Find the AWS spend you didn't know about
Idle NAT gateways, orphaned volumes, forgotten snapshots — the boring waste every AWS bill accumulates. CostLens scans read-only and hands you dollar-quantified findings with the exact CLI command to fix each one — not another dashboard nobody opens.
One field: your 12-digit account ID. No access keys, no credit card.
Identified savings
$1,284
▲ 18%Findings
23
Top finding
$412/mo
Idle NAT Gateway
Example findings
Idle NAT Gateway nat-0a1b2c3d4e5f
Processed 0.0 MB outbound over the last 14 days but bills hourly regardless.
$32.85/moaws ec2 delete-nat-gateway --nat-gateway-id nat-0a1b2c3d4e5f --region us-east-1
EKS cluster eks-staging-01 with zero nodes
Control plane has been running for 46 days with no node groups attached — paying for orchestration nothing is using.
$73.00/moaws eks delete-cluster --name eks-staging-01 --region us-east-1
S3 bucket reports-archive-2019 never transitions
612 GB sitting on S3 Standard with no lifecycle rule — most of it hasn't been touched in over a year.
$41.20/moaws s3api put-bucket-lifecycle-configuration --bucket reports-archive-2019 --lifecycle-configuration file://glacier-transition.json
How it works
Connect
Paste your 12-digit AWS account ID. We generate a CloudFormation or Terraform stack that creates one read-only IAM role — nothing else.
Scan
We check for idle NAT gateways, unattached volumes, orphaned load balancers, stale snapshots, and more — plus AWS Compute Optimizer's own rightsizing data.
Fix
Every finding ships with the exact CLI command to fix it, ranked by dollar impact. Dismiss what doesn't apply; it stays dismissed.
What it finds
Every check ships with an honest confidence level — low for estimates that could shift with incremental billing, high for findings we're certain about. Never inflated to make the report look stronger.
Idle & orphaned resources
Running (and billing) with nothing using them.
- EC2 stopped 30+ days, still paying for EBS
- Idle NAT Gateways
- Load balancers with no healthy targets
- Idle RDS instances (zero connections)
- Unassociated Elastic IPs
Storage waste
Volumes, snapshots, and buckets quietly piling up cost.
- Unattached EBS volumes
- gp2 → gp3 migration candidates
- Stale EBS snapshots
- S3 buckets missing abort-incomplete-upload rules
Rightsizing & commitments
AWS's own ML-backed recommendations, ingested and ranked by dollar impact.
- EC2 / RDS / Lambda rightsizing (via Compute Optimizer)
- Savings Plans purchase recommendation
High confidence Medium confidence Low confidence
We never hold an AWS credential
Read-only, always
The IAM policy grants only Describe/Get/List actions. Object data and secrets carry an explicit Deny — not just an absence of Allow.
No stored keys
Access is granted role-to-role, gated by a per-tenant secret only you and we know. No access keys are ever created or transmitted.
Revoke anytime
Delete the CloudFormation stack (or run `terraform destroy`) and access is gone immediately. Nothing to rotate, nothing to leak.
Pricing
Free
$0
- 1 AWS account
- All orphan / idle / rightsizing checks
- On-demand scans, 4 regions
- ~$0.05/mo AWS API cost to you
Pro
$69~$51.75/mo
Early-access pricing, locked in for as long as you stay subscribed.
- Unlimited accounts
- Nightly automated scans, 25 regions
- Spend trend + Savings Plans recommendation
- 365-day history, CSV export, weekly digest
Free tier isn't exactly $0.00 in AWS API cost — pennies, not dollars, and never billed to us.
Where CostLens runs
AWS is live today. The same read-only, dollar-quantified approach is coming to Google Cloud and Azure next — one scanning engine, every major cloud.
Amazon Web Services
Available now
Google Cloud
Coming soon
Microsoft Azure
Coming soon