CLOUD CLEANUP. WITH A SAFETY NET.

Stop paying for
resources that are dead.

Find abandoned AWS resources. Prove they’re unused with GitHub evidence. Shut them down safely—with the owner in the loop.

Read-only first. No surprise deletions. No blind trust.

LIVE RESOURCE SCAN READ-ONLY MODE
gpu-inference-dev
api-production
preview-db-vol
prod-database
llm-eval-endpoint
prod-nat-east
zombie-cli
$ zombie scan --dry-run
Matching infrastructure to code activity…0 resources modified
YOUR STACK. CONNECTED. AWS+ GitHub+ Slack
● THE PR IS MERGED. THE BILL ISN’T.

Your code moved on.
Your cloud resources didn’t.

That GPU experiment. That preview environment. That “temporary” endpoint. Dashboards flag the waste. Zombie connects the evidence—and helps you safely act on it.

ONE FORGOTTEN GPU ENDPOINT
$349.0600

burned since its PR was merged.

↗ +$1.212 / hour · illustrative example
DON’T TRUST A HUNCH. FOLLOW THE EVIDENCE.

Idle isn’t enough. Prove it’s abandoned.

CPU and tags tell half the story. A merged PR, a deleted branch, and no activity? Now you have something to act on.

Infrastructure ↔ code
dry-run-reportSAMPLE DATA
Resource / IDEvidenceStatusMonthly waste
No resources changed. Ever, in dry-run.3 resources · $1,948.96/mo
A SAFETY NET AT EVERY STEP

Less waste. No surprise deletions.

Start with read-only AWS access and a GitHub app. Detect idle resources, verify ownership and code activity, then retire them on your terms.

01

Notify

The right owner gets the evidence in Slack.

02

Grace period

Approve, extend, or exempt. Nothing happens in silence.

03

Stop

Stop the spend first. Keep the resource recoverable.

04

Snapshot

Preserve the data before anything is deleted.

05

Terminate

Only after approval and your retention window.

BUILT FOR AWS. CONNECTED TO GITHUB.

Find the expensive things you forgot.

GPU & AI experiments

Idle EC2 GPU nodes, SageMaker endpoints and notebooks, provisioned Bedrock throughput, and self-hosted vLLM or Ollama workloads.

Storage left behind

Unattached EBS volumes and orphaned snapshots, traced back to the environment and code that created them.

Quiet infrastructure

Unassociated Elastic IPs, idle NAT gateways and load balancers, and forgotten EC2 instances.

SAFE IS THE DEFAULT

Your infrastructure. Your final say.

A resource cleanup engine should earn permissions, not ask you to trust a black box.

Read-only comes first

Connect an AWS IAM role without write permissions. See the evidence before granting execution access.

Approval, not autopilot

Owners review the evidence in Slack. Grace periods and retention windows keep people in control.

A path back

Stop before terminate. Snapshot before delete. Preserve what matters before retiring a resource.

Your policies. Your boundaries.

Exempt tags and YAML policies protect the resources that should never be touched.

Nothing disappears from the record

A full audit trail of evidence, owner decisions, and every action taken.

Policies you can inspect

An open-source policy engine is part of the product design. Inspect the rules before granting permissions.

This preview is a simulation. No AWS, GitHub, or Slack account is connected.