Free · No obligation · Read-only
Find out what your AWS account is really costing you
One read-only scan tells you both where you are exposed and what the account is wasting - usually the same resources. Your score and your three highest-impact fixes land in about ten minutes, yours to action whether or not you go on to work with us.
You can revoke it in one step. Access is a CloudFormation stack in your own account. Delete the stack and our access ends immediately - no email to us, nothing to offboard. Read-only throughout, and you never send us a credential.See exactly what the role can read.
The scan
Free AWS audit
One read-only scan, 637 checks across every region with active resources. It tells you where you are exposed and what the account is wasting, in the same report - because they are usually the same resources.
- Automated checks
- 637Automated checks
- Resources audited
- 418Resources audited
- AWS regions covered
- 4AWS regions covered
- Compliance frameworks mapped
- 7Compliance frameworks mapped
What it finds
Where you are exposed
IAM, network exposure, encryption, logging, threat detection and workload configuration - every finding mapped to the SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, CIS and NIST controls it breaches.
- CriticalA security group exposing all 65,535 ports to the public internet, with a directly reachable instance behind it.
- CriticalCloudTrail disabled across every region - meaning a breach would leave no forensic evidence at all.
- HighA dormant administrator account holding an access key unrotated for 819 days.
- HighGuardDuty and Security Hub disabled everywhere, so cryptomining or data exfiltration would go unnoticed.
- HighEBS encryption off by default and S3 Block Public Access not set at the account level.
A recent audit returned 34 critical, 153 high and 226 medium findings across 418 resources, against a 76/100 risk score. The three fixes we led with were resolvable in under ten minutes each.
What it finds
Where the money goes
The same scan sweeps for the spend that buys you nothing - gateways carrying no traffic, ancient snapshots, addresses attached to no machine - and prices each one against AWS published rates rather than estimating it.
- HighAn idle NAT gateway provisioned but carrying no traffic, billed every month for serving nothing.
- HighSnapshots over 700 days old with no lifecycle policy, accumulating silently month over month.
- HighElastic IPs allocated but attached to no running instance, plus stopped instances still billing for storage.
- HighInstances running consistently below 5% CPU - over-provisioned for the workload they actually carry.
- MediumNo VPC endpoints for S3 or DynamoDB, routing internal traffic through a paid NAT gateway unnecessarily.
A recent audit identified 157 cost issues, 58 of them high-severity, and confirmed recoverable waste worth roughly $1,385 a year - every dollar of it removable in week 1 without a single code change or minute of downtime.
How it works
Three steps, about ten minutes end to end
Nothing installed, nothing changed, and no commercial conversation before your score is in front of you.
- 01~60 seconds
Connect in one click
You deploy a CloudFormation stack in your own account. It creates a read-only IAM role scoped by an external ID unique to you, carrying two AWS-managed policies - SecurityAudit and ViewOnlyAccess, nothing bespoke. You never send us a credential, and deleting the stack ends our access immediately.
- 023-15 minutes
We scan, read-only
637 checks across every region with active resources, covering IAM, network exposure, encryption, logging, threat detection and workload configuration - plus a sweep for idle and abandoned resources you are still paying for.
- 03Immediate
You get your score
Your risk score, three fully worked fixes, and what the account is wasting - each item priced from AWS published rates. The complete findings register and the 90-day roadmap come in a 30-minute walkthrough with the engineer who ran the scan.
How we work
What you can hold us to
Read-only, always
Two AWS-managed policies and zero write permissions. The role cannot create, modify or delete a single resource in your account - AWS enforces that, not our promise. Revoke it by deleting the stack.
Confirmed, not estimated
We report what we can demonstrate against live usage. Anything we could not confirm is listed separately as an observation.
One scan, both lenses
Exposure and waste overlap more than people expect. An idle NAT gateway is money burning and a network exposure at once - one fix, paid for twice.
Yours to action
The score and your three worked fixes arrive the moment the scan finishes, with no obligation and nothing to sign. They are written so your own team can action them without us.
Teams who have already had one
- Cylogy
- EazyBot
- Red Wire Services
- EnigmaPlus
- Simpler Media Group
- Astrolabe Analytics
- PADI Systems
- Tipedia
- Simply Analytics
- Tatango
- AnswerDash
- Ravenna Solutions
One scan, no charge
Read-only access, your score and three worked fixes in about ten minutes, then a 30-minute walkthrough with the engineer who ran it. Nothing else attached.