Proudly made and hosted in the European Union.Europe 🇪🇺 Read our story →

Fast, simple, secure, sovereign.

On European soil.

On Drift you sketch your app on Friday, deploy it on Sunday,
and your first users arrive on Monday.

15+building blocks

Build it in your head, run it in our engine.

The terminal above just used three of these blocks at once, in 1.8 seconds. NoSQL, queues, schedules, secrets, blobs. The pieces almost any app you can think of is made of.

Back to the basicsDrift offers everything you need to compose a fast and secure app, and nothing more. If you can write it in one night, you should be able to deploy it in one night too.

A hyposcalerSmall on purpose, rather than not yet large. A short catalogue is not a short list of parts: the network boundary, the TLS, the encryption at rest and the isolation are all there on the first deploy. They are simply not optional, and not sold separately.

The five pillarsEvery Drift app is built from five pillars. These primitives talk to each other for you. The infrastructure underneath does not disappear. It stops being your job to assemble, and stops being something you can leave switched off.

Your code, as functions. Write an ordinary function, name it in your Driftfile, and Atomic builds it, gives it a route and guards it. No framework to learn and no server to configure.

FunctionsServerless compute in six languages, deployed by one decorator.
ElementsA single-language backend: flat files, one dependency manifest.
TriggersAn HTTP route or a queue message, declared on the function.
SchedulesA cron line in the Driftfile that runs a function on a timer.
API keysPer-function keys checked against an X-API-Key header.

Your slice's data layer. Documents, SQL, blobs, queues, secrets and a realtime hub, all reached from the SDK by name, with no connection string to manage and nothing to provision.

NoSQLJSON document collections with lookups by id and field filters.
SQLPer-slice SQLite databases with schemas and transactions.
BlobsBinary object storage for files and uploads, organised by bucket.
SecretsEncrypted configuration (AES-256-GCM), injected into your functions.
QueuesFIFO message queues that can trigger functions.
CacheFast key/value store with an optional TTL.
LocksDistributed locks so work isn't processed twice.
RealtimeIn-slice pub/sub. Live messages fanned out over WebSocket.

Your site, served on your slice's own URL, with your API on the same origin at /api. There is no CORS to configure because there is no second origin to configure it against.

SitesStatic sites and framework builds, one command, automatic TLS, custom domains, per-branch previews.

Identity, verified. Passwordless device keys, tokens your slice signs itself, an encrypted keyring and per-identity storage. Deed verifies a signature; it never decides who you are.

KeyAuthPasswordless device-key auth (Ed25519): a challenge/verify handshake issuing a session JWT.
JWTGeneral-purpose HS256 sign/verify with your slice's own signing key.
VaultZero-knowledge, user-scoped recovery store: the slice holds ciphertext it can't read.
LinkMulti-device continuity: enroll a second device via a signed attestation, no shared secrets.
PocketE2EE per-identity app data, following an identity across every enrolled device.
Edge

How a slice is reached, and how far it can reach back. Custom domains, a gate in front of the site, private calls to your other slices, and the allowlist your functions dial out through.

DomainsCustom hostnames on your slice, verified by TXT, each with a certificate issued on first request.
Site authA username and password in front of the whole site, for anything that is not public yet.
LinksCall another slice you own over a private path, with no public hop in between.
EgressDeclare where your functions may connect out to. Private ranges and the control plane are refused on every slice.

Every one of these blocks is already provisioned, networked and encrypted before you write a line. Where all of it runs, and whose law reaches it, is next.

0foreign-owned links

European, full stop.

Built in the EU, hosted in the EU, owned in the EU. A region is only a location. Jurisdiction is who can compel access, and nothing in the path your slice's data takes answers to anybody else.

Where does the data physically sit?
On European infrastructure, in one European region.
Whose law governs it?
European law, and no other.
Who operates the machines?
Drift, in Europe.
Can a foreign legal process reach it?
There is no foreign-owned link in the slice's data path for one to act on.

Transactional email, meaning the signup code and the renewal notices, goes out through Microsoft 365. Your account's email address therefore passes through a company with a US parent, even though the entity and the servers are Irish. Your slice never does: not the source, the database, the blobs, the secrets, the identities or the site. The transport is moving to an EU-owned provider, and until it has, this is where the argument above costs us something. Data processing states the full scope.

None of this is a setting you turn on, and none of it is a region you select. It is where the company is, whose courts reach it, and what the data path is made of. Whether you could ever leave is the next question.

100%portable

Stay with us because you want to, not because leaving is hard.

Being hosted in the EU was one half of a deal; this is the other half. Portable by default. No lock-in: export your project and run it somewhere else, or self-host it.

12 January 2027 The law

From that date the EU Data Act makes portability a legal right for every cloud customer in Europe, not just good practice.

Already Drift
$ drift slice snapshot download

One command, and everything you handed us comes back: your original source code, your secrets, every NoSQL document, your blobs, your queues and your Canvas sites, as a plain tar.gz.

Your source arrives with every Drift-generated wrapper stripped out. No proprietary format, nothing to reverse-engineer.

To us, portability was a fundamental design decision, not an afterthought, and not something we implemented because we were forced to. The best way to test that claim costs nothing.

Freeforever

Never capped, never upsold.

None of what you just read costs anything to try first. Real functions, a real database, a real website, for your experiments. No trial, no credit card.

You get one free Slice the moment you register. Use it to experiment, or to actually ship something: a personal portfolio, a landing page, a blog. It's yours; what you build with it is up to you.

You can always create new Slices and pay for what you need. And if you outgrow one, you can resize it piecemeal (maybe one more function, maybe 20 MB more SQL) and pay only the difference.

Atomic functions
5
Scheduled job
1
Function memory
40 MB
NoSQL collections (40 MB)
2
SQL database (10 MB)
1
Blobs (50 MB)
10
Queue
1
Realtime conns.
50
Canvas website
1
  • Personal portfolio
  • Blog
  • Restaurant landing page
  • Guestbook
  • Small chat / collab room
  • Link-in-bio page
  • Waitlist page
  • Hackathon prototype
  • Hobby API prototype

That is the whole free tier: no meter running underneath it, nothing held back until you upgrade. Installing the CLI is the only step left.

Ship something this weekend.

You watched this exact sequence run at the top of the page. Install the CLI, take your free slice, then point it at the folder you are already standing in and let it do the rest.

Drift is in closed alpha. We will update you when it is ready.

# install the CLI
$ brew install ondrift/tap/drift

# take your free slice: no card, no browser
$ drift slice create myapp --free

# ship the project you are standing in
$ drift file apply