Cost Explorer

Find the cloud spend you forgot you're paying for.

Read-only scan of AWS and GCP. Ranked savings, with the exact fix. Open-source engine.

Run a free scan
npx costexplorer scan ./cur-export

Prefer not to connect an account? Try the CLI. It runs on your machine.

Estimated monthly waste

$789/mo

Sample report
  • Oversized compute

    3 × m5.2xlarge · p95 CPU 11%

    $420/mo

    medium

  • Savings Plan coverage gap

    $1.20/hr steady on-demand baseline

    $219/mo

    medium

  • NAT gateway data processing

    2,000 GB/mo of S3 traffic via NAT

    $90/mo

    high

  • Unattached EBS volume

    500 GB gp3 · detached 41 days

    $40/mo

    high

  • gp2 volumes

    1,000 GB still on gp2

    $20/mo

    high

Illustrative demo data at us-east-1 list prices, not a customer account.

29%

of cloud spend is wasted, by organizations’ own estimate. Billing dashboards tell you what you spent. They don’t tell you what to turn off on Monday.

Source: Flexera 2026 State of the Cloud Report, self-reported waste on IaaS and PaaS.

How it works

From connect to fix list in three steps

  1. 1About 2 minutes

    Connect read-only

    Deploy a one-click CloudFormation stack that creates a read-only role scoped to your account. Or skip it and point the CLI at an export on your laptop.

  2. 2A few minutes

    We analyze

    The open-source engine runs every analyzer over your cost export and resource inventory: idle, stale, oversized and mispriced resources.

  3. 3Yours to keep

    You get a ranked fix list

    Findings sorted by dollars saved per month, each with the evidence, a confidence level and a CLI or Terraform snippet you apply yourself.

Sample findings

Findings, not dashboards

Every finding leads with a dollar figure, shows its math and ends with the fix. Estimates are deliberately conservative.

aws.ebs.unattachedhigh confidence

Unattached EBS volume

$40/month

Evidence
vol-0a1b…9f2 · 500 GB gp3 · no attachment for 41 days
Math
500 GB × $0.08/GB-month

Fix

aws ec2 create-snapshot --volume-id vol-0a1b…9f2
aws ec2 delete-volume --volume-id vol-0a1b…9f2
aws.nat.s3-via-gatewayhigh confidence

NAT gateway that should be a VPC endpoint

$90/month

Evidence
nat-04c7…e1d · 2,000 GB/month of S3 traffic processed
Math
2,000 GB × $0.045/GB data processing

Fix

aws ec2 create-vpc-endpoint --vpc-id vpc-7d2e…a40 \
  --service-name com.amazonaws.us-east-1.s3 \
  --route-table-ids rtb-91f3…c08
aws.savingsplan.coverage-gapmedium confidence

Savings Plan coverage gap

$219/month

Evidence
$1.20/hr of on-demand compute, steady for 60 days
Math
$1.20 × 730 hrs × ~25% 1-year no-upfront discount

Fix

aws ce get-savings-plans-purchase-recommendation \
  --savings-plans-type COMPUTE_SP --term-in-years ONE_YEAR \
  --payment-option NO_UPFRONT --lookback-period-in-days SIXTY_DAYS

Illustrative examples at us-east-1 list prices. Your report uses your own rates.

Security

We never get write access

  • Read-only by design

    The role has no create, update or delete permissions. Fixes are snippets you review and run yourself.

  • No long-lived keys

    Access is a cross-account IAM role trusted only by our account and scoped by a per-customer ExternalId. Remove the stack and access is gone.

  • 30-day raw data retention

    Raw exports are deleted after 30 days. Findings and aggregates are kept, encrypted with per-tenant keys.

  • Or connect nothing

    The CLI runs the same analyzers locally against an export.

Read the IAM policy before you click anything
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "CostAndUsageRead",
      "Effect": "Allow",
      "Action": [
        "ce:Get*",
        "ce:List*",
        "ce:Describe*",
        "cur:DescribeReportDefinitions",
        "savingsplans:Describe*"
      ],
      "Resource": "*"
    },
    {
      "Sid": "InventoryAndMetricsRead",
      "Effect": "Allow",
      "Action": [
        "ec2:Describe*",
        "elasticloadbalancing:Describe*",
        "rds:Describe*",
        "logs:DescribeLogGroups",
        "s3:ListAllMyBuckets",
        "s3:GetBucketLocation",
        "s3:GetLifecycleConfiguration",
        "cloudwatch:GetMetricData",
        "cloudwatch:ListMetrics"
      ],
      "Resource": "*"
    },
    {
      "Sid": "CostExportBucketRead",
      "Effect": "Allow",
      "Action": ["s3:GetObject", "s3:ListBucket"],
      "Resource": [
        "arn:aws:s3:::YOUR-CUR-BUCKET",
        "arn:aws:s3:::YOUR-CUR-BUCKET/*"
      ]
    }
  ]
}

The onboarding template lives in the public repo, so you can audit exactly what access you grant.

Open source

Read every rule we run

The analysis engine is Apache-2.0. Each analyzer is one file with fixtures and tests, and the pricing data behind the savings math is versioned alongside it. Found waste we miss? Contribute an analyzer.

Pricing

Flat tiers, no percent of savings

CLI

Free

Open source

  • All public analyzers
  • Local reports
  • Runs entirely on your machine
View on GitHub

Free hosted

$0

No credit card

  • 1 account
  • Monthly scan
  • Free-tier analyzers
  • Shareable waste report
Run a free scan

Pro

$49

per month

  • 5 accounts
  • Weekly scans
  • All analyzers
  • Slack alerts
  • Anomaly detection
Start with a free scan

Team

$199

per month

  • Unlimited accounts
  • Daily scans
  • Multi-user
  • CSV and API export
  • White-label reports for consultants
Start with a free scan

FAQ

Questions engineers ask first

Is this affiliated with AWS?

No. Cost Explorer (costexplorer.net) is an independent product. It is not affiliated with, endorsed by or sponsored by Amazon Web Services, and it is not the AWS billing tool of the same name.

What permissions does it need?

A cross-account IAM role with read-only access to billing data, your cost export bucket, resource metadata and CloudWatch metrics, scoped by a per-customer ExternalId. The policy is published above and in the public repo.

What data do you keep?

Raw cost exports are processed and deleted after 30 days. We keep the findings and aggregates that make up your report. Data is encrypted with per-tenant keys.

Does it change anything in my account?

No. The role has no create, update or delete permissions. Every fix is a CLI or Terraform snippet that you review and apply yourself.

Which clouds are supported?

AWS first. GCP follows once the AWS findings are solid, and Azure comes after that.

What if I don't want to connect an account at all?

Run the open-source CLI against a cost export on your own machine. Nothing leaves your laptop.

See what you’re wasting in the next five minutes

Read-only, free, and no credit card. Or run it locally first.

Run a free scan
npx costexplorer scan ./cur-export