For developers and teams

Delivery from hardware near your visitors

Static sites, assets and edge functions, served from nodes in the same metro area as the person requesting them. Deployed with one command.

Start deploying (opens in a new tab)Read how it works

How deploying works

Four steps, and the fourth is the one that matters — you do not wait for a global propagation window.

  1. Point us at a build

    Images, video, Javascript, PDFs — any static files.

  2. We sign and chunk it

    Every object is hashed so a node cannot alter what it serves.

  3. It spreads by demand

    Nodes pull what their Metro Area asks for, not the whole site.

  4. Purge is immediate

    Invalidation is a signature change, not a cache sweep.

$ export EE_CDN_TOKEN=…
$ ee-deploy ./dist --domain sub.domain.tld --project proj_abc
Packaging /home/user/projects/site-name/dist as a Level 0 workload…
Content hash 185210ddc1c65e0f0ab4e4be0dcf0d825880aaaa29e91f36d1b8305566479d44
Uploaded 0.25 MB — 185210ddc1c65e0f… (alias grown-fowl)
Requested domain binding sub.domain.tld → 185210ddc1c65e0f…
Propagation takes up to ~90s (alias cache 60s, edge domain cache 30s, heartbeat 30s). Confirm the binding actually took with:
curl -sS -o /dev/null -w '%{http_code}\n' https://sub.domain.tld/

Output from a real deploy. The path, hash and alias are illustrative.

What you get

Cache rules you write

Per-path TTLs, stale-while-revalidate, vary on header. Declared on workload refresh.

Origin shielding

Regional gateways absorb metro area cache misses so your origin sees a fraction of the traffic.

TLS 1.3, end to end

Certificates are issued and renewed for you. A node never holds a private key for your content.

Logs you can read

Request logs are streamed to your bucket, or a daily roll-up. No dashboard required.

Custom domains

Apex or subdomain, with automatic certificates and a CAA record we do not need to own.

Per-gigabyte pricing

One rate for delivered bytes. No request charges, no regional multipliers, no egress cliff. Free during the open beta.

What a node can and cannot see

For a Level 1 workload, where your content is encrypted before it reaches us. A simple table of facts, not pararaphs of text.

What the node handlesWhat the node seesCan the node read it?
Your contentAES-256-GCM ciphertext, cached as hash-named blocks.No. It never has the key.
The decryption keyNothing. The key stays in the link's URL fragment, which browsers never send to a server.It never reaches the node.
Page pathsThe path each visitor requests, logged in plain text.Yes. Level 1 hides content, not which page was asked for.
File sizesThe approximate size of each object.Yes. Compressed ciphertext length tracks the original.
Visitor IPsEach visitor's address, needed to complete the connection.Not written to the node's request log.

Before you ask

What happens when a node goes offline mid-request?

Every request targets multiple nodes simultaneously. With multiple redundant nodes in each metro area, a single downed node doesn't affect delivery.

How does this compare to a data-center CDN?

With an adequate number of nodes in a metro area, Evolving Edge performs as well — or better — than a data center CDN. Benchmarks coming soon.

Can I run this alongside an existing CDN?

Evolving Edge works as your primary or secondary CDN.

Deploy something small first

A static site takes about four minutes end to end, and it's free during the open beta.

Start deploying (opens in a new tab)