Skip to content

Features

Everything StaleSweep watches for you

Detection across compute, storage, database, networking, security and messaging — every finding costed, and traceable back to the evidence that flagged it.

Coverage

What we detect, by category

Detection is judgement, not a list query — every check is age-gated, so a resource provisioned yesterday is never flagged for having no traffic yet.

  • Compute

    Stopped instances, idle running instances judged on CPU and network, unused machine images, orphaned launch templates, idle autoscaling groups and ECS clusters.

  • Storage

    Unattached volumes, orphaned and redundant snapshots, unused container images, empty and stale buckets, abandoned multipart uploads.

  • Database

    Idle instances, stale snapshots, idle read replicas (with a nudge toward suppression rules if they're DR standbys), unused tables, idle Redshift and OpenSearch clusters, idle cache clusters.

  • Networking

    Unassociated Elastic IPs, empty VPCs, idle NAT gateways, unused endpoints and route tables, stale peering connections, empty hosted zones, idle distributions, load balancers with no targets, unused target groups.

  • Security & identity

    Unused roles, users, policies and access keys; unused secrets; disabled or unused KMS keys; orphaned web ACLs; security groups that no launch template references.

  • Messaging & analytics

    Idle queues and topics, idle clusters, orphaned alarms, log groups with no retention policy.

Capabilities

Not just a report — a system that keeps watching

Finding the waste once is the easy part. These are the pieces that keep it found after you've cleaned up.

  • Detectors for the waste that hides

    Unattached EBS volumes, idle NAT Gateways, stopped EC2/RDS instances, unassociated Elastic IPs, empty VPCs, orphaned snapshots, and more — updated as AWS adds new ways to leave things running.

  • AWS Organizations, one connection

    Connect your management account and StaleSweep discovers and scans every member account automatically — no per-account setup.

  • Scheduled scans

    Set it once and StaleSweep keeps re-scanning on your schedule, so new waste gets caught the week it appears, not the quarter you finally go looking.

  • Exceptions

    Silence expected noise — default VPCs, a specific tag, a whole region — by resource type, account, or tag, instead of re-triaging the same finding every scan.

  • SSO & SAML

    Sign in with Google or Microsoft, or connect your own identity provider (Okta, Entra ID, Google Workspace) with domain-verified SAML SSO for your whole team.

Security

The strongest guarantee is the one we can't break.

StaleSweep holds no write permissions in your account. Not restricted ones, not audited ones — none. There is no code path that could delete your data, because there is no credential that would let it.

Cost savings
Identify and clean up idle, unattached, and overprovisioned resources quietly running up your bill.
Stronger security posture
Shrink your unmanaged cloud footprint — fewer forgotten resources means fewer things an attacker can find.
  • Read-only, always

    A cross-account IAM role with an external ID. No long-lived credentials are ever stored, and nothing in your account is modified or deleted — by design, not by policy.

  • Tenant isolation in depth

    Row-level security in the database sits underneath the application's own tenant checks, so a bug in one layer isn't sufficient to cross a tenant boundary.

  • Append-only audit

    Every configuration change is written to an append-only audit log, readable from inside the product without opening a support ticket.

Your next AWS bill is already smaller than you think.

Connect a read-only role and see what you’re paying for — on your own numbers, in your own account, within minutes.

14-day free trial · No credit card · Read-only access · Revocable anytime