PRIVACY · SECURITY · COMPLIANCE
Your Data. Your Network.
Your Control.
Last updated: June 2026 · NetPol Enterprise Dashboard
What Data We Store
✓Minimal Data Architecture
NetPol Enterprise is designed to store the absolute minimum. Your switch data, configurations and historical logs stay on your NetPol node — not on our servers.
The Enterprise Dashboard stores only:
- Account information — company name, email address, password (hashed, never stored in plain text)
- Node registration details — site name, hostname, IP address, API key
- Latest snapshot — the most recent data push from each node (~10–15KB per node). This is overwritten on every push — no historical data is retained on the Enterprise server
- Support tickets — submitted by you, including any screenshots you choose to attach
We do not store: switch configurations, historical metrics, syslog data, interface counters over time, or any data that remains on your NetPol node.
How We Use Your Data
✓One Purpose Only
Your data is used exclusively to provide the NetPol Enterprise Dashboard service. We do not use it for advertising, analytics, AI training, or any other purpose.
We explicitly commit to the following:
- Your data will never be sold to third parties
- Your data will never be used for advertising or marketing purposes
- Your data will never be used to train AI or machine learning models
- Your network topology and switch data will never be shared with any party outside your account
- Support ticket contents are only accessed by NetPol support staff to resolve your issue
Security Measures
Tenant Isolation
Every account is strictly isolated. Your nodes, data and support tickets are only visible to your account and NetPol administrators. Database queries are enforced at the application level to prevent cross-account data access.
Encryption in Transit
All communication between your NetPol nodes and the Enterprise Dashboard is encrypted via HTTPS/TLS (Let's Encrypt SSL). API keys use cryptographically secure random generation.
Password Security
Passwords are hashed using SHA-256 and never stored in plain text. We recommend using a strong, unique password for your Enterprise account.
API Key Authentication
Each node uses a unique API key (prefix: npk_) for authentication. Keys are generated using Python's cryptographically secure secrets module. Keys can be revoked at any time by deleting and re-registering the node.
Self-Hosted & Air-Gapped Deployments
For organisations with strict data sovereignty or air-gap requirements, NetPol Enterprise is available as a self-hosted download. In this mode:
- The Enterprise Dashboard runs entirely on your own infrastructure
- No data leaves your network — zero cloud dependency
- Suitable for OT/SCADA environments with internet-restricted policies
- License validation uses a locally-verified signed key — no phone-home required
Data Retention & Deletion
- Snapshots — overwritten on every node push. No historical data accumulates
- Account data — retained while your account is active
- On cancellation — all account data, nodes and snapshots are deleted within 30 days of account closure
- Support tickets — retained for 12 months for quality assurance, then deleted
- Immediate deletion — contact support@netpol.io to request immediate data deletion at any time
Compliance & Hosting
- Hosting — Cloud Enterprise is hosted on Linode (Akamai) infrastructure in the Asia-Pacific region
- Australian Business — NetPol is an Australian business based in Perth, Western Australia
- Privacy Act — We comply with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs)
- IEC 62443 — NetPol is designed for use in IEC 62443 compliant OT environments