Fixed-price audit

A complete cloud cost audit in two weeks, for a fixed fee

We scan your AWS or Google Cloud accounts with read-only access, price every saving we find, and hand your engineers a ranked fix plan. If we find less than three times our fee in annual savings, we refund it.

Your team's time: about 2 hours in total, for setup and the readout.

Price
From $1,500, fixed
Timeline
2 weeks from access
Access
Read-only, no keys
You get
Priced findings and a fix plan

Is this right for you?

A good fit if

  • You spend $10,000 or more a month on AWS or Google Cloud and the bill keeps growing faster than the business.
  • You want an independent, line-by-line answer before you buy any cost tool or hire a FinOps person.
  • Your engineers will act on a clear list, but nobody has time to build one.
  • You are planning a budget, a renewal or a board conversation and need defensible numbers.

Probably not for you if

  • Your monthly cloud bill is under about $5,000. Our free tools will get you most of the way.
  • You run mainly on Azure. We do not cover it today.
  • You want someone to make changes in production without your team reviewing them.

What you walk away with

01

Every saving, priced

A workbook of every finding with its monthly and annual saving, effort, risk and owner, ranked so the biggest, safest wins come first.

02

A plan your engineers can ship

The top fixes written up as Terraform changes or step-by-step runbooks, not slides. Your team reviews and applies them like any other change.

03

A clear answer on what to do next

A readout call that covers what to fix this month, what to commit to, and whether ongoing help is worth it for you. Sometimes the honest answer is no.

What is included

Every package includes all of this. The tiers below change the size of the estate we cover and how much hands-on help you get.

120+ checks across 30+ AWS services

Idle and oversized compute, unattached storage, old snapshots, database sizing, NAT and data transfer, Lambda, containers, caching and more.

Google Cloud coverage

Compute Engine, GKE node pools, Cloud SQL, Cloud Storage, BigQuery, Bigtable, Dataflow and committed use discounts.

Commitment and rate review

How much of your steady usage is covered by Savings Plans, Reserved Instances or committed use discounts, and what is being wasted on unused commitments.

Tagging and allocation check

How much of your spend can be traced to a team or product today, and the smallest set of tags that would close the gap.

Anomalies and trends

Recent spikes, services growing faster than the rest, and the cost drivers behind them.

A practitioner, not a report generator

Every finding is reviewed by a FinOps-certified practitioner before you see it, so the list contains changes worth making.

What we hand over

  • Findings workbook (Excel) with every saving priced and ranked
  • Executive summary: total opportunity, top 10 fixes, quick wins
  • Fix plan: Terraform changes or runbooks for the top fixes
  • AWS Well-Architected cost pillar mapping (COST01 to COST11)
  • Waste Score per AWS account, so you can track progress
  • 60-minute readout with your engineering and finance leads

How it works

  1. Day 0

    Free scoping call

    Thirty minutes to confirm your clouds, accounts and goals. You get a written quote that matches one of the packages below, so there are no surprises.

  2. Day 1

    Connect read-only access

    On AWS, one CloudFormation stack per account, deployed with our engineer on a short call. Turn on Cost Explorer a day earlier. On Google Cloud, one setup script in Cloud Shell, about five minutes.

  3. Days 2 to 4

    We scan and analyze

    The Finitizer platform runs its checks across every account in scope. A practitioner reviews each finding, removes the noise and prices what is left.

  4. Day 5

    First-look call with quick wins

    Twenty minutes on the safest, largest savings we have found so far, so your team can start on them while we finish the rest.

  5. Days 6 to 10

    Fix plan and workbook

    Findings ranked by saving and effort, with the top fixes written up as Terraform changes or runbooks your team can apply.

  6. Days 10 to 14

    Readout and follow-up

    A 60-minute walkthrough with your team, then email follow-up while you ship the first fixes. Remove our access whenever you like.

Pricing

One fixed fee per audit, agreed before we start. Paid by card or by invoice at kickoff. Prices are in US dollars and exclude applicable taxes.

Starter

One cloud (AWS or Google Cloud), up to 3 accounts or projects

Typical spend: $10,000 to $40,000 a month

$1,500USD, one-time

  • Full read-only scan of every account in scope
  • Findings workbook with every saving priced
  • Top 10 fixes ranked by saving and effort
  • 60-minute readout call
  • 14 days of email follow-up
Request Starter
Most popular

Standard

AWS and Google Cloud, up to 10 accounts or projects

Typical spend: $25,000 to $150,000 a month

$2,500USD, one-time

  • Everything in Starter
  • Terraform changes or runbooks for the top 10 fixes
  • Commitment coverage review and purchase plan
  • AWS Well-Architected cost pillar mapping
  • 30 days of email follow-up
Request Standard

Plus

Up to 25 accounts or projects, with hands-on help

Typical spend: $100,000 a month and up

$5,000USD, one-time

  • Everything in Standard
  • Two working sessions with your engineers to ship the first fixes
  • Every finding filed as a Jira ticket with an owner, if you use Jira
  • A second scan after 30 days showing what changed
Request Plus
  • More than 25 accounts or projects? Book a call and we will quote it.
  • Start FinOps-as-a-Service within 60 days and the full audit fee is credited to your retainer.

