Your AWS bill is paying for resources no one is using.
StaleSweep connects with a read-only role and scans every account in your organisation — unattached volumes, idle NAT Gateways, stopped instances, empty VPCs, and dozens of other resources nobody remembers creating. Every finding arrives priced, so you know what it costs you each month.
14-day free trial · No credit card required · Read-only access · Revocable anytime
The problem
Nobody's job is to go looking for this
Cloud waste doesn't come from carelessness. It comes from every individual item being too small to chase, and the total belonging to no one.
Stopped in March
An EC2 instance nobody restarted — still billing for its attached storage every month since.
Left from a migration
A 200 GiB volume that outlived the server it was attached to. Detached, intact, invoiced.
Two quarters ago
A NAT gateway serving a VPC that emptied out. Zero bytes moved, full hourly rate charged.
Individually, none of it is worth a ticket. Together, it's a line item on every invoice you've ever paid.
Three steps. No agents to install.
From zero to your first findings in under a couple of minutes.
Connect, read-only
Deploy a CloudFormation template that creates a read-only IAM role, gated by a unique External ID only you and StaleSweep know. We never see or store access keys — and you can revoke access anytime by deleting the role.
We scan for waste
StaleSweep checks every region against its full detector set, cross-referencing CloudWatch metrics and resource metadata to separate genuinely unused resources from things that just look quiet.
You decide what to do
Review findings with estimated monthly cost, suppress the ones that are expected, and act on the rest in the AWS console — StaleSweep never modifies or deletes anything on its own.
Everything you need to stop the bleeding
Not just a report — a system that keeps watching after you've cleaned up.
Detectors for the waste that hides
Unattached EBS volumes, idle NAT Gateways, stopped EC2/RDS instances, unassociated Elastic IPs, empty VPCs, orphaned snapshots, and more — updated as AWS adds new ways to leave things running.
AWS Organizations, one connection
Connect your management account and StaleSweep discovers and scans every member account automatically — no per-account setup.
Scheduled scans
Set it once and StaleSweep keeps re-scanning on your schedule, so new waste gets caught the week it appears, not the quarter you finally go looking.
Exceptions
Silence expected noise — default VPCs, a specific tag, a whole region — by resource type, account, or tag, instead of re-triaging the same finding every scan.
SSO & SAML
Sign in with Google or Microsoft, or connect your own identity provider (Okta, Entra ID, Google Workspace) with domain-verified SAML SSO for your whole team.
Security
Built to pass your security review, not to talk around it.
You're granting access to your AWS account. Here is exactly what that means — stated plainly, so your reviewer can check it off.
- Read-only, always
- A cross-account IAM role with an external ID, launched from a CloudFormation template you can read before you run it. No credentials are stored, and nothing is ever modified or deleted — findings link you to your own console to act.
- Enterprise identity
- SAML 2.0 single sign-on and SCIM 2.0 provisioning. De-provisioning a user through your identity provider revokes their live sessions immediately, not at the next token refresh.
- Isolation you can verify
- Row-level security in the database sits beneath the application's own tenant checks — a second barrier that holds even if the first is bypassed, proven by an integration test rather than a policy document.
- Audited by design
- An append-only record of every configuration change, surfaced to you in-product rather than kept on our side of the line.
Cost savings
Identify and clean up idle, unattached, and overprovisioned resources quietly running up your bill.
Stronger security posture
Shrink your unmanaged cloud footprint — fewer forgotten resources means fewer things an attacker can find.
Simple pricing, unlimited team members
Plans are differentiated by features, not seats — invite as many teammates as you want on every plan.
Your next AWS bill is already smaller than you think.
Connect a read-only role and see what you're paying for — on your own numbers, in your own account, within minutes.
