Ngris vs Netlify
Looking for a Netlify alternative that puts a security edge in front of your site? Ngris deploys a static site or SPA the same way — drop a .zip or connect a git repo, we build it, and it goes live on our global edge at an HTTPS URL with your own custom domain. What’s different: every deployed site sits behind the same edge policy engine Ngris uses for tunnels — WAF, edge auth, rate limits, geo/CIDR rules and bot management, per route. This is an honest, feature-by-feature comparison; Netlify is an excellent platform, and we only claim what our code ships today — including where Ngris is narrower than Netlify.
Read this first — scope. Ngris Deploy hosts static sites and single-page apps only. It has no serverless / edge functions, no framework SSR (e.g. a Next.js server), no build cache, no monorepo support, and no custom build scripts. Netlify does all of those and has a large plugin ecosystem. If you need functions or SSR, Netlify is the better fit — Ngris does not replace them. Ngris is for teams who want static/SPA hosting plus a real security edge (and, optionally, tunneling) in one platform.
Ngris pricing at a glance
What Ngris adds on top of static hosting
Netlify pioneered git-push static deploys with preview URLs. Ngris gives you that workflow and wraps every site in a policy-enforcing security edge.
Deploy by zip or git
Upload a .zip, connect a GitHub/GitLab repo for auto-deploy on push, or one-call quick-deploy. Ngris runs the build (static-build-worker) and publishes to our global edge at a live HTTPS URL with custom domains.
Preview URLs & instant rollback
Every deploy gets its own preview URL (<deploy>.<your-domain>). Promotion is an atomic pointer flip, so rollback to any previous deploy is instant — no rebuild.
A WAF in front of your site
The differentiator: your deployed site runs behind Ngris’s per-endpoint policy engine — OWASP WAF, rate limits, IP/CIDR and geo rules, and JA3 bot management — applied per route. Netlify doesn’t ship an OWASP WAF or mTLS per route.
Edge authentication
Gate a whole site or a path with HTTP basic auth, mutual TLS (client CAs), an OAuth2 + PKCE portal, or JWT validation — enforced at the edge, before a request reaches your files. Ideal for staging sites, internal tools, and docs.
Env vars, secrets & build config
Per-app environment variables and encrypted secrets (masked in logs), plus publish-dir, custom 404, and SPA-fallback settings. Build logs stream live while your deploy runs.
One platform: expose or deploy
Ngris is a two-sided edge platform. Deploy a site to the edge, and tunnel a local or Kubernetes service through the same edge with the same policies — plus the Iris AI assistant to draft your firewall and rate-limit rules.
Ngris vs Netlify, feature by feature
“Yes” means the capability ships in Ngris today. For Netlify we mark only widely-known facts; where a capability isn’t applicable or varies by plan we say so plainly rather than guess. The rows where Netlify wins are marked honestly.
| Feature | Ngris | Netlify |
|---|---|---|
| Deploy & hosting | ||
| Static site hosting | ||
| Single-page app (SPA) hosting | ||
| Deploy by git push (GitHub/GitLab) | ||
| Deploy by drag-and-drop / zip upload | ||
| Global edge / CDN delivery | ||
| Custom domains + automatic TLS | ||
| Per-deploy preview URLs | ||
| Instant atomic rollback | ||
| Streamed build logs | ||
| Env vars + encrypted secrets | ||
| SPA fallback / custom 404 / publish dir | ||
| Where Netlify is broader | ||
| Serverless / edge functions | ||
| Framework SSR (e.g. Next.js server) | ||
| Build cache | ||
| Monorepo support | ||
| Custom build scripts | ||
| Large plugin / integration ecosystem | ||
| Security & policy at the edge | ||
| Per-endpoint policy engine (17+ rule types) | Built-in | Not applicable |
| OWASP WAF in front of the site | Built-in | Not applicable |
| Rate limiting | Not applicable | |
| IP / CIDR & geo restrictions | Not applicable / check plan | |
| JA3 bot management | Not applicable | |
| Edge basic auth | Password protection / check plan | |
| Mutual TLS (client CAs) per route | Built-in | Not applicable |
| OAuth2 + PKCE / JWT edge auth | Not applicable / check plan | |
| Beyond hosting | ||
| Tunnel a local / K8s service (expose) | Not a feature | |
| Kubernetes operator (CRDs + Gateway API) | 9 CRDs | Not a feature |
| AI assistant for edge rules (Iris) | Built-in (Iris) | Not applicable |
| Live request inspector + server-side replay | Built-in | Not applicable |
Netlify’s feature set and pricing change over time and vary by plan — check netlify.com for their current tiers. “Not applicable” means the capability isn’t part of that product’s model; “check plan” means we aren’t asserting a yes or a no. Ngris Deploy is static/SPA only — see the scope note above.
Where Ngris is still maturing
Honesty first — where Ngris Deploy is narrower than Netlify, and the flags we ship with today.
Static & SPA only — no functions or SSR
Ngris hosts static sites and single-page apps. There are no serverless/edge functions and no framework SSR (no Next.js server, no API routes). If your app needs server-side rendering or backend functions, keep them on Netlify (or run them behind an Ngris tunnel).
No build cache, monorepo, or custom scripts
Builds run fresh (no incremental cache), one git repo per app (no monorepo path selection), and the build is a standard static build — no arbitrary custom build script or plugin marketplace like Netlify’s.
HTTP/3 is experimental
HTTP/3 / QUIC works but is not yet marked production-stable. HTTP/1.1 and HTTP/2 are the default delivery paths for your deployed site.
Iris autonomy is firewall-only
The Iris AI assistant can act autonomously only on firewall rules, and auto-reverts. Every other change is gated behind an explicit confirmation card with a dry-run.
Dedicated-IP enforcement is being hardened
Dedicated ports and IPs are built; full end-to-end enforcement of dedicated IPs is still being tightened. Talk to us before you depend on it in production.
Deploy in 60 seconds
Create an app and push your build
Connect a GitHub/GitLab repo (auto-deploy on push) or drop a .zip of your build output. Ngris builds it and serves it at your edge URL.
Add a custom domain
Point your domain at the edge and Ngris provisions TLS automatically — every deploy still gets its own preview URL.
Turn on WAF, auth & rate limits
Attach a traffic policy, enable edge auth, or ask Iris to write a firewall rule — all per endpoint. And if you also need to expose a local service, the same CLI tunnels it:
curl -fsSL https://ngris.com/install.sh | shStatic hosting with a security edge. Free to start.
Developer is $0, Team is $10/mo, Enterprise is $25/mo. No credit card to get going.