Find the AWS spend you didn't know about

Idle NAT gateways, orphaned volumes, forgotten snapshots — the boring waste every AWS bill accumulates. CostLens scans read-only and hands you dollar-quantified findings with the exact CLI command to fix each one — not another dashboard nobody opens.

One field: your 12-digit account ID. No access keys, no credit card.

Identified savings

$1,284

▲ 18%

Findings

23

Top finding

$412/mo

Idle NAT Gateway

Example findings

Idle NAT Gateway nat-0a1b2c3d4e5f

Processed 0.0 MB outbound over the last 14 days but bills hourly regardless.

$32.85/mo
aws ec2 delete-nat-gateway --nat-gateway-id nat-0a1b2c3d4e5f --region us-east-1
Pro

EKS cluster eks-staging-01 with zero nodes

Control plane has been running for 46 days with no node groups attached — paying for orchestration nothing is using.

$73.00/mo
aws eks delete-cluster --name eks-staging-01 --region us-east-1
Pro

S3 bucket reports-archive-2019 never transitions

612 GB sitting on S3 Standard with no lifecycle rule — most of it hasn't been touched in over a year.

$41.20/mo
aws s3api put-bucket-lifecycle-configuration --bucket reports-archive-2019 --lifecycle-configuration file://glacier-transition.json

How it works

1

Connect

Paste your 12-digit AWS account ID. We generate a CloudFormation or Terraform stack that creates one read-only IAM role — nothing else.

2

Scan

We check for idle NAT gateways, unattached volumes, orphaned load balancers, stale snapshots, and more — plus AWS Compute Optimizer's own rightsizing data.

3

Fix

Every finding ships with the exact CLI command to fix it, ranked by dollar impact. Dismiss what doesn't apply; it stays dismissed.

See the full walkthrough, start to finish →

What it finds

Every check ships with an honest confidence level — low for estimates that could shift with incremental billing, high for findings we're certain about. Never inflated to make the report look stronger.

Idle & orphaned resources

Running (and billing) with nothing using them.

  • EC2 stopped 30+ days, still paying for EBS
  • Idle NAT Gateways
  • Load balancers with no healthy targets
  • Idle RDS instances (zero connections)
  • Unassociated Elastic IPs

Storage waste

Volumes, snapshots, and buckets quietly piling up cost.

  • Unattached EBS volumes
  • gp2 → gp3 migration candidates
  • Stale EBS snapshots
  • S3 buckets missing abort-incomplete-upload rules

Rightsizing & commitments

AWS's own ML-backed recommendations, ingested and ranked by dollar impact.

  • EC2 / RDS / Lambda rightsizing (via Compute Optimizer)
  • Savings Plans purchase recommendation

High confidence Medium confidence Low confidence

We never hold an AWS credential

Read-only, always

The IAM policy grants only Describe/Get/List actions. Object data and secrets carry an explicit Deny — not just an absence of Allow.

No stored keys

Access is granted role-to-role, gated by a per-tenant secret only you and we know. No access keys are ever created or transmitted.

Revoke anytime

Delete the CloudFormation stack (or run `terraform destroy`) and access is gone immediately. Nothing to rotate, nothing to leak.

See exactly what's granted, down to the IAM action →

Pricing

Free

$0

  • 1 AWS account
  • All orphan / idle / rightsizing checks
  • On-demand scans, 4 regions
  • ~$0.05/mo AWS API cost to you
Connect your AWS account
Most popular25% off

Pro

$69~$51.75/mo

Early-access pricing, locked in for as long as you stay subscribed.

  • Unlimited accounts
  • Nightly automated scans, 25 regions
  • Spend trend + Savings Plans recommendation
  • 365-day history, CSV export, weekly digest
Get started

Free tier isn't exactly $0.00 in AWS API cost — pennies, not dollars, and never billed to us.

Where CostLens runs

AWS is live today. The same read-only, dollar-quantified approach is coming to Google Cloud and Azure next — one scanning engine, every major cloud.

Amazon Web Services

Available now

Google Cloud

Coming soon

Microsoft Azure

Coming soon