ACCESS INTELLIGENCE FOR CLOUD STORAGE

Who's Touching Your S3 Data?

Every read, by every identity - agents, pipelines, people - on every object. reCost turns your S3 access logs into security, data flow, and cost intelligence. No agents to install, connects in 5 minutes.

Book a Demo
Live Access Intelligence
s3://prod-data · access logs
IDENTITIESS3 OBJECTSRAG agentbedrock:claudeETL pipelineglue:nightlyLangChain agentsdk:boto3/1.34Unregistered agentsdk:boto3/1.9 ⚠models/embeddings/2.4M reads · 24hanalytics-parquet/312 GB scannedpii-exports/dormant 3y → readraw-events/2026/$418/day GET cost
Shadow agent detectedDormant data awakenedRunaway reads: 2.1M/dayCost spike traced to prefix
no_agentsmetadata_only5min_setupaws_nativezero_data_access
WHY RECOST

Your AWS data layer is running blind

Five layers deep, one blind spot wide. Watch what reCost surfaces at every level of your stack - from the agents at the top to the access logs at the bottom.

AI Agents & Identities
bedrock · langchain · services · humans
Query Engines
athena · spark · trino
Lakehouse Tables
iceberg · delta lake · hudi
S3 Objects
buckets · prefixes · objects
S3 Access Logs
the record you already have
recost://live-analysis
who is doing what
  • Every agent fingerprinted by access pattern + user-agent
  • 17 machine identities found · 3 were never registered
  • Runaway agent looping hot bucket 2.1M reads/day
shadow agentsrunaway reads
what queries really cost
  • Scan cost attributed per table, per query pattern
  • Full scans reading 4.2x more bytes than they return
  • 214 cold partitions scanned on every single query
cost per tablescan waste
what is silently breaking
  • 4 pipelines stopped writing · no alarm ever fired
  • 42,015 orphaned snapshots across 134 tables
  • Compaction lag adding 18% overhead to every read
broken writerstable health
who reads, who writes
  • Every read and write, by every identity, per object
  • Dormant 3 years - then read in bulk at 3am: flagged
  • $418/day GET cost traced to one prefix
dormant datacost anomaly
one read-only source
  • reCost reads the logs AWS already writes - nothing installed
  • Security, data flow, and cost signals from one connection
  • First finding in under 5 minutes
agentless5 min setup
FEATURES

Everything reCost sees

One platform for S3 monitoring, data lake health, pipeline observability, and IAM security. Covers Delta Lake, Athena, Spark, Glue, and more.

Data Lake Health Monitoring01 / 06

Know exactly what's degrading inside your tables

Snapshot counts, orphaned files, manifest bloat, and small file accumulation, per table, per engine. Covering Delta Lake health, Iceberg snapshots, and Hudi compaction, all from S3 inventory and access logs, without touching your catalog.

reCost · Data Lake Health Monitoring
live
DETECTED
42,015
orphaned snapshots detected
15.6 TB recoverable · expiry policy never enforced · affecting 134 Iceberg tables across prod-data-lake
INTEGRATIONS
Apache Iceberg
Apache Iceberg
Delta Lake
Delta Lake
Apache Hudi
Apache Hudi
Apache Spark
Apache Spark
Databricks
Databricks
AWS Glue
AWS Glue
ACCESS INTELLIGENCE

Every request, mapped end-to-end

See exactly which IAM roles are hitting which buckets, prefixes, and operations, down to the object level. No sampling, no blind spots.

IAM ROLEBUCKETPREFIXOPERATIONetl-pipeline-role520k req/mospark-analytics-role380k req/moapi-ingest-role290k req/moml-training-role180k req/modev-console-role60k req/moprod-data-lakeS3 · bucketanalytics-storeS3 · bucketarchive-coldS3 · bucketiceberg/orders/table prefixdelta/events/table prefixspark-output/write prefixarchive/2021/cold prefixGETobject readPUTobject writeLISTprefix listDELETEobject delete

IAM Role → Bucket → Prefix → Operation · live data flow map

"42,015 snapshots on a single Iceberg table. Expiry had never run. Query planning overhead was costing them on every scan. We found it in minutes."

This is what object-level observability looks like.

SUPPORTED TECHNOLOGIES
Apache Iceberg
Delta Lake
Apache Hudi
Databricks
Amazon Athena
Trino
Apache Spark
AWS Glue
Amazon S3
AWS IAM
Amazon CloudFront
Amazon Redshift

See exactly what's happening in your S3 data layer

Works with your existing AWS setup. Read-only access. No agents. No data exposure.

Book a Demo