StaleSweep

Everything StaleSweep watches for you

52 distinct resource types across six categories, each finding costed and traceable back to the evidence that flagged it.

Everything you need to stop the bleeding

Not just a report — a system that keeps watching after you've cleaned up.

Detectors for the waste that hides

Unattached EBS volumes, idle NAT Gateways, stopped EC2/RDS instances, unassociated Elastic IPs, empty VPCs, orphaned snapshots, and more — updated as AWS adds new ways to leave things running.

AWS Organizations, one connection

Connect your management account and StaleSweep discovers and scans every member account automatically — no per-account setup.

Scheduled scans

Set it once and StaleSweep keeps re-scanning on your schedule, so new waste gets caught the week it appears, not the quarter you finally go looking.

Exceptions

Silence expected noise — default VPCs, a specific tag, a whole region — by resource type, account, or tag, instead of re-triaging the same finding every scan.

SSO & SAML

Sign in with Google or Microsoft, or connect your own identity provider (Okta, Entra ID, Google Workspace) with domain-verified SAML SSO for your whole team.

What we detect, by category

Detection is judgement, not a list query — every check is age-gated so a resource provisioned yesterday is never flagged for having no traffic yet.

Compute

Stopped instances, idle running instances judged on CPU and network, unused machine images, orphaned launch templates, idle autoscaling groups and ECS clusters.

Storage

Unattached volumes, orphaned and redundant snapshots, unused container images, empty and stale buckets, abandoned multipart uploads.

Database

Idle instances, stale snapshots, idle read replicas (with a nudge toward suppression rules if they're DR standbys), unused tables, idle Redshift and OpenSearch clusters, idle cache clusters.

Networking

Unassociated Elastic IPs, empty VPCs, idle NAT gateways, unused endpoints and route tables, stale peering connections, empty hosted zones, idle distributions, load balancers with no targets, unused target groups.

Security & identity

Unused roles, users, policies and access keys; unused secrets; disabled or unused KMS keys; orphaned web ACLs; security groups no launch template references.

Messaging & analytics

Idle queues and topics, idle clusters, orphaned alarms, log groups with no retention policy.

Your next AWS bill is already smaller than you think.

Connect a read-only role and see what you're paying for — on your own numbers, in your own account, within minutes.