Three times the fee, or your money back

If the audit does not identify at least three times its fee in annual savings, estimated conservatively from your own usage data, we refund the fee in full. It is written into your order, and you keep the workbook either way.

Access and security

We need to read your cloud configuration and billing data. We never need to change anything, and you can remove our access at any time.

  • We sign your NDA before any access is granted, and send the exact IAM policy and trust policy for your security team to review first.
  • AWS: one CloudFormation stack per account creates a single IAM role with a read-only policy built from the checks you choose. No AWS managed policies, no admin rights.
  • No keys and no shared secrets. The role trusts one Finitizer scanner identity through OIDC federation, so there is nothing to leak or rotate.
  • Explicit deny rules block reading your data: S3 objects, DynamoDB items, CloudWatch Logs, container images and Lambda invocation.
  • Google Cloud: you grant viewer roles to a dedicated Finitizer reader identity at project or folder level. No keys are created, and no organization or billing-account roles are needed.
  • What we keep: configuration, usage and billing metadata, stored in a dedicated dataset for your company in Finitizer's Google Cloud environment in the US, and deleted on request.
  • Remove access in minutes by deleting the CloudFormation stack or the role grants.

Who does the work

Nitin GandhiFounder, Finitizer

Every engagement is led by Finitizer's founder, a FinOps practitioner who has run cost programs inside large enterprises, not just advised them. The Finitizer platform does the scanning; the judgment is human.

  • 25 years in enterprise IT
  • FinOps programs for IT budgets of more than $220 million
  • Five FinOps certifications
  • MBA, Cornell University

Frequently asked questions

How is this different from the free savings analysis?

The free savings analysis is a short, automated scan with headline numbers, aimed at teams evaluating the Finitizer platform. The audit is a complete, practitioner-led review: every finding priced and ranked, a fix plan your engineers can execute, a readout, and a refund guarantee, with no software purchase required.

How much will we save?

It depends on your estate, so we do not promise a percentage. What we do promise is in writing: if the audit identifies less than three times its fee in annual savings, you get the fee back. Every finding shows its own monthly and annual estimate, so you can decide what is worth doing.

How is this different from AWS Cost Explorer, Trusted Advisor or Google's recommendations?

Those tools show symptoms one service at a time. We look across every account, price each finding against your own usage, remove the ones that are not safe to act on, and write up the fix. You also get a person to ask.

Do you make changes in our accounts?

No. Our access is read-only and cannot change anything. Fixes are delivered as Terraform changes, runbooks or tickets that your team reviews and applies. On the Plus package we work alongside your engineers while they do it.

What do you need from our team?

An engineer who can deploy a CloudFormation stack on AWS or run a script in Google Cloud Shell, for about 30 minutes. On AWS, Cost Explorer must be switched on at least a day before, because AWS takes up to 24 hours to activate it. Then about an hour for the readout.

What counts as an account or project?

One AWS account or one Google Cloud project. If you have more than the package allows, choose the next package up or book a call for a quote.

Our security team reviews every vendor. What can you send them?

Before you deploy anything we send the exact IAM policy, the trust policy and our security FAQ. One point we disclose up front: the AWS role can read Lambda function configuration, which includes environment variables, so keep secrets in Secrets Manager or Parameter Store. Our SOC 2 program is in progress.

Do you cover Kubernetes?

For EKS and GKE we review node pools, instance choices and commitments; we do not report cost per pod. Azure is not covered today.

We do not use Terraform. Is the fix plan still useful?

Yes. Every top fix comes with console or CLI steps, the expected saving and how to roll it back. Terraform changes are included where you manage the resource with Terraform.

What happens after the audit?

Your team ships the fixes, with our email follow-up. If you want help keeping costs down month to month, the audit fee is credited in full to FinOps-as-a-Service if you start within 60 days. Many teams also add Commitment Management.

How do we pay?

By card through a secure Stripe checkout, or by invoice if you need a purchase order. The fee is fixed and agreed before any work starts.

Ready to start?

Pick a package above, or book a free 30-minute call and we will tell you which one fits, or whether you need one at all. From $1,500, one-time fee.