Seven scanners live across your AWS estate

Zero agents.
Instant cloud savings.

Nothing hidden. Nothing touched.
We read the metadata your cloud already tells the truth in — and never the data itself.

GhostTrace analyzes metadata — never your files or workloads — to uncover unattached storage, idle compute, abandoned databases, and security drift across your AWS account.

No credit card Read-only IAM Zero disruption Results in 2 mins
GHOSTTRACE_INSPECT // AUDIT_ENGINE [ ACTIVE ]
12:04:02Connected via STS AssumeRole (acct 847…312)
12:04:05Enumerating 426 resources (S3, EBS, EC2, RDS)…
12:04:12FINDING · 14 unattached EBS volumes · $5,100/yr
12:04:18FINDING · 9 zero-connection RDS instances
12:04:21Correlating spend · storage class · attachment state
12:04:23Audit complete · report generated
Scanning estate
ESTIMATED ANNUAL SPEND $64,820
RECOVERABLE WASTE $12,450 / yr
20–35%
average waste across cloud estates
65%
of EBS volumes remain idle after detachment
Silent
idle DBs and unattached Elastic IPs bill 24/7
2 min
to connect and generate a full estate audit
01Capability

We see what dashboards omit. Consoles hand you metrics. We hand you the bill, the risk, and the fix.

Native consoles give metrics.
We deliver action items.

Every finding arrives with an exact dollar figure, a risk impact, and step-by-step remediation. Priority-ranked so you clean up the highest impact first.

Multi-service cost intelligence

We correlate resource utilization, pricing tiers, storage classes, and attachment states into concrete financial impact. Savings calculations prevent double counting across overlapping optimizations.

  • Dollar-quantified waste per bucket, volume, compute instance, and database
  • gp2 to gp3 migration projections and unattached volume tracking
  • 6 and 12-month spend forecasts built on observed usage trends

Uncovers hidden infrastructure waste

Orphaned EBS volumes, abandoned snapshot chains, incomplete S3 multipart uploads, stopped EC2 instances, and zero-connection RDS databases.

Governance & tag compliance

Untagged resource identification, environment drift tracking, compliance reporting for ISO/SOC2, and cost allocation tag enforcement.

Exposure & encryption

Public bucket and unencrypted volume detection, publicly accessible RDS alerts, and logging posture across core layers.

02Your AWS estate

Every layer keeps a secret. We walk them one by one.

Your cloud infrastructure,
dissected.

GhostTrace inspects configuration metadata across storage, compute, and database layers to pinpoint non-optimized spend.

S3, EBS, EC2, RDS — scanning live
Lambda & ECR, CloudWatch Logs — scanning live
Architecture Review — scanning live
03Service matrix

One key. Every door read, none opened.

One read-only role.
Complete visibility.

Seven scanning engines cover storage, compute, database, serverless, logging, and cross-service architecture out of the box. Scroll to walk each layer.

    7
    scanners live today
    1
    read-only role to connect
    0
    write permissions requested
    <3min
    to a full estate audit

    Need a specific AWS service audited? Tell us what to cover next.

    04Architecture Review

    The layer above every single-resource scanner.

    Waste that hides
    between services.

    Most cost tools look at one resource at a time. The Architecture Review scanner reads across your account to catch spend that works correctly but wastes money by design — idle plumbing, avoidable data-processing charges, and always-on services with nothing behind them.

    • Kill idle plumbing on the clockLoad balancers with no healthy targets, idle NAT gateways, unattached Elastic IPs, and idle Transit Gateways all bill per hour whether or not anything uses them.
    • Cut avoidable NAT data chargesMissing S3/DynamoDB VPC gateway endpoints route traffic through NAT and rack up data-processing fees a free gateway endpoint would erase.
    • Right-size the restUnderutilized ElastiCache clusters and low-value CloudFront distributions surface with hard savings where a per-hour or idle charge is provable — advisory flags where it isn't.
    • Deterministic, never guessedFindings and savings are computed from facts by pure functions — reproducible and auditable. Every number ties out to the 2-year cost projection on your dashboard.

    Sample cross-service findings

    Idle load balancer · no targets
    $197/yr
    Idle NAT gateway
    $394/yr
    Unattached Elastic IPs · ×3
    $118/yr
    Missing S3 VPC endpoint
    NAT data ↓
    Underutilized ElastiCache
    right-size

    Read-only metadata & CloudWatch metrics only. Advisory flags cover questions we can't quantify read-only — cross-AZ transfer, duplicate telemetry, over-engineered pipelines.

    05Deployment pipeline

    In and out. No footprint left behind.

    Four steps. Two minutes. Zero risk.

    Connect your AWS environment with strict, read-only permissions.

    01

    Generate tenant ID

    Create an account to issue your unique cryptographic External ID.

    02

    Deploy IAM role

    Launch via 1-click CloudFormation stack or standard policy paste.

    03

    STS handshake

    Instant STS verification validates secure, read-only access.

    04

    Savings report

    Metadata collectors evaluate estate waste in under 3 minutes.

    06Security architecture

    We change nothing. We keep nothing. Observation is the whole of the contract.

    We read metadata.
    Never your customer data.

    Our IAM policies strictly forbid data payload reading (s3:GetObject, database queries, shell access, or SSH/SSM actions). We inspect the control plane only.

    SYSTEM BOUNDARIES

    • Cannot read object contents, database records, or disks
    • Cannot modify, create, delete, or alter any resource
    • Cannot alter IAM permissions or network ACLs

    ACCESS CONTROL

    • Per-tenant External ID protects against Confused Deputy
    • STS AssumeRole sessions expire within 60 minutes
    • Revoke access anytime by deleting the IAM role
    07Subscription tiers

    Pay for what you hunt. Nothing more.

    Simple pricing. Pay per scan.

    Start free with 3 scans per month. Upgrade when you need more — cancel anytime.

    Important: at checkout, pay with the same email you signed in with. We match your payment to your account by email — a different billing email means your plan won't activate automatically.

    Free
    $0

    No card required.

    Start free
    • 3 scans / month
    • 1 AWS account
    • S3 scanner only
    Starter · Popular
    $19 / mo

    For a single team.

    Subscribe — $19
    • 25 scans / month
    • Up to 3 AWS accounts
    • All 7 scanners
    Growth
    $49 / mo

    For growing teams.

    Subscribe — $49
    • 75 scans / month
    • Up to 10 AWS accounts
    • All 7 scanners
    Business
    $99 / mo

    For large estates.

    Subscribe — $99
    • 200 scans / month
    • Unlimited accounts
    • Priority support
    Agency & White-Label · In development

    For consultancies managing many client accounts

    A dedicated agency account with multi-client management and white-labelled client reports is planned. Not available yet — register interest and we'll reach out when it ships.

    IN DEV

    Agency accounts and white-label reporting are on the roadmap, not yet live.

    08Recovered so far
    $0/ yr reclaimed

    GhostTrace turns idle storage, ghost compute, and abandoned databases into line-item savings — swept straight out of your monthly bill.

    Unattached EBS $980 Zero-conn RDS $720 Idle EC2 $480 S3 lifecycle $200
    Instant deployment

    The waste was always there. Now it has nowhere to hide.

    Uncover the money hiding in your AWS estate.

    Connect a read-only role and inspect your actionable, cost-quantified audit report in under three minutes.