Privacy Policy

Last updated: July 2026

1. Introduction

NetDiag ('we', 'us', 'our') operates netdiag.co and provides cloud network diagnostic services. This policy explains how we collect, use, and protect your information when you use our platform.

2. Information We Collect

Account information

  • Email address
  • Company name
  • Password (bcrypt hashed — never stored in plaintext)

AWS connectivity data

  • IAM Role ARN (encrypted with AES-256-GCM)
  • External ID (encrypted with AES-256-GCM)
  • AWS Account ID
  • AWS Region

Network topology metadata

  • VPC IDs, CIDR blocks, subnet configurations
  • Security group rules and configurations
  • Route table configurations
  • Load balancer configurations
  • EC2 instance metadata (IDs, types, states)
  • ECS cluster and service names
  • IAM role names and policy summaries
  • CloudTrail event metadata

What we do NOT collect

  • Raw VPC Flow Log data (queried in your account, never copied)
  • Raw ALB access log data (queried in your account, never copied)
  • Application data or customer PII from your workloads
  • Network traffic content

3. How We Use Your Information

  • To provide network topology mapping and diagnostic services
  • To detect security misconfigurations and anomalies
  • To send alerts and notifications you configure
  • To improve our services

We never sell your data to third parties.

4. Data Storage and Security

  • Network topology data stored in Neo4j AuraDB (AWS US-East, SOC 2 Type II)
  • Account data stored in Railway PostgreSQL (US-East)
  • AWS credentials encrypted with AES-256-GCM before storage
  • All data in transit protected with TLS 1.2+
  • All data stored in the United States

5. AWS Access

  • NetDiag accesses your AWS account using a read-only IAM role you create
  • We use an External ID to prevent confused deputy attacks
  • All NetDiag API calls to your AWS account are logged in your CloudTrail
  • You can revoke our access at any time by deleting the CloudFormation stack

6. Data Retention

  • Account data: retained until account deletion
  • Network topology data: retained until account deletion
  • Incident and audit history: 90 days (Starter), 1 year (Enterprise)
  • You can request data deletion at any time

7. Data Sharing

We share data with the following sub-processors to operate our service:

We do not sell data to advertisers or data brokers.

8. Your Rights

  • Access your data: contact support@netdiag.co
  • Delete your data: contact support@netdiag.co — completed within 30 days
  • Export your data: available from the dashboard
  • Opt out of non-essential communications: unsubscribe link in emails

9. Security Incidents

We will notify affected users within 72 hours of discovering a security breach. To report a security concern, contact security@netdiag.co.

10. Children's Privacy

NetDiag is not directed at children under 13. We do not knowingly collect data from children. If you believe we have inadvertently collected such data, contact us immediately.

11. Changes to This Policy

We will notify users of material changes via email at least 14 days before they take effect. Continued use of the service after the effective date constitutes acceptance of the updated policy.

12. Contact

NetDiag
Email: support@netdiag.co
Website: netdiag.co