New — Iris AI drafts your firewall, routing & rate-limit rules. Explore AI features →

Ngris vs Vercel

Vercel hosts your frontend. Ngris runs your whole stack — and guards it.

Looking for a Vercel alternative that builds and hosts your front-end framework app behind a security edge? Ngris deploys the same way — connect a git repo or upload a .zip, and we run your npm/yarn/pnpm install and build in a sandboxed job, then serve the output on our global edge at an HTTPS URL with your own custom domain. We auto-detect and build React (CRA), Vite, Vue, Svelte/SvelteKit, Angular, Astro, Gatsby, Next.js (static export), Nuxt (generate) and Hugo (plus prebuilt static). The difference — and the reason to pick Ngris: every deployed site runs behind the same edge policy engine Ngris uses for tunnels — WAF, edge auth, rate limits, geo/CIDR rules and bot management, per route — with no second vendor to bolt on. This is an honest, feature-by-feature comparison: we only claim what our code ships today, and we state our scope plainly — including where Ngris is narrower than Vercel.

Read this first — scope. Ngris Deploy builds and hosts front-end framework and JAMstack apps — it runs your npm/yarn/pnpm install and build in a sandboxed job and serves the static output on the edge (React, Vite, Vue, Svelte/SvelteKit, Angular, Astro, Gatsby, Next.js static export, Nuxt generate, Hugo, plus prebuilt static). And it hosts the backend too — a Go, Node, or Python service (auto-detected), or any app with a Dockerfile (a Next.js server included) — built in a sandboxed job and run behind the same policy engine as your front end. That's live today. Ngris also runs per-request serverless / edge functions — a scale-to-zero function app type where you write a Web Fetch-style handler and Ngris wakes it on demand and idles it back to zero (deploy a long-running backend instead when you want an always-on service). Front end, back end, and functions, one platform, behind a real security edge (and, optionally, tunneling) — that's more than Vercel gives you.

Deploy your backend — Go, Node, Python, or any Dockerfile — behind the Ngris edge. Live now. Run your backend behind the same policy engine as your front end (WAF, edge auth, rate limits) — one platform, one edge, one bill. Go, Node, and Python services are auto-detected from your repo; bring a Dockerfile for anything else, a Next.js server included.

curl -fsSL https://ngris.com/install.sh | sh
See plans & deploy

Ngris pricing at a glance

$10/mo
Team
For professionals & power users — custom domains, the policy engine, WAF, and edge auth on your deploys.
$25/mo
Enterprise
Dedicated ports/IPs, SSO/RBAC, and priority support.

What Ngris adds on top of static hosting

Vercel set the bar for git-push deploys with preview URLs. Ngris gives you that workflow for static/SPA and wraps every site in a policy-enforcing security edge.

Builds your framework app

Connect a GitHub/GitLab repo for auto-deploy on push, upload a .zip, or one-call quick-deploy. Ngris auto-detects the framework and runs your npm/yarn/pnpm install and build (React, Vite, Vue, Svelte/SvelteKit, Angular, Astro, Gatsby, Next.js static export, Nuxt generate, Hugo — overridable) in a sandboxed job, then publishes the output to our global edge at a live HTTPS URL with custom domains.

Preview URLs & instant rollback

Every deploy gets its own preview URL (<deploy>.<your-domain>). Promotion is an atomic pointer flip, so rollback to any previous deploy is instant — no rebuild.

A WAF in front of your site

The differentiator: your deployed site runs behind Ngris’s per-endpoint policy engine — OWASP WAF, rate limits, IP/CIDR and geo rules, and JA3 bot management — applied per route. Vercel doesn’t ship an OWASP WAF or mTLS per route.

Edge authentication

Gate a whole site or a path with HTTP basic auth, mutual TLS (client CAs), an OAuth2 + PKCE portal, or JWT validation — enforced at the edge, before a request reaches your files. Ideal for staging sites, internal tools, and docs.

Env vars, secrets & build config

Per-app environment variables and encrypted secrets (masked in logs), plus publish-dir, custom 404, and SPA-fallback settings. Build logs stream live while your deploy runs.

One platform: expose or deploy

Ngris is a two-sided edge platform. Deploy a site to the edge, and tunnel a local or Kubernetes service through the same edge with the same policies — plus the Iris AI assistant to draft your firewall and rate-limit rules.

Ngris vs Vercel, feature by feature

“Yes” means the capability ships in Ngris today. For Vercel we mark only widely-known facts; where a capability isn’t applicable or varies by plan we say so plainly rather than guess. The rows where Vercel wins are marked honestly.

