Full support for S3, EBS, EC2 & RDS is live

Zero agents.
Instant cloud savings.

Nothing hidden. Nothing touched.
We read the metadata your cloud already tells the truth in — and never the data itself.

GhostTrace analyzes metadata — never your files or workloads — to uncover unattached storage, idle compute, abandoned databases, and security drift across your AWS account.

No credit card Read-only IAM Zero disruption Results in 2 mins
GHOSTTRACE_INSPECT // AUDIT_ENGINE [ ACTIVE ]
12:04:02Connected via STS AssumeRole (acct 847…312)
12:04:05Enumerating 426 resources (S3, EBS, EC2, RDS)…
12:04:12FINDING · 14 unattached EBS volumes · $5,100/yr
12:04:18FINDING · 9 zero-connection RDS instances
12:04:21Correlating spend · storage class · attachment state
12:04:23Audit complete · report generated
Scanning estate
ESTIMATED ANNUAL SPEND $64,820
RECOVERABLE WASTE $12,450 / yr
20–35%
average waste across cloud estates
65%
of EBS volumes remain idle after detachment
Silent
idle DBs and unattached Elastic IPs bill 24/7
2 min
to connect and generate a full estate audit
01Capability

We see what dashboards omit. Consoles hand you metrics. We hand you the bill, the risk, and the fix.

Native consoles give metrics.
We deliver action items.

Every finding arrives with an exact dollar figure, a risk impact, and step-by-step remediation. Priority-ranked so you clean up the highest impact first.

Multi-service cost intelligence

We correlate resource utilization, pricing tiers, storage classes, and attachment states into concrete financial impact. Savings calculations prevent double counting across overlapping optimizations.

  • Dollar-quantified waste per bucket, volume, compute instance, and database
  • gp2 to gp3 migration projections and unattached volume tracking
  • 6 and 12-month spend forecasts built on observed usage trends

Uncovers hidden infrastructure waste

Orphaned EBS volumes, abandoned snapshot chains, incomplete S3 multipart uploads, stopped EC2 instances, and zero-connection RDS databases.

Governance & tag compliance

Untagged resource identification, environment drift tracking, compliance reporting for ISO/SOC2, and cost allocation tag enforcement.

Exposure & encryption

Public bucket and unencrypted volume detection, publicly accessible RDS alerts, and logging posture across core layers.

02Your AWS estate

Every layer keeps a secret. We walk them one by one.

Your cloud infrastructure,
dissected.

GhostTrace inspects configuration metadata across storage, compute, and database layers to pinpoint non-optimized spend.

S3, EBS, EC2, RDS — scanning live
Lambda & ECR — in active development
CloudWatch Logs — coming next
03Service matrix

One key. Every door read, none opened.

One read-only role.
Complete visibility.

Our core scanning engines cover storage, compute, and database workloads out of the box. Scroll to walk each layer.

    4
    services live today
    1
    read-only role to connect
    0
    write permissions requested
    <3min
    to a full estate audit

    Need a specific AWS service audited? Tell us what to cover next.

    04Deployment pipeline

    In and out. No footprint left behind.

    Four steps. Two minutes. Zero risk.

    Connect your AWS environment with strict, read-only permissions.

    01

    Generate tenant ID

    Create an account to issue your unique cryptographic External ID.

    02

    Deploy IAM role

    Launch via 1-click CloudFormation stack or standard policy paste.

    03

    STS handshake

    Instant STS verification validates secure, read-only access.

    04

    Savings report

    Metadata collectors evaluate estate waste in under 3 minutes.

    05Security architecture

    We change nothing. We keep nothing. Observation is the whole of the contract.

    We read metadata.
    Never your customer data.

    Our IAM policies strictly forbid data payload reading (s3:GetObject, database queries, shell access, or SSH/SSM actions). We inspect the control plane only.

    SYSTEM BOUNDARIES

    • Cannot read object contents, database records, or disks
    • Cannot modify, create, delete, or alter any resource
    • Cannot alter IAM permissions or network ACLs

    ACCESS CONTROL

    • Per-tenant External ID protects against Confused Deputy
    • STS AssumeRole sessions expire within 60 minutes
    • Revoke access anytime by deleting the IAM role
    06Pricing

    Free while in beta. No card required.

    Free while in beta.
    No card required.

    Every scanner is free during beta — S3, EBS, EC2, and RDS. 10 scans a month, no card required. Early users keep free access when paid tiers launch.

    ● Free Beta
    $0 / forever during beta

    Full assessment across S3, EBS, EC2 & RDS. 10 free scans a month. Zero commitment.

    Start free assessment
    • Full audit of S3, EBS, EC2 & RDS
    • 10 free scans every month
    • Dollar-quantified savings breakdown
    • Security and governance risk evaluation
    • Export findings to CSV & PDF
    • Locked in free for beta users
    Coming soon
    $29 / month

    Automated weekly scans, drift tracking, and alerts. Launching after beta.

    Join the waitlist
    • Everything in Free Beta
    • Automated weekly scheduled scans
    • Waste drift & unattached resource alerts
    • Historical spend & savings trends
    Planned
    $149 / month

    For consultancies, agency partners, and multi-tenant AWS Organizations.

    Talk to us
    • Unlimited AWS Accounts & Organizations
    • Daily automated background scanning
    • White-label reporting for client deliverables
    • Slack & Teams alert webhooks

    Beta is free — 10 scans a month, no card. Paid tiers (Continuous Monitoring, Multi-Account) launch after beta — early users keep free access.

    07Recovered so far
    $0/ yr reclaimed

    GhostTrace turns idle storage, ghost compute, and abandoned databases into line-item savings — swept straight out of your monthly bill.

    Unattached EBS $980 Zero-conn RDS $720 Idle EC2 $480 S3 lifecycle $200
    Instant deployment

    The waste was always there. Now it has nowhere to hide.

    Uncover the money hiding in your AWS estate.

    Connect a read-only role and inspect your actionable, cost-quantified audit report in under three minutes.