Skip to content
01Free AWS Cloud Recon

See what is hiding in your AWS account.

A first-time, no-cost look at your AWS account across the three things that quietly cost you the most: security exposure, wasted spend, and architecture that will not age well.

Request your free reconFree · Read-only · No obligation
02What I look at

Three lenses, one honest picture.

The recon covers the three things that quietly cost the most. You get findings that are triaged and readable, not a raw tool dump.

Security findings

Where you are exposed, ranked by how much it should actually worry you.

  • Public exposure, over-broad IAM, and unencrypted data
  • Logging, guardrail, and threat-detection gaps
  • Findings triaged by severity, not a 400-page dump

Cost & FinOps

The spend that is not earning its keep, with dollar figures attached.

  • Idle and oversized resources, and orphaned storage
  • Commitment coverage: Savings Plans and Reserved Instances
  • A ranked list of savings with estimated monthly impact

Best practices

A Well-Architected read on what will bite you as you scale.

  • Reliability, performance, and operational gaps
  • Single points of failure and missing automation
  • The few changes that matter, sequenced
03What you walk away with

A report you can act on Monday.

  • Ranked findings across security, cost, and best practices
  • Estimated monthly savings, with the biggest items called out
  • Quick wins you can action this week, separated from bigger work
  • A 30-minute readout call to walk through all of it

Delivered as a ranked report plus a 30-minute readout call. Yours to keep, whether or not we work together.

04How it works

One week, four steps, zero risk.

You grant read-only access, I do the work in my environment, and you get a report. That is the whole thing.

01

Grant read-only access

You deploy a one-click CloudFormation stack. It creates a read-only, audit-scoped role I can assume, plus read access to your cost data. It can look, never touch.

02

I run the recon

Everything runs in my environment against that read-only access. Automated analysis plus a Well-Architected review by hand. Nothing is deployed or run in your account.

03

You get the report

A ranked findings report with quick wins, strategic fixes, and estimated savings, walked through on a 30-minute readout call.

04

You decide

No obligation. Take the report and fix it yourself, or bring me in to do it. You keep the findings either way.

05The part your security team will ask about

Read-only. Runs on my side. Revocable.

You are handing an outside party access to your cloud, so the access model is built to make that an easy yes.

Read-only and audit access

You grant look-but-do-not-touch: AWS SecurityAudit and ViewOnly access plus read-only Cost Explorer and billing data. No write permissions exist, anywhere.

Runs in my environment

The scan runs from my account against that read-only role. Nothing is deployed or left running in yours, so there is no EC2 or process for you to pay for.

Revocable in one click

Access is a cross-account role scoped to my account with an ExternalId. Delete the CloudFormation stack and it is gone. Nothing persists.

Access is granted by a one-click CloudFormation stack you deploy in your own account. It creates a cross-account role with AWS-managed read-only and audit policies plus read access to your cost data, scoped to my account with an ExternalId. You review exactly what it can do before you deploy it, and delete the stack to revoke it.

06Why it is free

Because the fastest way to show you what I would bring to a paid engagement is to bring it. Most accounts turn up enough to pay for the fix many times over. If yours does not, you still keep the report, and I would rather you know that than sell you work you do not need.

07FAQ

The usual questions.

Yes. The recon and the readout call cost nothing and carry no obligation. It is how I show what I would bring to a paid engagement. Most accounts turn up enough to justify one, but that is your call.

No. The scan runs entirely in my environment against read-only access. Nothing is deployed or left running in your account, so there is no EC2, agent, or process on your side to pay for.

The access is read-only and audit-scoped by design: AWS-managed SecurityAudit and ViewOnly policies plus read-only cost data, granted through a cross-account role with an ExternalId that trusts only my account. No write access exists, and you delete the stack to revoke it.

About a week. Once the role is in place the scan itself is quick. Writing up findings that are actually useful takes a couple of days.

You keep the report and act on it however you like. There is no follow-up pressure. If it is useful later, you know where I am.

Find out what a fresh set of eyes sees.

Free, read-only, and run on my side. Tell me a bit about your setup and I will send the access template.

Request your free recon