Features
Everything StaleSweep watches for you
Detection across compute, storage, database, networking, security and messaging — every finding costed, and traceable back to the evidence that flagged it.
Coverage
What we detect, by category
Detection is judgement, not a list query — every check is age-gated, so a resource provisioned yesterday is never flagged for having no traffic yet.
Compute
Stopped instances, idle running instances judged on CPU and network, unused machine images, orphaned launch templates, idle autoscaling groups and ECS clusters.
Storage
Unattached volumes, orphaned and redundant snapshots, unused container images, empty and stale buckets, abandoned multipart uploads.
Database
Idle instances, stale snapshots, idle read replicas (with a nudge toward suppression rules if they're DR standbys), unused tables, idle Redshift and OpenSearch clusters, idle cache clusters.
Networking
Unassociated Elastic IPs, empty VPCs, idle NAT gateways, unused endpoints and route tables, stale peering connections, empty hosted zones, idle distributions, load balancers with no targets, unused target groups.
Security & identity
Unused roles, users, policies and access keys; unused secrets; disabled or unused KMS keys; orphaned web ACLs; security groups that no launch template references.
Messaging & analytics
Idle queues and topics, idle clusters, orphaned alarms, log groups with no retention policy.
Capabilities
Not just a report — a system that keeps watching
Finding the waste once is the easy part. These are the pieces that keep it found after you've cleaned up.
Detectors for the waste that hides
Unattached EBS volumes, idle NAT Gateways, stopped EC2/RDS instances, unassociated Elastic IPs, empty VPCs, orphaned snapshots, and more — updated as AWS adds new ways to leave things running.
AWS Organizations, one connection
Connect your management account and StaleSweep discovers and scans every member account automatically — no per-account setup.
Scheduled scans
Set it once and StaleSweep keeps re-scanning on your schedule, so new waste gets caught the week it appears, not the quarter you finally go looking.
Exceptions
Silence expected noise — default VPCs, a specific tag, a whole region — by resource type, account, or tag, instead of re-triaging the same finding every scan.
SSO & SAML
Sign in with Google or Microsoft, or connect your own identity provider (Okta, Entra ID, Google Workspace) with domain-verified SAML SSO for your whole team.
Security
The strongest guarantee is the one we can't break.
StaleSweep holds no write permissions in your account. Not restricted ones, not audited ones — none. There is no code path that could delete your data, because there is no credential that would let it.
- Cost savings
- Identify and clean up idle, unattached, and overprovisioned resources quietly running up your bill.
- Stronger security posture
- Shrink your unmanaged cloud footprint — fewer forgotten resources means fewer things an attacker can find.
Read-only, always
A cross-account IAM role with an external ID. No long-lived credentials are ever stored, and nothing in your account is modified or deleted — by design, not by policy.
Tenant isolation in depth
Row-level security in the database sits underneath the application's own tenant checks, so a bug in one layer isn't sufficient to cross a tenant boundary.
Append-only audit
Every configuration change is written to an append-only audit log, readable from inside the product without opening a support ticket.
Your next AWS bill is already smaller than you think.
Connect a read-only role and see what you’re paying for — on your own numbers, in your own account, within minutes.
14-day free trial · No credit card · Read-only access · Revocable anytime