NetDiag is an AI-powered network diagnostics platform for AWS environments that identifies the root cause of cloud network failures and translates them into plain-English explanations. The platform connects via read-only IAM access to map live topology, detect configuration changes, and pinpoint what broke, what changed, and how to fix it. It offers a 5-minute setup, requires no agents, and provides a free tier to start.
Funding
Funding not disclosed
Founders
Product
Problem
Cloud network incidents are notoriously difficult to diagnose because relevant logs are scattered across multiple AWS services like CloudWatch, CloudTrail, ALB logs, and VPC flow logs, with no single view of what happened. Additionally, teams often lack visibility into who changed a security group rule, route table entry, or target group—and when—making it hard to determine if a change caused an outage. Existing tools were not built for this level of cross-service troubleshooting, leading to hours of manual investigation.
Solution
NetDiag connects to a customer's AWS account using a read-only IAM role and provides an AI-powered diagnostic platform that identifies the root cause of network failures in seconds. The service continuously maps the entire AWS network topology—including VPCs, subnets, ECS services, load balancers, and NAT gateways—and correlates it with CloudTrail event metadata to detect what changed and when. It translates complex technical findings into plain-English explanations, telling teams exactly what broke, what changed, and how to fix it. The platform also flags security misconfigurations and anomalies, offering a single pane of glass from outage to resolution without requiring agents or making any changes to the customer's infrastructure.
Target Audience
Primary customers are DevOps, SRE, and cloud infrastructure teams at companies running production workloads on AWS who need rapid incident response and network visibility. The platform is also suited for security engineers seeking to identify misconfigurations and audit network changes.
Features
- Live topology map showing VPCs, subnets, ECS services, load balancers, and NAT gateways, updated every 15 minutes
- AI-driven root cause analysis that correlates CloudTrail events with network configuration changes to identify the cause of incidents
- Read-only IAM role access with External ID protection, ensuring no changes are made to the customer's environment and all API calls are logged in CloudTrail
- Security misconfiguration and anomaly detection across security groups, route tables, and load balancer configurations
- Plain-English incident summaries that explain what broke, what changed, and recommended remediation steps
- Data storage in Neo4j AuraDB and PostgreSQL with AES-256-GCM encryption for credentials and TLS 1.2+ for all data in transit