Skip to content
CloudSave

How CloudSave works

CloudSave reads your billing and inventory data through a read-only connection and turns it into a prioritised list of savings. Nothing is ever changed in your account without your sign-off, and the connection can be revoked by you at any time.

1. Connect

You grant read-only access — never a password, never write access. On AWS that is a one-click CloudFormation stack that provisions an IAM role limited to Cost Explorer, EC2, RDS, S3, EBS, Lambda and CloudWatch. Every provider we add gets the equivalent native grant: a service principal on Azure, a service account on GCP. You can revoke it yourself, at any time, without asking us.

2. Scan

We inventory what you run, how it is used, and what it costs — idle instances, unattached volumes, oversized databases, unused elastic IP addresses, lifecycle gaps, and over-provisioned functions — and match provider pricing to your actual workload.

3. Report

You get an executive summary, a per-service breakdown, and a priority matrix that separates quick wins from strategic moves. Every recommendation carries a projected saving and the effort it takes.

4. Act

Implement what you agree with. We re-scan on request and show you what changed, so a finding is either fixed or still on your list — never quietly dropped.

Which clouds we analyse

We analyse AWS today. Further providers are on the roadmap, and the current list with the dates we have published lives in the provider coverage section of the homepage.

Edited in the CMS at /admin; last reviewed 2026-09-18.