VNet IQ / Docs

VNet IQ documentation

Everything you need to go from a read-only connection to a deconflicted, well-planned IP estate across AWS, Azure, and Google Cloud.

How VNet IQ works

VNet IQ is a read-only intelligence layer on top of your existing cloud networks. The whole workflow is four steps — and you never grant write access to your infrastructure:

  1. Connect — create a read-only role in each cloud and connect it. Connect a cloud →
  2. Discover — VNet IQ syncs every VPC, VNet, subnet, and address range automatically, on a schedule.
  3. Deconflict & plan — review conflicts, organise IP pools, declare on-prem ranges, and hold future reservations.
  4. Reserve — allocate right-sized CIDRs from the UI, or straight from your pipeline with Terraform and the REST API.

Before you begin

Sign in to app.vnetiq.com with your Microsoft (Entra ID) or Google account — there is no separate password to manage. You land in a workspace that starts on a 7-day full-feature trial, so you can follow every guide below end to end.

Roles

Everyone in a workspace has one of three roles. Owner manages members, billing, and API tokens; Editor can create pools, connections, reservations, and trigger syncs; Viewer is read-only (and can export CSV). Each guide notes the role it needs.

Pick a guide

Each tutorial is a short, click-and-go walkthrough with the exact buttons and fields you'll see in the app.

  • Connect a cloud — Add a read-only AWS, Azure, or Google Cloud connection and let VNet IQ map your networks. (Any plan · Editor)
  • Create a pool — Organise your address space into named root and child pools, and track utilisation. (Any plan · Editor)
  • Static (on-prem) CIDRs — Declare on-prem ranges so VNet IQ flags overlaps with your cloud networks. (Starter+ · Editor)
  • Future reservations — Hold CIDR space for what is coming next, before a single resource ships. (Pro+ · Editor)
  • Terraform & API — Allocate CIDRs from your pipeline with the Terraform provider or the REST allocation API. (Pro Plus+ · Owner)
Read-only, always

VNet IQ only ever reads from your clouds. The single thing it writes to is its own database — when you allocate a CIDR from a reservation. You can revoke its access on your side in about 60 seconds. See the Security page for the full access model.

Ready to try it?

Start free — connect a read-only role and see your whole IP estate.

Start free