FeatureNgrisVercel
Build & hosting
Builds framework apps (npm/yarn/pnpm install + build)
React (CRA), Vite & Vue builds
Svelte/SvelteKit (static), Angular, Astro, Gatsby builds
Next.js static export, Nuxt generate, Hugo
Framework auto-detection (overridable)
Prebuilt / plain static hosting
Single-page app (SPA) hosting
Deploy by git push (GitHub/GitLab)
Deploy by zip / CLI upload
Global edge / CDN delivery
Custom domains + automatic TLS
Per-deploy preview URLs
Instant atomic rollback
Streamed build logs
Env vars + encrypted secrets
SPA fallback / custom 404 / publish dir
Backend & full-stack hosting
Backend / API hosting (Go, Node & Python auto-detected)
Run any Dockerfile — any language or framework, a Next.js server included
Where Vercel is broader
Serverless / edge functions (per-request FaaS)
Managed databases / storage
Build cache
Monorepo support
Custom install / build / output-dir override
Deep framework / integration ecosystem
Security & policy at the edge
Per-endpoint policy engine (17+ rule types)Built-inNot applicable
OWASP WAF in front of the siteBuilt-inNot applicable / check plan
Rate limitingNot applicable / check plan
IP / CIDR & geo restrictionsNot applicable / check plan
JA3 bot managementNot applicable
Edge basic authPassword protection / check plan
Mutual TLS (client CAs) per routeBuilt-inNot applicable
OAuth2 + PKCE / JWT edge authNot applicable / check plan
Beyond hosting
Tunnel a local / K8s service (expose)Not a feature
Kubernetes operator (CRDs + Gateway API)9 CRDsNot a feature
AI assistant for edge rules (Iris)Built-in (Iris)Not applicable
MCP server / AI-native control (manage from Claude)Built-in (mcp.ngris.com)Not applicable
Live request inspector + server-side replayBuilt-inNot applicable

Vercel’s feature set and pricing change over time and vary by plan — check vercel.com for their current tiers. “Not applicable” means the capability isn’t part of that product’s model; “check plan” means we aren’t asserting a yes or a no. Ngris Deploy builds & hosts framework/JAMstack front ends and backends (Go/Node/Python services, or any Dockerfile — a Next.js server included) live today, and runs scale-to-zero serverless / edge functions as a fifth app type — see the scope note above.

Where Ngris is still maturing

Honesty first — where Ngris Deploy is narrower than Vercel, and the flags we ship with today.

Serverless / edge functions — scale-to-zero

Ngris builds and hosts front-end framework and JAMstack apps (React, Vite, Vue, Svelte, Angular, Astro, Gatsby, Next.js static export, Nuxt generate, Hugo) and backends — a Go / Node / Python service, or any app with a Dockerfile (a Next.js server included), run behind the same policy engine. It also runs per-request serverless / edge functions: a scale-to-zero function app type where you write a Web Fetch-style handler and Ngris wakes it on demand and idles it back to zero. FaaS-first architectures are a first-class fit; for an always-on service, deploy a long-running managed backend.

No build cache or monorepo (yet)

Builds run fresh (no incremental cache) and it's one git repo per app (no monorepo path selection). You can override the detected install, build, and output-dir commands, but there are no multi-step build pipelines or the deep framework presets Vercel ships.

HTTP/3 is experimental

HTTP/3 / QUIC works but is not yet marked production-stable. HTTP/1.1 and HTTP/2 are the default delivery paths for your deployed site.

Iris autonomy is firewall-only

The Iris AI assistant can act autonomously only on firewall rules, and auto-reverts. Every other change is gated behind an explicit confirmation card with a dry-run.

Dedicated-IP enforcement is being hardened

Dedicated ports and IPs are built; full end-to-end enforcement of dedicated IPs is still being tightened. Talk to us before you depend on it in production.

Deploy in 60 seconds

1

Create an app and connect your repo

Connect a GitHub/GitLab repo (auto-deploy on push) — Ngris detects the framework and runs your install + build — or drop a .zip of an already-built site. Either way it serves the output at your edge URL.

2

Add a custom domain

Point your domain at the edge and Ngris provisions TLS automatically — every deploy still gets its own preview URL.

3

Turn on WAF, auth & rate limits

Attach a traffic policy, enable edge auth, or ask Iris to write a firewall rule — all per endpoint. And if you also need to expose a local service, the same CLI tunnels it:

curl -fsSL https://ngris.com/install.sh | sh

Deploying a specific stack? Read Deploy a React or Vite App: Ngris vs Vercel for the head-to-head walkthrough, or the broader Ngris vs Netlify and Vercel comparison.

Static hosting with a security edge. Free to start.

Developer is $0, Team is $10/mo, Enterprise is $25/mo. No credit card to get going.

Get Started Free View Pricing
Ask an AI to summarise this page