How it works
Read-only in, findings out
Three steps to your first result, and no step where StaleSweep touches your infrastructure.
How it works
Three steps. No agents to install.
From zero to your first findings in under a couple of minutes.
- 01
Connect, read-only
Deploy a CloudFormation template that creates a read-only IAM role, gated by a unique External ID only you and StaleSweep know. We never see or store access keys — and you can revoke access anytime by deleting the role.
sts:AssumeRole · ReadOnlyAccess · external ID
- 02
We scan for waste
StaleSweep checks every region against its full detector set, cross-referencing CloudWatch metrics and resource metadata to separate genuinely unused resources from things that just look quiet.
Every detector · all regions · all accounts
- 03
You decide what to do
Review findings with estimated monthly cost, suppress the ones that are expected, and act on the rest in the AWS console — StaleSweep never modifies or deletes anything on its own.
Estimated $/mo · suppression rules · zero write access
Example scan output
Every finding, with the number attached.
A finding without a cost is a chore. A finding with a cost is a decision. Everything StaleSweep surfaces carries an estimated monthly figure, so the list sorts itself into the order worth acting on.
Organization o-7f3a · last sweep 4 hours ago
READ-ONLY- Accounts
- 38
- Regions
- 17
- Findings
- 214
- Est. monthly waste
- $4,182.60
| Resource | Account | Region | Idle | Est. cost |
|---|---|---|---|---|
Stopped EC2 instance m5.2xlarge · 500 GiB attached | sandbox | us-west-2 | 138d | $41.20/mo |
Idle NAT Gateway 0 bytes processed | prod-net | eu-west-1 | 61d | $32.85/mo |
Unattached EBS volume 200 GiB gp3 | prod-data | us-east-1 | 94d | $18.40/mo |
Idle load balancer No healthy targets | staging | us-east-2 | 47d | $16.43/mo |
Orphaned snapshots ×12 Source volume deleted | prod-data | us-east-1 | 210d | $9.60/mo |
Unassociated Elastic IPs ×3 Not attached to any ENI | sandbox | eu-central-1 | 88d | $10.95/mo |
Showing 6 of 214 · sorted by estimated cost
Suppress, export, or open in the AWS console
Illustrative figures based on AWS list pricing. Your own numbers depend on your account.
First questions
The questions that come up first
What people actually ask on a first call — the exact shape of the access grant, and what happens after a finding appears.
- What exactly are you granting?
- A cross-account IAM role that StaleSweep assumes with an external ID. You create it by launching a CloudFormation template in your own console, so the permission set is visible to you before you approve it. No access keys change hands, and nothing is stored on our side that could be replayed.
- Can it change anything in my account?
- No. The role is read-only and the product has no write path. Every finding links back to the resource in your own AWS console — the deletion, if you want one, is yours to make.
- How does it handle an AWS Organization?
- Connect the management account and StaleSweep enrols member accounts through CloudFormation StackSets, discovering new ones as they're created. You don't onboard accounts one at a time.
- What stops it flagging things we meant to keep?
- Two mechanisms. Age-gating means a resource must exist for the full metrics window before it can be called idle. Suppression rules let you permanently silence intentional resources — DR standbys, compliance snapshots — by type, region, resource ID or tag.
- How current do the numbers stay?
- Scans run on a schedule you set, from daily to bimonthly. When a flagged resource disappears, StaleSweep notices and credits it as realised savings, so the dashboard reflects what you've actually recovered rather than what you could theoretically save.
The full access model, subprocessors and incident response are documented in the Trust Center.
Your next AWS bill is already smaller than you think.
Connect a read-only role and see what you’re paying for — on your own numbers, in your own account, within minutes.
14-day free trial · No credit card · Read-only access · Revocable anytime