Your AWS bill is paying for resources no one is using.
Connect with read-only credentials. StaleSweep sweeps every account in your organization and puts an estimated monthly cost against every idle volume, gateway and instance it finds — then leaves the decision to you.
14-day free trialNo credit cardRead-only accessRevocable anytime
The problem
Nobody decided to waste this money.
It accumulated.
Cloud waste isn't negligence, it's fragmentation. A team ships, a team reorganises, an engineer leaves, and the resource they created outlives the reason it existed. Every item below is small enough to ignore on its own. Together they're a line on your invoice.
94 days
The instance nobody stopped
Someone stopped an m5.2xlarge in March to debug a deploy. The compute stopped billing. The 500 GiB of attached storage did not.
200 GiB
The volume the migration left
A migration finished, the instance was replaced, and the old root volume detached cleanly — then sat there, unattached and fully billed, for two quarters.
$32.85
The gateway in the empty VPC
A NAT Gateway charges by the hour whether or not a single byte crosses it. The VPC around this one has had no instances in it since last summer.
How it works
Three steps. No agents to install.
From zero to your first findings in under a couple of minutes.
- 01
Connect, read-only
Deploy a CloudFormation template that creates a read-only IAM role, gated by a unique External ID only you and StaleSweep know. We never see or store access keys — and you can revoke access anytime by deleting the role.
sts:AssumeRole · ReadOnlyAccess · external ID
- 02
We scan for waste
StaleSweep checks every region against its full detector set, cross-referencing CloudWatch metrics and resource metadata to separate genuinely unused resources from things that just look quiet.
Every detector · all regions · all accounts
- 03
You decide what to do
Review findings with estimated monthly cost, suppress the ones that are expected, and act on the rest in the AWS console — StaleSweep never modifies or deletes anything on its own.
Estimated $/mo · suppression rules · zero write access
Example scan output
Every finding, with the number attached.
A finding without a cost is a chore. A finding with a cost is a decision. Everything StaleSweep surfaces carries an estimated monthly figure, so the list sorts itself into the order worth acting on.
Organization o-7f3a · last sweep 4 hours ago
READ-ONLY- Accounts
- 38
- Regions
- 17
- Findings
- 214
- Est. monthly waste
- $4,182.60
| Resource | Account | Region | Idle | Est. cost |
|---|---|---|---|---|
Stopped EC2 instance m5.2xlarge · 500 GiB attached | sandbox | us-west-2 | 138d | $41.20/mo |
Idle NAT Gateway 0 bytes processed | prod-net | eu-west-1 | 61d | $32.85/mo |
Unattached EBS volume 200 GiB gp3 | prod-data | us-east-1 | 94d | $18.40/mo |
Idle load balancer No healthy targets | staging | us-east-2 | 47d | $16.43/mo |
Orphaned snapshots ×12 Source volume deleted | prod-data | us-east-1 | 210d | $9.60/mo |
Unassociated Elastic IPs ×3 Not attached to any ENI | sandbox | eu-central-1 | 88d | $10.95/mo |
Showing 6 of 214 · sorted by estimated cost
Suppress, export, or open in the AWS console
Illustrative figures based on AWS list pricing. Your own numbers depend on your account.
Detectors
Every service you run, checked on your schedule.
Not just a report — a system that keeps watching after you've cleaned up.
- Unattached EBS volume
- Running web tier
- Idle NAT Gateway
- Primary database
- Orphaned snapshot
- Application load balancer
- Stopped instance
- Object store
- Unassociated Elastic IP
- Container service
- Empty VPC
- Event queue
- Idle load balancer
- Function runtime
- Stopped RDS instance
- Private subnet
- Unused IAM role
- CDN distribution
- Old AMI
- Cache cluster
Detectors for the waste that hides
Unattached EBS volumes, idle NAT Gateways, stopped EC2/RDS instances, unassociated Elastic IPs, empty VPCs, orphaned snapshots, and more — updated as AWS adds new ways to leave things running.
AWS Organizations, one connection
Connect your management account and StaleSweep discovers and scans every member account automatically — no per-account setup.
Scheduled scans
Set it once and StaleSweep keeps re-scanning on your schedule, so new waste gets caught the week it appears, not the quarter you finally go looking.
Exceptions
Silence expected noise — default VPCs, a specific tag, a whole region — by resource type, account, or tag, instead of re-triaging the same finding every scan.
SSO & SAML
Sign in with Google or Microsoft, or connect your own identity provider (Okta, Entra ID, Google Workspace) with domain-verified SAML SSO for your whole team.
Security
The strongest guarantee is the one we can't break.
StaleSweep holds no write permissions in your account. Not restricted ones, not audited ones — none. There is no code path that could delete your data, because there is no credential that would let it.
- Cost savings
- Identify and clean up idle, unattached, and overprovisioned resources quietly running up your bill.
- Stronger security posture
- Shrink your unmanaged cloud footprint — fewer forgotten resources means fewer things an attacker can find.
Read-only, always
A cross-account IAM role with an external ID. No long-lived credentials are ever stored, and nothing in your account is modified or deleted — by design, not by policy.
Tenant isolation in depth
Row-level security in the database sits underneath the application's own tenant checks, so a bug in one layer isn't sufficient to cross a tenant boundary.
Append-only audit
Every configuration change is written to an append-only audit log, readable from inside the product without opening a support ticket.
Pricing
Priced by what it covers, not who logs in.
A plan is a number of connected AWS accounts and a set of capabilities. Start on a 14-day trial without a card, and connect an account in about five minutes.
Priced by AWS accounts
The plan sets how many accounts StaleSweep can reach and which capabilities are switched on. That's the whole pricing model.
Every plan is read-only
Security posture isn't a paid tier. Cross-account role, external ID and zero write access are how the product works, on every plan.
Monthly or annual
Switch between them whenever. Annual agreements can be invoiced against a PO. Cancel from inside the product without a retention call.
Your next AWS bill is already smaller than you think.
Connect a read-only role and see what you’re paying for — on your own numbers, in your own account, within minutes.
14-day free trial · No credit card · Read-only access · Revocable anytime
