Skip to content

Your AWS bill is paying for resources no one is using.

Connect with read-only credentials. StaleSweep sweeps every account in your organization and puts an estimated monthly cost against every idle volume, gateway and instance it finds — then leaves the decision to you.

14-day free trialNo credit cardRead-only accessRevocable anytime

The problem

Nobody decided to waste this money. It accumulated.

Cloud waste isn't negligence, it's fragmentation. A team ships, a team reorganises, an engineer leaves, and the resource they created outlives the reason it existed. Every item below is small enough to ignore on its own. Together they're a line on your invoice.

  • 94 days

    The instance nobody stopped

    Someone stopped an m5.2xlarge in March to debug a deploy. The compute stopped billing. The 500 GiB of attached storage did not.

  • 200 GiB

    The volume the migration left

    A migration finished, the instance was replaced, and the old root volume detached cleanly — then sat there, unattached and fully billed, for two quarters.

  • $32.85

    The gateway in the empty VPC

    A NAT Gateway charges by the hour whether or not a single byte crosses it. The VPC around this one has had no instances in it since last summer.

How it works

Three steps. No agents to install.

From zero to your first findings in under a couple of minutes.

  1. 01

    Connect, read-only

    Deploy a CloudFormation template that creates a read-only IAM role, gated by a unique External ID only you and StaleSweep know. We never see or store access keys — and you can revoke access anytime by deleting the role.

    sts:AssumeRole · ReadOnlyAccess · external ID

  2. 02

    We scan for waste

    StaleSweep checks every region against its full detector set, cross-referencing CloudWatch metrics and resource metadata to separate genuinely unused resources from things that just look quiet.

    Every detector · all regions · all accounts

  3. 03

    You decide what to do

    Review findings with estimated monthly cost, suppress the ones that are expected, and act on the rest in the AWS console — StaleSweep never modifies or deletes anything on its own.

    Estimated $/mo · suppression rules · zero write access

Example scan output

Every finding, with the number attached.

A finding without a cost is a chore. A finding with a cost is a decision. Everything StaleSweep surfaces carries an estimated monthly figure, so the list sorts itself into the order worth acting on.

Organization o-7f3a · last sweep 4 hours ago

READ-ONLY
Accounts
38
Regions
17
Findings
214
Est. monthly waste
$4,182.60
ResourceAccountRegionIdleEst. cost

Stopped EC2 instance

m5.2xlarge · 500 GiB attached

sandboxus-west-2138d$41.20/mo

Idle NAT Gateway

0 bytes processed

prod-neteu-west-161d$32.85/mo

Unattached EBS volume

200 GiB gp3

prod-dataus-east-194d$18.40/mo

Idle load balancer

No healthy targets

stagingus-east-247d$16.43/mo

Orphaned snapshots ×12

Source volume deleted

prod-dataus-east-1210d$9.60/mo

Unassociated Elastic IPs ×3

Not attached to any ENI

sandboxeu-central-188d$10.95/mo

Showing 6 of 214 · sorted by estimated cost

Suppress, export, or open in the AWS console

Illustrative figures based on AWS list pricing. Your own numbers depend on your account.

Detectors

Every service you run, checked on your schedule.

Not just a report — a system that keeps watching after you've cleaned up.

  • Unattached EBS volume
  • Running web tier
  • Idle NAT Gateway
  • Primary database
  • Orphaned snapshot
  • Application load balancer
  • Stopped instance
  • Object store
  • Unassociated Elastic IP
  • Container service
  • Empty VPC
  • Event queue
  • Idle load balancer
  • Function runtime
  • Stopped RDS instance
  • Private subnet
  • Unused IAM role
  • CDN distribution
  • Old AMI
  • Cache cluster
  • Detectors for the waste that hides

    Unattached EBS volumes, idle NAT Gateways, stopped EC2/RDS instances, unassociated Elastic IPs, empty VPCs, orphaned snapshots, and more — updated as AWS adds new ways to leave things running.

  • AWS Organizations, one connection

    Connect your management account and StaleSweep discovers and scans every member account automatically — no per-account setup.

  • Scheduled scans

    Set it once and StaleSweep keeps re-scanning on your schedule, so new waste gets caught the week it appears, not the quarter you finally go looking.

  • Exceptions

    Silence expected noise — default VPCs, a specific tag, a whole region — by resource type, account, or tag, instead of re-triaging the same finding every scan.

  • SSO & SAML

    Sign in with Google or Microsoft, or connect your own identity provider (Okta, Entra ID, Google Workspace) with domain-verified SAML SSO for your whole team.

Security

The strongest guarantee is the one we can't break.

StaleSweep holds no write permissions in your account. Not restricted ones, not audited ones — none. There is no code path that could delete your data, because there is no credential that would let it.

Cost savings
Identify and clean up idle, unattached, and overprovisioned resources quietly running up your bill.
Stronger security posture
Shrink your unmanaged cloud footprint — fewer forgotten resources means fewer things an attacker can find.
  • Read-only, always

    A cross-account IAM role with an external ID. No long-lived credentials are ever stored, and nothing in your account is modified or deleted — by design, not by policy.

  • Tenant isolation in depth

    Row-level security in the database sits underneath the application's own tenant checks, so a bug in one layer isn't sufficient to cross a tenant boundary.

  • Append-only audit

    Every configuration change is written to an append-only audit log, readable from inside the product without opening a support ticket.

Pricing

Priced by what it covers, not who logs in.

A plan is a number of connected AWS accounts and a set of capabilities. Start on a 14-day trial without a card, and connect an account in about five minutes.

  • Priced by AWS accounts

    The plan sets how many accounts StaleSweep can reach and which capabilities are switched on. That's the whole pricing model.

  • Every plan is read-only

    Security posture isn't a paid tier. Cross-account role, external ID and zero write access are how the product works, on every plan.

  • Monthly or annual

    Switch between them whenever. Annual agreements can be invoiced against a PO. Cancel from inside the product without a retention call.

Your next AWS bill is already smaller than you think.

Connect a read-only role and see what you’re paying for — on your own numbers, in your own account, within minutes.

14-day free trial · No credit card · Read-only access · Revocable anytime