Overview
When an identity, an AI agent, or a stolen credential calls the Amazon S3 API directly, the request never crosses a workload. There is no process to instrument and no network path to inspect. Runtime and posture tools have nothing to observe. The only evidence is the S3 server access log, and most organizations never ingest those logs because the volume makes SIEM ingestion uneconomical. The result is an entire access layer that goes unmonitored.
reCost.io turns those logs into a queryable, object-level record of who and what read, listed, wrote, or deleted every object, and when. Every request is attributed to an IAM identity and user agent through assume-role chains. Each identity is baselined so that deviations in volume, operation mix, timing, and assets touched become findings rather than noise. The record supports investigation years after the fact: supply an object key or a date and receive the complete access history.
The platform is built for the agentic era. reCost.io identifies AI agents, MCP clients, and external crawlers touching your storage, including the read-only and consent flags they actually operated with. It surfaces agents performing writes where they were assumed read-only, roles declared read-only attempting to copy or delete, and the true consumer behind a presigned URL when the signing role masks the reader.
Detections span destructive and evasive behavior that only appears in access logs: encryption-based ransomware patterns, bulk deletions and delete-marker floods, lifecycle rules scheduling silent data deletion, versioning or object-lock changes that remove recovery, logging configuration changes, and denied writes from AWS logging services that quietly break log integrity. It also covers enumerate-then-retrieve sequences, dormant prefixes suddenly read, cross-account and cross-region copies, anonymous requests, end-of-life SDKs with known CVEs, and direct object reads that bypass Iceberg, Delta Lake, or Hudi catalogs.
Deployment takes under an hour with a scoped read-only role. No agents, no per-bucket connectors, no code changes, no CloudTrail data-event costs, and object contents are never read. Curated findings route into your existing SIEM, SOC, or ticketing workflow while billions of log lines remain in your own account. reCost.io operates at hundreds of billions of objects and roughly 100 billion requests per month, with retention long enough to support audit and investigation.
Highlights
- Sees what workload tools cannot. Direct-to-storage access never crosses a workload, so runtime and posture tools have nothing to observe. The evidence exists only in S3 access logs, which most teams never ingest because SIEM volume pricing makes it uneconomical. reCost.io processes 100 percent of them, with no sampling.
- Built for AI agents and MCP. Attributes every AI agent, MCP client, and external crawler touching your storage, including the read-only and consent flags they actually ran with. Detects agents writing where they were assumed read-only, and identifies the true consumer behind presigned URLs when the signing role masks the reader.
- Agentless, read-only, and metadata only. Deploys in under an hour with a scoped read-only role. No agents, no per-bucket connectors, no code changes. Object contents are never read. Curated findings flow into your existing SIEM or ticketing system while the full log volume stays in your own account.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
Startup | Up to 500 TB | $5,000.00 |
Business | 501 TB to 2 PB | $18,000.00 |
Enterprise | 2+ PB | $60,000.00 |
Vendor refund policy
reCost.io does not offer refunds. However, we provide a 3-week free trial so customers can evaluate the platform before committing to an annual subscription. If you have any questions or need assistance, please contact us at support@recost.io .
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
Support Email: support@recost.io
Customers receive email support with response times under 24 hours. Our team assists with onboarding, IAM role configuration, log source validation, detection tuning, and SIEM or ticketing integration. Enterprise customers receive priority support, including direct access to our engineering team for investigation assistance and custom detection development. Documentation and onboarding guides are available through our support portal.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.