Skip to content

How it works

Read-only in, findings out

Three steps to your first result, and no step where StaleSweep touches your infrastructure.

How it works

Three steps. No agents to install.

From zero to your first findings in under a couple of minutes.

  1. 01

    Connect, read-only

    Deploy a CloudFormation template that creates a read-only IAM role, gated by a unique External ID only you and StaleSweep know. We never see or store access keys — and you can revoke access anytime by deleting the role.

    sts:AssumeRole · ReadOnlyAccess · external ID

  2. 02

    We scan for waste

    StaleSweep checks every region against its full detector set, cross-referencing CloudWatch metrics and resource metadata to separate genuinely unused resources from things that just look quiet.

    Every detector · all regions · all accounts

  3. 03

    You decide what to do

    Review findings with estimated monthly cost, suppress the ones that are expected, and act on the rest in the AWS console — StaleSweep never modifies or deletes anything on its own.

    Estimated $/mo · suppression rules · zero write access

Example scan output

Every finding, with the number attached.

A finding without a cost is a chore. A finding with a cost is a decision. Everything StaleSweep surfaces carries an estimated monthly figure, so the list sorts itself into the order worth acting on.

Organization o-7f3a · last sweep 4 hours ago

READ-ONLY
Accounts
38
Regions
17
Findings
214
Est. monthly waste
$4,182.60
ResourceAccountRegionIdleEst. cost

Stopped EC2 instance

m5.2xlarge · 500 GiB attached

sandboxus-west-2138d$41.20/mo

Idle NAT Gateway

0 bytes processed

prod-neteu-west-161d$32.85/mo

Unattached EBS volume

200 GiB gp3

prod-dataus-east-194d$18.40/mo

Idle load balancer

No healthy targets

stagingus-east-247d$16.43/mo

Orphaned snapshots ×12

Source volume deleted

prod-dataus-east-1210d$9.60/mo

Unassociated Elastic IPs ×3

Not attached to any ENI

sandboxeu-central-188d$10.95/mo

Showing 6 of 214 · sorted by estimated cost

Suppress, export, or open in the AWS console

Illustrative figures based on AWS list pricing. Your own numbers depend on your account.

First questions

The questions that come up first

What people actually ask on a first call — the exact shape of the access grant, and what happens after a finding appears.

What exactly are you granting?
A cross-account IAM role that StaleSweep assumes with an external ID. You create it by launching a CloudFormation template in your own console, so the permission set is visible to you before you approve it. No access keys change hands, and nothing is stored on our side that could be replayed.
Can it change anything in my account?
No. The role is read-only and the product has no write path. Every finding links back to the resource in your own AWS console — the deletion, if you want one, is yours to make.
How does it handle an AWS Organization?
Connect the management account and StaleSweep enrols member accounts through CloudFormation StackSets, discovering new ones as they're created. You don't onboard accounts one at a time.
What stops it flagging things we meant to keep?
Two mechanisms. Age-gating means a resource must exist for the full metrics window before it can be called idle. Suppression rules let you permanently silence intentional resources — DR standbys, compliance snapshots — by type, region, resource ID or tag.
How current do the numbers stay?
Scans run on a schedule you set, from daily to bimonthly. When a flagged resource disappears, StaleSweep notices and credits it as realised savings, so the dashboard reflects what you've actually recovered rather than what you could theoretically save.

The full access model, subprocessors and incident response are documented in the Trust Center.

Your next AWS bill is already smaller than you think.

Connect a read-only role and see what you’re paying for — on your own numbers, in your own account, within minutes.

14-day free trial · No credit card · Read-only access · Revocable anytime