Find the resources
no one is using.
Before finance
does.
Fixed detection rules on read-only AWS APIs. Waste and idle resources in a weekly email. Full report in the app. Read-only. 5-minute setup.
Sample digest (summary by email). Full web report lives in the app. Delivered Monday 09:00 in your timezone.
Deploy a read-only role
CloudFormation, Terraform, or StackSets. You inspect the template first.
We scan every region
30+ services, 51+ rules. Nothing changes in your account.
Digest, then the app
Weekly email you can forward. Full report in the app when you want the detail.
51+ rules. Real ones. Battle-tested.
51+ fixed rules on standard AWS read-only APIs, across 30+ services and every region. Waste, idle, drift, RI/SP coverage, hygiene. The rules decide. You act.
Idle instances, office-hours EC2, and over-provisioned Lambda.
EC2 · SageMaker · LambdaVolumes nobody attached, old snapshots, gp2 still billed as gp2.
EBS · SnapshotsRDS busy only on weekdays, silent ElastiCache, unused DynamoDB.
RDS · ElastiCache · DynamoDBNAT with no traffic, unused load balancers, idle VPC endpoints.
NAT · ELB · VPCLog groups that never expire, unused secrets, stale images.
CloudWatch · Secrets · ECRAlso: Graviton candidates, Cost Optimization Hub, extended support surcharges. The full list is in the dashboard after you connect.
Digest in your inbox.
Full web report in the app.
Email carries a concise weekly summary you can forward. The full web report (trends, drill-downs, executive rollups) lives in the dashboard. Trends follow each unused resource over time. Realized savings are what actually cleared. Scan alerts (Slack or Teams) include what cleared since the last complete scan. Navi, on Business, sits on that report. On Enterprise, the leadership digest can also post to a Telegram Channel.
9 busy only on working hours · $1,240/mo
14 idle EC2 · $968/mo
Email is the weekly digest (see above). Slack and Teams carry scan alerts. Telegram is the leadership rollup, not per-account noise.
Sample of the in-app report. Same findings as the email, with drill-down.
The full report lives here.
Trends, accounts, and regions on the same findings. Navi is on Business, in that report. Email is the summary you can forward. Realized savings in the app are findings that cleared, not a guess.
Same digest. Built for a phone, and for people who do not live in AWS.
- ▸Org rollup across accounts. No resource IDs.
- ▸Posts to a channel you already run. Not a bot spam thread.
- ▸Opens the full web report when someone needs the detail.
mtd $48.2K +4.2% eom $72.4K waste $4.2K/mo 5.8% score 72/100 Good
1. Reclaim idle compute · Eng · $2.1K/mo
2. Convert gp2 volumes · Eng · $890/mo
An agent over your scans and web report.
On Business and Enterprise. Off until you enable it in Settings. Navi is the AI layer on top of your deterministic scans. Threaded chats and optional memory, with answers grounded in real findings and in-app report context, not the open web, not guesswork. On Enterprise, a Settings note for facts the scan cannot see. Read-only. Nothing runs in AWS without you.
- ▸Grounded in your scan findings and the in-app report, not the open web
- ▸Your prompts are not used to train foundation models. Nothing runs in AWS without you.
| Resource | Account / region | Weekly cost | Reason |
|---|---|---|---|
| m5.4xlarge i-0a1b2… | acme-prod / eu-west-1 | $612 | 3% CPU · idle 10d |
| 40 unattached gp3 | acme-staging | $498 | last attached > 30d |
| 2 NAT gateways | acme-dev | $134 | < 1MB egress/day |
details: app.unusd.cloud/scan/3f7a
Boring on purpose.
Full security pack · DPA, subprocessors, deletion, operator.
AssumeRolePolicyDocument:
Statement:
- Effect: Allow
Principal:
AWS: "arn:aws:iam::<unusd-hub>:role/scanner"
Action: sts:AssumeRole
Condition:
StringEquals:
sts:ExternalId: "<your-customer-id>"
ManagedPolicyArns:
- arn:aws:iam::aws:policy/SecurityAudit
Policies:
- PolicyName: unusd-cost-readonly
PolicyDocument:
Statement:
- Effect: Allow
Action:
- ce:GetCostAndUsage
- ce:GetCostForecast
- cloudwatch:GetMetricData
- cost-optimization-hub:ListRecommendations
- pricing:GetProducts
Resource: "*"Simple. Credit-based. Annual.
- credits
- 30 scans
- accounts
- 1
- Navi
- -
- drift
- -
- credits
- 15,000
- accounts
- unlimited
- Navi
- -
- drift
- ●
- credits
- 50,000
- accounts
- unlimited
- Navi
- Navi
- drift
- ●
- credits
- 100,000
- accounts
- unlimited
- Navi
- Navi
- drift
- ●
1 credit is 1 resource on one scan. Credits pool across every account you connect. Unlimited accounts from Startup. On a weekly schedule, Startup (15,000 credits) covers about 3,500 resources, Business (50,000) about 12,000, Enterprise (100,000) about 25,000. Daily scans use more credits. Prices are monthly, billed annually. Individual is 30 free scans on one account, no card. AWS Marketplace is how procurement pays.
Answers for security, FinOps, and AI.
Quick facts for procurement, platform teams, and anyone evaluating read-only AWS cost tooling.
Is unusd.cloud read-only on AWS?+
Yes. We use standard AWS read-only APIs and a read-only IAM role you deploy. Nothing is changed in your accounts unless you act on findings yourself.
What AWS services and regions do you scan?+
We run deterministic rules across 30+ services and every enabled region (51+ detection types). After you connect an account, the dashboard lists every check that ran.
Can I scan more than one AWS account?+
Yes. Connect an Organization or as many accounts as you need. Individual is one account. Startup and above are unlimited accounts, billed by credits, not by account count.
How does pricing work?+
1 credit is 1 resource on one scan. Credits pool across every account you connect. Unlimited accounts from Startup. On a weekly schedule, Startup (15,000 credits) covers about 3,500 resources, Business (50,000) about 12,000, Enterprise (100,000) about 25,000. Daily scans use more credits. Prices are monthly, billed annually. Individual is 30 free scans on one account, no card. AWS Marketplace is how procurement pays.
What do I get in email vs the app?+
Email carries a concise weekly digest you can forward. Slack and Teams get scan alerts, including how many findings cleared since the last complete scan. The full web report, trends, and drill-downs live in the dashboard. Navi, on Business, sits on that report. On Enterprise, the executive digest can also post to a Telegram Channel. Trends follow each unused AWS resource over time. Realized savings are findings that actually cleared.
How do you know a finding was fixed?+
A later complete scan no longer sees it. Delete it, attach it, or whitelist it: same signal. The dashboard calls that cleared. Incomplete scans do not mark missing regions as cleared.
How fast can I get the first scan?+
Most teams connect a read-only role in about five minutes and get a first scan shortly after.
How is Navi different from a generic chatbot?+
Navi is on Business and Enterprise, off until you enable it in Settings. It is grounded in your scan results and in-app report context, not open-web search. Optional memory is opt-in. On Enterprise, a Settings note covers org facts the scan cannot see.
Is my data or my prompts used to train foundation models?+
Your prompts are not used to train our models. Navi is off until you enable it. Then it sends scan-grounded context to OpenAI under their API terms. What we store, subprocessors, deletion, and how to request a DPA: unusd.cloud/security.
Connect an AWS account.
Digest in your inbox,
full report in the app.
Deploy a read-only role with one click. We run your first scan right away: digest by email, full web report in the app.
30 free scans · no credit card · 5-minute setup