2 weeks
Fixed scope, fixed price, defined deliverable
Read-only
One IAM role. No agents, nothing installed in your account
Priced
Every finding quantified in dollars per month, not percentages
Yours to keep
The plan is written so your team can implement it without us
Your bill is not high because of one mistake. It is high because of seven.
Teams asking why their AWS bill is so high usually expect one dramatic answer. There almost never is one. What we find instead is a stack of ordinary things: EC2 and RDS instances sized for a load test that ran two years ago, non-production environments that run at full size overnight and at weekends, EBS volumes still billing months after the instance they were attached to was terminated, a NAT Gateway charging per gigabyte for traffic that should be going through a VPC endpoint, chatty services split across availability zones paying cross-AZ transfer in both directions, years of forgotten snapshots and untagged ECR images, a handful of unused Elastic IPs, EKS node groups provisioned for a peak that arrives twice a year, and steady-state usage sitting entirely on on-demand rates with no Savings Plan coverage. Individually, not one of them is worth calling a meeting about. Together they are routinely a quarter to a third of the bill.
The reason they persist is not that they are hard to fix — most of them are an afternoon of work. They persist because nobody owns them. Cost falls into the gap between the platform team, who did not choose the workload, the product teams, who cannot see what their own service costs, and finance, who can see the total and nothing underneath it. Everyone can name a suspect. Nobody has the mandate, the data and an uninterrupted week to go and check.
A cost dashboard does not close that gap. It will tell you what you spent, sliced more ways than before, and it will be accurate. It will not tell you that your NAT Gateway charge is an architectural decision rather than a usage spike, that two RDS instances are running Multi-AZ for a workload that does not need it, or which three changes to make first given your release calendar. That is a judgement about your systems, and it takes an engineer who has read your bill line by line. That is what this audit is.
Core Capabilities
Audit vs. FinOps tool vs. doing nothing
These three are usually framed as alternatives. They are not — they solve different halves of the problem, and one of them is genuinely better than us at what it does.
If cost is a recurring conversation at your company, the honest answer is to do both. Buy a FinOps tool for continuous tracking and anomaly alerts — CloudZero, Vantage and Cast AI are all good at that, and a one-off audit is not. Then run an audit once, because the architectural findings — the NAT Gateway path, the cross-AZ chatter, the commitment gap, the cluster sized for a peak that never comes — are the ones no dashboard will ever raise as a ticket.
Our Process
Read-Only Access & Kickoff — Day 1
You create one IAM role with the AWS-managed ReadOnlyAccess and Billing policies, scoped to an external ID. We install no agents and deploy nothing into your account. A 45-minute kickoff covers your architecture, what is production, what is disposable, and any change freezes we need to respect.
Automated & Manual Analysis — Days 2 to 6
Automated passes over the CUR, Compute Optimizer, Trusted Advisor and CloudWatch catch the mechanical waste. Then an engineer reads the bill by hand, because the expensive findings are almost always architectural and no tool flags them as anomalies — they have been steady-state for a year.
Findings Priced & Ranked — Days 7 to 9
Every finding gets a monthly dollar figure, an implementation effort in hours or days, and a risk rating. They are then ranked by return against effort and risk, so the list opens with things you can safely do this week and closes with the ones that need a design discussion.
Walkthrough Session — Day 10
A 90-minute session with your engineering and finance stakeholders, walking the findings with the engineer who produced them. You get the written report, the underlying queries, and a remediation backlog you can paste straight into Jira or Linear.
Implementation — Optional
Most teams take the plan and run it themselves; it is written for that. If you would rather not spend the sprint capacity, we can implement the changes — right-sizing, lifecycle rules, VPC endpoints, commitment purchases, Karpenter rollout — under a separate, separately scoped engagement.
Tech Stack
We choose the right tool for the job — not the trendiest one.
AWS
Kubernetes
Terraform
Python

