New — Iris AI drafts your firewall, routing & rate-limit rules. Explore AI features →

Edge infrastructure, rebuilt for the AI era

Ngris is one control plane for secure tunnels, an API gateway, a WAF, and identity-aware access — with an AI assistant, Iris, that previews every change against your real traffic and undoes anything that hurts.

Start free Read the docs

One platform for the whole request path — from localhost to production Kubernetes to AI pipelines — behind a single, observable, AI-native control plane.

Why we built Ngris

Existing tools treated ingress as an afterthought. Tunneling tools were built for one person debugging a webhook on a Friday afternoon. Load balancers assumed a team of platform engineers. Neither was built for a world where the traffic — and increasingly the operator — is an AI.

We wanted a single platform that handles local development, production traffic, and model routing with the same simple interface — and that a language model can safely operate on your behalf. That last part changes everything: an AI can only manage infrastructure if it can predict the blast radius before it acts and verify and undo after. So we built that in from the start.

The old ingress stack wasn't built for this

How a legacy setup compares to Ngris, across the things that actually slow teams down.

DimensionLegacy stackNgris
SetupProxies, DNS, certs, and a load balancer wired by handOne agent, one command, live in seconds
ObservabilityBolted on later, if at allPer-request traffic inspector built in
SecuritySeparate WAF, separate auth, separate configFirewall, rate limits, and identity-aware access in one control plane
ChangesEdit, deploy, hopePreview the blast radius against real traffic, then apply
AIA chatbot bolted to a dashboardAn assistant that acts within your limits, verifies, and auto-rolls-back
Multi-regionDuplicate the whole stack per regionOne global control plane, region-aware edge

“Infrastructure should be observable by default, secure by design, and safe for both people and AI to operate.”

The principle we measure every feature against.

What we believe

Observable by default

You should be able to see every request the moment it flows — not after you've wired up a separate stack for it.

Secure by design

Firewall, rate limiting, and identity-aware access are part of the platform, not an add-on you remember too late.

Simple to operate

The same interface from localhost to production. If it takes a runbook to change a rule, we got it wrong.

AI you can trust

An assistant only earns autonomy if it previews impact, stays inside your permissions, and can undo its own mistakes.

How we build

A small set of rules we hold ourselves to.

Ship the safe path

Every change to a rule is previewed against real traffic first. A "what would this do?" answer comes before "apply."

Nothing without a way back

If an automated action can't be verified and reversed, it stays a human decision.

One control plane

Tunnels, gateway, WAF, and access share one config and one source of truth — no drift between four tools.

Least privilege, always

Fine-grained roles, audit logs, and hard limits — for your team and for the AI acting on your behalf.

Built to comply

Security isn't a page — it's how the platform is put together.

TLS 1.3 everywhere, encrypted at rest, SSO/SAML and RBAC for your whole org, and a per-account audit log of every change — including everything the AI does. Enterprise plans add dedicated regions, custom SLAs, and compliance packages for regulated industries.

TLS 1.3 GDPR / CCPA SSO / SAML Encrypted at rest Audit logging RBAC

Read our security page

Bring your infrastructure into the AI era.

Start free in minutes, or talk to us about a rollout tailored to your org.

Start free Talk to Sales
Ask an AI to summarise this page
Iris