πŸ—ΊοΈ Network Topology

An interactive map of your entire AWS network, updated daily.


FeatureDescription
Interactive graph Force-directed D3.js graph. VPCs, TGWs, Internet Gateways, NAT Gateways shown as AWS icons. Click any node to inspect it.
Environment groups VPCs automatically grouped by environment tag (production, staging, development, cde). Colour-coded rings show compliance status.
Reachability query The graph shows which VPCs can reach each other. Click any VPC node to see its reachable peers highlighted.
Reachability matrix Full NΓ—N matrix of all VPC pairs. Download as CSV.
CIDR map All CIDR blocks across all VPCs, with overlap detection highlighted.
Topology diff Banner shows what changed since the last scan β€” new peerings, new VPCs, changed tags.
Snapshot history Browse past topology snapshots. Compare any two snapshots.
Compute instances Click a VPC to see EC2 instances within each subnet β€” instance type, state, private IP.

πŸ›‘οΈ Compliance

Daily isolation monitoring with 365-day audit history and one-click compliance report.


FeatureDescription
Isolation rules Select two environment groups (e.g. production and staging) β€” Netway evaluates whether any network path exists between them on every scan.
Rule history 365 days of pass/fail results per rule. Immutable audit log.
Topology detectors CIDR conflict, orphaned VPC, CDE internet exposure, missing TGW propagation, and more.
Compliance report Signed HTML or PDF evidence report. Sections covering PCI-DSS 1.2.3, 1.2.4, 1.3.x, 1.4.1, 11.4.5 and SOC2 CC6.x, CC7.2, CC8.1.
Network diagram Auto-generated network diagram (PNG + SVG) using AWS Architecture Icons. Embedded in the compliance report.
Report signing HMAC-SHA256 signature on every report β€” proves integrity and origin.
Slack alerts Immediate alert when an isolation rule violation is detected.
Environment group inference Automatically infers environment groups from VPC tags. Manual override available.
RequirementCoverage
PCI-DSS 1.2.3Auto-generated network diagram
PCI-DSS 1.2.4Flow log traffic overlay on topology
PCI-DSS 1.3.1 / 1.3.2Routing + traffic plane isolation evidence
PCI-DSS 1.4.1CDE exposure detector
PCI-DSS 11.4.5365-day daily scan log
SOC2 CC6.1Environment group isolation rules
SOC2 CC6.6Internet exposure detection
SOC2 CC7.2Topology change detection
SOC2 CC8.1Change log in compliance report

πŸ’° Cost Optimisation

Detects avoidable AWS network spend from VPC flow logs.


Note: Netway detects multiple categories of avoidable network spend. Each finding includes the source resource, estimated monthly savings, and exact CLI fix command.
PatternTypical Saving
S3 via NAT Gateway$200–500/mo
Avoidable Internet Egress$500–8,000/mo
Cross-Region S3 Access$200–1,000/mo
Cross-AZ Database Traffic$50–200/mo
AWS APIs via NAT$30–150/mo
NAT Gateway in Wrong AZ$20–100/mo
ML Checkpoint via NAT$300–2,000/mo
GPU Cross-AZ Gradient Sync$100–800/mo
Inference Cold Start S3$50–400/mo
+ more patternsβ€”

πŸ“¦ Tiers

All plans start with a 14-day Enterprise trial. No credit card required.


Feature Starter Standard Enterprise
Topology graphβœ… read-only, 10 VPC maxβœ… Fullβœ… Full
Reachability queryβœ…βœ…βœ…
Reachability matrixβ€”βœ…βœ…
CIDR mapβœ…βœ…βœ…
Topology diffLast 2 snapshotsLast 30All
Compliance report (HTML)β€”βœ…βœ…
Compliance report (PDF)β€”β€”βœ…
Network diagram (PNG)β€”βœ…βœ…
Network diagram (SVG)β€”β€”βœ…
Snapshot history2 days180 days365 days
Isolation rules2 max5 maxNo enforced limit
Cost detectors2 (top patterns)AllAll
Topology detectors2 (CIDR, orphan)All 9All 9
Slack alertsβœ…βœ…βœ…
Email digestβœ…βœ…βœ…
Trial14-day Enterprise trial on signup