Read-only in, findings out
Three steps to your first result, and no step where StaleSweep touches your infrastructure.
Three steps. No agents to install.
From zero to your first findings in under a couple of minutes.
Connect, read-only
Deploy a CloudFormation template that creates a read-only IAM role, gated by a unique External ID only you and StaleSweep know. We never see or store access keys — and you can revoke access anytime by deleting the role.
We scan for waste
StaleSweep checks every region against its full detector set, cross-referencing CloudWatch metrics and resource metadata to separate genuinely unused resources from things that just look quiet.
You decide what to do
Review findings with estimated monthly cost, suppress the ones that are expected, and act on the rest in the AWS console — StaleSweep never modifies or deletes anything on its own.
The questions that come up first
- What exactly are you granting?
- A cross-account IAM role that StaleSweep assumes with an external ID. You create it by launching a CloudFormation template in your own console, so the permission set is visible to you before you approve it. No access keys change hands, and nothing is stored on our side that could be replayed.
- Can it change anything in my account?
- No. The role is read-only and the product has no write path. Every finding links back to the resource in your own AWS console — the deletion, if you want one, is yours to make.
- How does it handle an AWS Organization?
- Connect the management account and StaleSweep enrols member accounts through CloudFormation StackSets, discovering new ones as they're created. You don't onboard accounts one at a time.
- What stops it flagging things we meant to keep?
- Two mechanisms. Age-gating means a resource must exist for the full metrics window before it can be called idle. Suppression rules let you permanently silence intentional resources — DR standbys, compliance snapshots — by type, region, resource ID or tag.
- How current do the numbers stay?
- Scans run on a schedule you set, from daily to bimonthly. When a flagged resource disappears, StaleSweep notices and credits it as realised savings, so the dashboard reflects what you've actually recovered rather than what you could theoretically save.
The full access model, subprocessors and incident response are documented in the Trust Center.
Your next AWS bill is already smaller than you think.
Connect a read-only role and see what you're paying for — on your own numbers, in your own account, within minutes.
