Frequently asked questions
Access and security
What exactly can you see in our account?+
Cost Explorer figures, resource configuration metadata such as instance types, volume sizes and lifecycle policies, and CloudWatch utilisation metrics. The role has no write access at all and cannot read the data plane, so no S3 object contents, no database rows and no secrets. The full policy JSON is on the security page.
Why a cross-account role instead of access keys?+
Keys are long-lived credentials and long-lived credentials leak. A cross-account role with an ExternalId gives us temporary, auditable, scoped sessions that you revoke by deleting the role. It is the pattern AWS recommends for third-party access.
How do we revoke access?+
Delete the FramzCostAudit CloudFormation stack, or the IAM role directly. Access ends the moment you do.
How long do you keep our data?+
Findings are encrypted at rest and deleted 90 days after your audit closes, or 90 days after the scan if you never buy the audit. Retainer clients keep their history for as long as they subscribe.
The scan and the audit
What is the difference between the free scan and the £499 audit?+
The scan is automated. It gives you the estimated total, the counts per category, and one complete finding from your account. The audit adds a person checking every finding, the judgement calls automation cannot make such as Spot suitability, scheduling and architectural changes, exact pricing, and a written report your team can work through.
How accurate is the estimated saving?+
It is deliberately low. Idle resources count at 100% of their cost, a gp2 to gp3 move at 20%, rightsizing uses AWS Compute Optimizer's own figures, and anything we cannot price counts as zero. On our own scan, 66 of 105 findings came back unpriced for that reason. The guarantee is judged against the conservative total rather than a best case.
Which regions and services are covered?+
Every region with spend in your account. Coverage includes EC2, EBS, S3, RDS, DynamoDB, ElastiCache, OpenSearch, Redshift, Lambda, ECS and EKS, CloudWatch, CloudTrail, Config, EFS, ECR, SageMaker, WorkSpaces, Kinesis, Route 53, Secrets Manager, KMS and Backup.
Do you support GCP or Azure?+
No, AWS only. We would rather cover one platform properly than three badly.
Can I see what the output looks like before signing up?+
Yes. The complete scan of our own AWS account is published on the demo page, with every finding and its evidence. It came in at 3.4%, under our own guarantee threshold, and it is on the site anyway.
Commercials
How does payment work?+
£249.50 by bank transfer after the kick-off call and the same again on delivery. The free scan needs no card. VAT invoices provided.
What does the guarantee exclude?+
Nothing hidden. If the report's conservative total comes in below both 20% of your monthly spend and £499 a month, the audit is free. The free scan exists to catch that before anyone spends money, and when we ran it on ourselves it did exactly that.
What is the £149 a month retainer?+
The audit checks re-run monthly, an alert when costs regress or new waste appears, and a review call each quarter. Set up after the audit and cancellable whenever.
Who you are dealing with
We are aware that a website asking about your AWS account, with no name attached to it, looks exactly like the thing your security training told you to close. So here are the details you would need to check us out, and the two pages that let you judge the work before you talk to anyone.
The company
- Registered name
- Framz Limited
- Incorporated
- Registered in England and Wales, 2024
- Registered office
- 1 Glamorgan Close, Mitcham, CR4 1XG, United Kingdom
How to reach us
- hello@framz.io
- Phone
- +44 7774 856956
- linkedin.com/company/framz-io
- Parent site
- framz.io
Judge the work first
Neither of these asks you for anything.
- A complete scan of our own account
Every finding, including the total that fell short of our own guarantee.
- The exact IAM policy we ask for
Published in full, so your engineers can reject it on the merits.
We have no client testimonials on this site because we have not finished a paid audit yet. When that changes we will put the names here with permission. Until then the scan of our own account is the only evidence we have, so it is the evidence we show.