S3 scanning is free while we build the rest

Zero agents.
Instant S3 savings.

GhostTrace analyzes metadata — never your files — to uncover lifecycle gaps, version sprawl, and security risks. Get an actionable, dollar-quantified cleanup plan in minutes.

No card required · Read-only IAM role · Zero object access · Results in minutes
Live product 302 buckets scanned
ghosttrace.cloud/dashboard
Storage assessment
acct 847…312 · 186 buckets · 94.7 TB
Scan complete
Est. annual
$28,340
Recoverable
$3,217
No lifecycle
87
Orphaned MPU
634
Projected spend if nothing changes
now+6mo+12mo  $43.8k
Cost by category
Application Data$9.4k
Logging$7.8k
Backup$5.2k
Analytics$3.6k
Other$2.3k

Built for teams running S3 at scale

Northwind Cadence Halcyon Vantiq Meridian Orbital
Why this matters
20–35%
of S3 spend is typically recoverable
78%
of buckets ship with no lifecycle rule
Invisible
orphaned multipart uploads still bill you
2 min
to connect and get your first report
GhostTrace - Free, Agentless, read-only S3 waste and risk audit | Product Hunt
Capability

Storage Lens shows you bytes.
We show you decisions.

Every finding arrives with a dollar figure, a health score and the exact remediation to apply. Sorted worst-first, because that's where the money is.

01

Costed findings, not raw metrics

We translate bucket size, storage class mix and access patterns into an annual figure — then model what each remediation actually returns. Savings are capped conservatively and never double-counted across overlapping actions.

  • Per-bucket annual cost and recoverable amount
  • Blended-rate estimates across all seven storage classes
  • 6 and 12-month spend projection from observed growth
02

Waste the console won't surface

Incomplete multipart uploads bill silently and never appear in the object list. We count them, age them and tell you what an abort rule reclaims.

  • Orphaned multipart uploads with oldest-age
  • Version sprawl on buckets with no cleanup rule
  • Partial lifecycle coverage across prefixes
  • Empty and idle buckets flagged for review

Governance scoring

Tag coverage against your required schema, ownership gaps and drift — scored per bucket so you can chase the worst offenders first.

Exposure & encryption

Public access block state, SSE mode, access logging and replication — rolled into a security score with the specific setting that failed.

Any account, any org

Cross-account by design. Scan client estates that don't sit inside your AWS Organization — something native tooling can't reach.

Your AWS estate

Your cloud city,
dissected.

Every service is a layer. Every layer hides waste. GhostTrace peels them apart and prices what's hiding inside — starting with S3 today, compute next.

S3 — scanning live, free
EBS / EC2 — in development
RDS / Lambda / Logs — planned
Cloud infrastructure
Free while in beta

S3 assessments are free. No limits, no card, no expiry date.

We're building coverage for the rest of your estate — EBS, EC2, RDS and beyond. While that work is underway, every S3 scan is on us. Connect an account and keep the savings.

Claim your free scan
Coverage

One ghost hunter.
Every wasted resource.

S3 is live today. The same read-only role and the same costed-findings model is being extended service by service — starting with the biggest silent spenders.

Want a service prioritised? Tell us what's costing you most

How it works

Four steps. No agents.

You create one read-only role scoped to metadata calls. We assume it with a per-tenant external ID and never touch object data.

01

Sign in

Email and password via Cognito. We issue you a unique external ID that scopes the trust relationship to your tenant alone.

02

Create the role

Paste the trust policy and the read-only permission set into IAM. Both are shown on the connect page, ready to copy.

03

Validate

We attempt a single ListBuckets call to confirm the trust and permissions resolve before anything else runs.

04

Scan

Metadata collection runs asynchronously. The dashboard populates as results land — typically a few minutes for several hundred buckets.

trust-policy.json
{
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Principal": {
      "AWS": "arn:aws:iam::<ghosttrace>:root"
    },
    "Action": "sts:AssumeRole",
    "Condition": {
      "StringEquals": {
        "sts:ExternalId": "gt-<your-id>"
      }
    }
  }]
}
permissions.json — read-only
// metadata only — no s3:GetObject
"s3:ListAllMyBuckets"
"s3:GetBucketLocation"
"s3:GetBucketVersioning"
"s3:GetLifecycleConfiguration"
"s3:GetEncryptionConfiguration"
"s3:GetBucketPublicAccessBlock"
"s3:GetBucketLogging"
"s3:GetBucketReplication"
"s3:GetBucketTagging"
"s3:ListBucketMultipartUploads"
"cloudwatch:GetMetricStatistics"
Security

We read configuration.
Never your data.

The permission set has no object-level read. Even if our account were compromised, an attacker could not retrieve a single object from your buckets.

What we can never do

  • Read, copy or move any object
  • Write, delete or modify a bucket
  • Change a policy, ACL or lifecycle rule
  • Access anything outside S3 and CloudWatch metrics

How access is controlled

  • Per-tenant external ID blocks the confused-deputy path
  • Credentials are session-scoped and expire in one hour
  • Reports encrypted at rest, auto-purged after 90 days
  • You can delete the role at any time and access ends instantly
Pricing

S3 is free. Pay only when we cover more.

Nothing to pay while S3 is our only live scanner. Paid tiers unlock as EBS, EC2 and RDS coverage ships — and beta users keep S3 free permanently.


Available now
S3 Scanner
$0 / forever

Every S3 capability, unmetered, for as long as S3 is the only live scanner.

Start scanning
  • Unlimited accounts and scans
  • Full cost, governance and security findings
  • Trend projection and Excel export
  • Cross-account and cross-org support
  • Locked in free for beta users
Soon
Compute & Storage
$29 / month

Adds EBS, EC2 and Elastic IP coverage on top of everything in S3 Scanner.

Join the waitlist
  • Everything in S3 Scanner
  • Unattached volumes & snapshot sprawl
  • Idle EC2 and orphaned Elastic IPs
  • Weekly scheduled scans
  • Email digest on new findings
Later
Agency
$149 / month

For MSPs and consultancies reporting across many client estates.

Talk to us
  • Every service we cover
  • Daily scans & Slack alerts
  • White-label PDF reports
  • API access
  • Priority on service requests
EBS & EC2 coming soon

Get notified when compute scanning drops.

First in line. We'll email you once — no spam.

Join waitlist
Free during beta

See what your buckets are really costing you.

Connect a read-only role and get a costed action list in minutes. Free while S3 is our only live scanner — and free for good if you join now.

Two minutes to connect · Revoke any time by deleting the role