Signed-in teammates can skip the line. This is a Cloudflare Cloudflare Waiting Room alternative included on every Zipper plan.
Palace Guard
Palace Guard is Zipper’s antivirus at the gate. It looks at uploads and stored objects while they are still in flight: known malware hashes, EICAR, a Zipper canary, web-shell names, filename tricks, and ZIP headers without opening a bomb. Bad Gallery, Archives, Video, Site Hosting HTML, inbound mail, and function source is held. Quarantined hashes stay held when served. You can watch the scan on the dashboard. This is a Cloudflare edge file antivirus alternative included on every Zipper plan.
Compute
Edge Functions
Edge Functions run your JS in a timed Node vm on Zipper. Use them to rewrite a response, sit in front of origin, or run on a schedule. This is not Cloudflare Workers and not a GPU. This is a Cloudflare Cloudflare Workers alternative included on every Zipper plan.
Site Hosting
Site Hosting connects a git repo. Zipper builds it, gives each branch a preview URL, and lets you roll back to an earlier deploy. Secrets sit encrypted. Attach your own domain when you are ready. This is a Cloudflare Cloudflare Pages / Vercel alternative included on every Zipper plan.
Job Queues
Job Queues take webhooks, mail, and retries off the page request. Zipper retries failed jobs. Poison messages go to a dead-letter queue. Payloads are AES-256-GCM and cannot sit in plaintext. This is a Cloudflare Cloudflare Queues alternative included on every Zipper plan.
Edge AI
Edge AI answers from Zipper’s own help text (zip-fast, zip-large) and can embed text (embed-v1). It is the same engine as Zipper AI on Support. It is not a rented GPU and not a general chatbot. This is a Cloudflare Cloudflare Workers AI alternative included on every Zipper plan.
Zipper Wire
Zipper Wire is Zipper’s AI automation control plane. Publish a wire (workflow), attach a manual, schedule, or webhook trigger, and run linear steps: map, branch, grounded AI, HTTP (SSRF-guarded), Function invoke, Job enqueue, email draft, delay, and human approval. Wire orchestrates; it does not replace Job Queues, Edge Functions, Edge AI, Pilot bots, or The Cellar. Runs, step logs, and approvals stay on this process with Palace RBAC and Watchtower audit. Not Zapier’s global farm, not Temporal’s multi-service cluster, and not Cellar’s PGWire adapter. Included on every Zipper plan.
Data
The Cellar
The Cellar is a sealed database for your app. You get a connection string, REST, live updates, and an import hatch. Paste a phpMyAdmin SQL dump (or CSV / JSON) and Zipper turns those tables into chambers. Browse and edit rows in Studio. Mint, revoke, and regenerate capability seals. Encryption and row rules stay on. SQL is Zipper’s dialect — it never hits the host Postgres parser. It is not Amazon RDS, not stock MySQL, and not a second Supabase. Live updates run on this Zipper process, not a world bus. Included on every Zipper plan.
The Armory
The Armory is Zipper’s warrant mesh for iOS, Android, and the web. You mint a hatch-bound session, then a warrant that names a rack. A write warrant is a spent cartridge — reuse returns 409. Musters hold sealed documents with revisions. Kit is cordoned by Palace Guard, including JSON bodies. The roll is real SSE on this node: writes publish put/patch/unput. Rotate anon and service keys from the dashboard anytime. Twenty Docker racks isolate duties. This is not Firebase, not Appwrite Cloud, not FCM/APNs, and not Kubernetes. Without Docker the same twenty racks run in-process and still fail closed. Included on every Zipper plan.
Support
Identity & access
The Herald
The Herald is where you keep hostname records. Apps look them up with GET /dns-query (JSON). Zipper does not listen on UDP/TCP 53, does not publish nameservers, and does not sign DNSSEC. This is a Cloudflare Cloudflare DNS-over-HTTPS JSON (not authoritative :53) alternative included on every Zipper plan.
The Vault
The Vault gets a certificate for each hostname, renews it, and keeps the private key off the tenant dashboard. You can also upload your own certificate. This is a Cloudflare Cloudflare SSL/TLS alternative included on every Zipper plan.
The Throne Room
The Throne Room puts a Zipper sign-in in front of an internal app. Only people in your workspace (with MFA if you require it) get through. The origin stays off the public internet. This is a Cloudflare Cloudflare Access (Zero Trust) alternative included on every Zipper plan.
Origin Connect
Origin Connect runs a small program on your server that dials Zipper. Zipper never needs an inbound hole. The Throne Room can then require sign-in. No public IP on the origin. This is a Cloudflare Cloudflare Tunnel alternative included on every Zipper plan.
Zipper Mail
Zipper Mail (also called Zipper Email) is transactional email on Zipper’s own MTA. Add a domain, publish SPF (include:_spf.tinyzipper.com), DKIM, and DMARC, verify DNS, then send with POST /api/v1/email/send (all plans) or SMTP at smtp.tinyzipper.com:587 on Starter+. Messages are DKIM-signed on this Global Server node and relayed by Postfix. Attachments, batch, schedule, tags, webhooks, and one-click unsubscribe are built in. Inbound stores encrypted messages and routes to mailbox, webhook, or function. Webmail at mail.tinyzipper.com. Not a marketing blast tool — batches cap at 50 recipients per message. This is a Cloudflare Transactional ESP + inbound routing alternative included on every Zipper plan.
Observe