Find the AWS spend nobody is using

Cloud Guard reads your account through a read-only role and reports what is costing money for no reason — priced from AWS list prices, with the evidence and the command that fixes it.

$ guard scan --target aws://prod  (example output) [OK] STS AssumeRole: arn:aws:iam::****:role/CloudGuardReadOnlyRole [SCAN] EC2, EBS, RDS, S3 across every enabled region... [COST] vol-0ab40… 8 GiB gp2, unattached → $0.80/mo [COST] eipalloc-0677… Elastic IP, unassociated → $3.65/mo [RISK] S3 bucket with public access detected [OK] RDS instances optimally sized ✓ Scan complete | Est. savings: $4.45/mo · every figure traced to a resource
0
Cost & security checks
0
Credentials we store
0
Scheduled scanning
0
Read-only access

How It Works

1

Deploy

Launch our CloudFormation template, then paste the role ARN back here. Takes about two minutes. Creates a read-only IAM role assumed via STS — we never hold long-term credentials.

2

Scan

Scans EC2, EBS, Elastic IPs, snapshots, RDS, S3 and Cost Explorer across every region you have enabled.

3

Act

Prioritized findings with risk levels, estimated savings, and Slack alerts. Fix issues before they become incidents.

The Guard Infra Suite

🟢 AVAILABLE NOW

Cloud Guard

AWS Infrastructure Security

  • Unattached EBS volumes, priced per GiB
  • Idle Elastic IPs — billed precisely because they are unused
  • gp2 volumes that should be gp3, 20% cheaper
  • Snapshots past your retention window
  • Public S3 buckets, idle and over-provisioned instances
  • CSV export and a copyable fix command per finding
Get Started →
🟣 OPEN SOURCE

Data Guard

A firewall for bad data

  • Validates API payloads and SQL rows against declarative rules
  • Pushes checks down into SQL instead of pulling every row
  • Alerts only when status flips, so the channel stays readable
  • Catches silent failures before they break logic downstream
View on GitHub
🟣 OPEN SOURCE

Shield

API Defense Engine

  • High-throughput Go rate limiter
  • Redis & in-memory backends
  • Sliding window & token bucket
  • Sub-millisecond enforcement
View on GitHub

Pricing

Free while we are early

$0/mo

Cloud Guard is new and I would rather have your feedback than your money. Connect an account, see what it finds, and tell me what is wrong with it.

  • Connect as many AWS accounts as you like
  • Scans every region you have enabled
  • Nine cost and security checks, priced from AWS list prices
  • CSV export and a copyable fix command per finding
  • Scheduled scans, with Slack alerts if you configure a webhook
Create an account

When paid plans arrive you will be told before anything changes, and nothing will start charging on its own.

Ready to secure your cloud infrastructure?

Start Scanning Now

Free while Cloud Guard is in early access · no card, no trial clock