Pay for the workload, not the accident.
A cloud bill is an architecture diagram with prices on it. We read it that way — finding the traffic that should never have left the VPC and the capacity nobody has used since launch.
Where the money usually is.
Cost work is concrete, measurable and fast to prove — which is why it is often the first thing we do together, and why it so reliably leads into the broader infrastructure work.
- Cloud cost assessment A full read of the bill against the architecture, with findings ranked by saving and by effort.
- ECS and Fargate right-sizing Task and service sizing from real utilization over a full cycle, with autoscaling for the peaks.
- NAT Gateway traffic analysis Flow logs answer what is actually crossing the gateway — usually AWS services and a retry loop.
- VPC endpoint strategy Interface and gateway endpoints where they pay for themselves, priced before they are deployed.
- RDS and Aurora optimization Instance class, storage type, replica count, backup retention and the idle databases nobody owns.
- Storage lifecycle optimization S3 class transitions, expiry rules, orphaned snapshots and unattached volumes.
- Idle and unused resource identification Load balancers with no targets, environments left running, addresses billed for doing nothing.
- Monthly cost governance and reporting Tagging and allocation, budgets and anomaly alerts, and a monthly figure your finance team trusts.
An 88% cut that was really a bug fix.
The line item was NAT data processing, growing month over month. The cause was not the gateway.
Flow log analysis showed two things: application traffic reaching S3 and other AWS services over the public path, and one container failing and restarting in a loop, re-pulling its dependencies every time. Private service endpoints removed the first. A stability fix removed the second.
Nothing was discounted, reserved or committed to. The traffic simply stopped existing — which is why the saving held the following month, and the month after that.
Reductions in the affected line items, not in total spend. What applies to your estate depends on what is in it.
Two weeks, ranked findings, no lock-in.
You get a written report: every finding with the saving, the change required, the risk and the effort. Implement it yourself, hand it to your team, or have us do the work — the report is yours either way.
-
Read-only access
Cost and usage data, plus a role scoped to describe resources. Nothing is changed.
-
Bill against architecture
Every significant line item traced to the thing that generates it.
-
Verify before recommending
Flow logs, utilization and access patterns — evidence, not assumptions about workloads.
-
Rank by saving and effort
What to do this week, this quarter, and what is not worth the disruption.
-
Implement and measure
Changes made as code, with the before and after figures published.
Is your bill growing faster than your traffic?
That gap is usually a handful of findings. An assessment tells you which ones, and what each is worth.