Slide 1 · Live ROI Engine

Drag the sliders. Watch your savings load in real time.

This is the same engine that runs on your account. Move the spend slider to your real AWS bill. Adjust the maturity profile. Everything rebuilds instantly.

Monthly AWS spend
$50,000
/ month
$1K$10K$50K$100K$250K$500K
Account maturity profile 12% waste rate
Startup — mostly greenfield. Low orphan resource rate. Some over-provisioning typical of fast growth.
Monthly waste
$6,000
found in your bill
Annual waste
$72,000
recoverable this year
Plan cost
$588
$49/mo · unlimited
Net first-year gain
$70,812
120× return on plan
Where the savings come from · tap any row
Total recoverable
$6,000 / mo
Slide 2 · Three ways to connect

Pick the credential path that fits your security posture.

Every path is read-only. Every path runs in under 30 seconds. Every path returns the same findings.

Path 1 · IAM Role — safest

You create an IAM role in your account that trusts ours. We call sts:AssumeRole and get temporary credentials that expire in 15–60 minutes. Your secret keys never touch your own resources. Revoking access is one click — delete the role.
Read-only Temporary creds One-click revoke

Path 2 · STS keys — fastest

Paste temporary session credentials generated by aws sts get-session-token. They expire in 1–36 hours. Better than long-lived access keys, same UX as pasting.
1-36 hour expiry No role setup

Path 3 · CUR / CSV upload — zero credentials

Upload a Cost & Usage Report or a Cost Explorer CSV export. We parse it locally — no API calls, no account access, nothing stored. The file is deleted from the temp directory the moment parsing finishes.
Zero credentials Maximum safety Works with any export
Side-by-side comparison
PathYou hand overOur accessRevocation
IAM RoleRole ARN + own keys (used once)Temporary, scoped to roleDelete the role
STS KeysSession credentialsTemporary accessWait for expiry (1–36h)
CUR UploadJust a CSV fileNothing at allDelete the file
Slide 3 · How it works under the hood

Three steps. Thirty seconds. Zero standing access.

Whether you connect via role, keys, or CSV — the pipeline is the same three-step process.

Step 01 · Connect

Depending on the path you chose, we either assume a scoped role, use short-lived session credentials, or read a CSV you uploaded. In every case, the credentials (or the file) exist only for the duration of the scan and are discarded the instant it finishes.

Step 02 · Scan

We query 20 AWS services in parallel — EC2, EBS, RDS, ElastiCache, Redshift, Lambda, S3, EFS, NAT, ELB, Elastic IPs, CloudWatch Logs, Secrets Manager, CodeBuild, Kinesis, Step Functions, EKS, ECS, OpenSearch, DynamoDB. Every check a senior FinOps engineer would run.

Step 03 · Price

Every finding is matched against current AWS on-demand pricing. An unattached gp3 volume is $0.08/GB/month. A NAT gateway is $32.40/month. A forgotten EKS control plane is $73/month. You see the exact dollar figure for every resource.
How you recover 20× — and often 100× — the plan cost

Tap any row to see the full explanation of each savings category.

Savings sourceTypical recoveryEffort to fix
$200–$2,000 / mo5 min · Delete in console
$300–$3,000 / mo1–2 hrs · Stop or resize
$150–$1,500 / mo30 min · Delete or consolidate
$400–$4,000 / mo2–4 hrs · Rightsize or schedule
$200–$2,500 / mo1 hr · Set retention & lifecycle
Slide 4 · Comparison + 24/7 service

Why teams choose PING192.

Four main players in AWS cost intelligence. Here's an honest breakdown — including where they win and where we do.

How we compare
CapabilityCostMunchnOpsVantageCloudHealthPING192
Starting price$49 one-time$199+/moCustomCustom$49/mo flat
Time to first scanMinutesDays–weeksDays–weeksWeeks30 seconds
Setup complexityCross-account roleCUR + agentCUR + S3Multi-cloud rolesThree paths
CSV reportOn requestDashboardDashboardScheduledInstant, every scan
Human supportEmail24/7 enterpriseEnterprise SLA24/7 live repNamed consultant at $999
Data storageRetainedTelemetryCUR ingestedAll dataNothing stored
Open sourceNoNoNoNoYes — one PHP file

The proprietary thing no one else does

Every competitor is built around the same assumption: the tool needs ongoing access to your AWS account — via a cross-account IAM role, a CUR export, an agent, or all three. That's why onboarding takes days and why security reviews block adoption.

We built the opposite. PING192 requires nothing that persists. Three credential paths, all read-only, all discard-after-use. For security-conscious teams, upload a CUR — we never touch your account at all.

24-hour human service · on-the-spot CSV

Every scan produces a downloadable CSV the moment it finishes — not a "we'll email you" promise.

Managed ($199/mo): 24/7 Slack channel with a real engineer. Under 1-hour response, any hour.
Enterprise+ ($999/mo): A named engineer who knows your account. Direct phone line. Joins your calls. Weekly strategy sessions. Under 15-minute SLA on critical issues.

Scan your account. See your real number.

Read-only keys. Nothing stored. CSV in hand in 30 seconds. If we don't find waste worth more than $49, don't sign up.

RUN THE SCANNER →
1 / 4
← Back to ping192.sbs