PERMISSIONS ARE EARNED

Stop the waste.
Keep the control.

First, a dry-run report with costs and evidence for every resource. Execution stays behind explicit permissions, owner decisions, and your own policies.

SAFE IS THE DEFAULT

Your infrastructure. Your final say.

A resource cleanup engine should earn permissions, not ask you to trust a black box.

Read-only comes first

Connect an AWS IAM role without write permissions. See the evidence before granting execution access.

Approval, not autopilot

Owners review the evidence in Slack. Grace periods and retention windows keep people in control.

A path back

Stop before terminate. Snapshot before delete. Preserve what matters before retiring a resource.

Your policies. Your boundaries.

Exempt tags and YAML policies protect the resources that should never be touched.

Nothing disappears from the record

A full audit trail of evidence, owner decisions, and every action taken.

Policies you can inspect

An open-source policy engine is part of the product design. Inspect the rules before granting permissions.

This preview is a simulation. No AWS, GitHub, or Slack account is connected.
A SAFETY NET AT EVERY STEP

Less waste. No surprise deletions.

Start with read-only AWS access and a GitHub app. Detect idle resources, verify ownership and code activity, then retire them on your terms.

01

Notify

The right owner gets the evidence in Slack.

02

Grace period

Approve, extend, or exempt. Nothing happens in silence.

03

Stop

Stop the spend first. Keep the resource recoverable.

04

Snapshot

Preserve the data before anything is deleted.

05

Terminate

Only after approval and your retention window.