Skip to content
Read-only AWS access, revocable anytime

Your AWS bill is paying for resources no one is using.

StaleSweep connects with a read-only role and scans every account in your organisation — unattached volumes, idle NAT Gateways, stopped instances, empty VPCs, and dozens of other resources nobody remembers creating. Every finding arrives priced, so you know what it costs you each month.

14-day free trial · No credit card required · Read-only access · Revocable anytime

The problem

Nobody's job is to go looking for this

Cloud waste doesn't come from carelessness. It comes from every individual item being too small to chase, and the total belonging to no one.

Stopped in March

An EC2 instance nobody restarted — still billing for its attached storage every month since.

Left from a migration

A 200 GiB volume that outlived the server it was attached to. Detached, intact, invoiced.

Two quarters ago

A NAT gateway serving a VPC that emptied out. Zero bytes moved, full hourly rate charged.

Individually, none of it is worth a ticket. Together, it's a line item on every invoice you've ever paid.

Three steps. No agents to install.

From zero to your first findings in under a couple of minutes.

STEP 01

Connect, read-only

Deploy a CloudFormation template that creates a read-only IAM role, gated by a unique External ID only you and StaleSweep know. We never see or store access keys — and you can revoke access anytime by deleting the role.

STEP 02

We scan for waste

StaleSweep checks every region against its full detector set, cross-referencing CloudWatch metrics and resource metadata to separate genuinely unused resources from things that just look quiet.

STEP 03

You decide what to do

Review findings with estimated monthly cost, suppress the ones that are expected, and act on the rest in the AWS console — StaleSweep never modifies or deletes anything on its own.

Everything you need to stop the bleeding

Not just a report — a system that keeps watching after you've cleaned up.

Detectors for the waste that hides

Unattached EBS volumes, idle NAT Gateways, stopped EC2/RDS instances, unassociated Elastic IPs, empty VPCs, orphaned snapshots, and more — updated as AWS adds new ways to leave things running.

AWS Organizations, one connection

Connect your management account and StaleSweep discovers and scans every member account automatically — no per-account setup.

Scheduled scans

Set it once and StaleSweep keeps re-scanning on your schedule, so new waste gets caught the week it appears, not the quarter you finally go looking.

Exceptions

Silence expected noise — default VPCs, a specific tag, a whole region — by resource type, account, or tag, instead of re-triaging the same finding every scan.

SSO & SAML

Sign in with Google or Microsoft, or connect your own identity provider (Okta, Entra ID, Google Workspace) with domain-verified SAML SSO for your whole team.

Security

Built to pass your security review, not to talk around it.

You're granting access to your AWS account. Here is exactly what that means — stated plainly, so your reviewer can check it off.

Read-only, always
A cross-account IAM role with an external ID, launched from a CloudFormation template you can read before you run it. No credentials are stored, and nothing is ever modified or deleted — findings link you to your own console to act.
Enterprise identity
SAML 2.0 single sign-on and SCIM 2.0 provisioning. De-provisioning a user through your identity provider revokes their live sessions immediately, not at the next token refresh.
Isolation you can verify
Row-level security in the database sits beneath the application's own tenant checks — a second barrier that holds even if the first is bypassed, proven by an integration test rather than a policy document.
Audited by design
An append-only record of every configuration change, surfaced to you in-product rather than kept on our side of the line.

Cost savings

Identify and clean up idle, unattached, and overprovisioned resources quietly running up your bill.

Stronger security posture

Shrink your unmanaged cloud footprint — fewer forgotten resources means fewer things an attacker can find.

Simple pricing, unlimited team members

Plans are differentiated by features, not seats — invite as many teammates as you want on every plan.

Your next AWS bill is already smaller than you think.

Connect a read-only role and see what you're paying for — on your own numbers, in your own account, within minutes.