reCost.io delivers object-level threat detection and access intelligence for Amazon S3. Agentless and read-only, it reveals every identity, AI agent, and MCP client reading your data. The platform detects unusual identities, dormant data becoming active, abnormal reads and writes, denied-access patterns, credential misuse, and direct activity from AI agents, crawlers, and automated tools. reCost analyzes metadata and behavior only, never object contents, and forwards high-signal findings into your existing security stack.
When an identity, an AI agent, or a stolen credential calls the Amazon S3 API directly, the request never crosses a workload. There is no process to instrument and no network path to inspect. Runtime and posture tools have nothing to observe. The only evidence is the S3 server access log, and most organizations never ingest those logs because the volume makes SIEM ingestion uneconomical. The result is an entire access layer that goes unmonitored.
reCost.io turns those logs into a queryable, object-level record of who and what read, listed, wrote, or deleted every object, and when. Every request is attributed to an IAM identity and user agent through assume-role chains. Each identity is baselined so that deviations in volume, operation mix, timing, and assets touched become findings rather than noise. The record supports investigation years after the fact: supply an object key or a date and receive the complete access history.
The platform is built for the agentic era. reCost.io identifies AI agents, MCP clients, and external crawlers touching your storage, including the read-only and consent flags they actually operated with. It surfaces agents performing writes where they were assumed read-only, roles declared read-only attempting to copy or delete, and the true consumer behind a presigned URL when the signing role masks the reader.
Detections span destructive and evasive behavior that only appears in access logs: encryption-based ransomware patterns, bulk deletions and delete-marker floods, lifecycle rules scheduling silent data deletion, versioning or object-lock changes that remove recovery, logging configuration changes, and denied writes from AWS logging services that quietly break log integrity. It also covers enumerate-then-retrieve sequences, dormant prefixes suddenly read, cross-account and cross-region copies, anonymous requests, end-of-life SDKs with known CVEs, and direct object reads that bypass Iceberg, Delta Lake, or Hudi catalogs.
Deployment takes under an hour with a scoped read-only role. No agents, no per-bucket connectors, no code changes, no CloudTrail data-event costs, and object contents are never read. Curated findings route into your existing SIEM, SOC, or ticketing workflow while billions of log lines remain in your own account. reCost.io operates at hundreds of billions of objects and roughly 100 billion requests per month, with retention long enough to support audit and investigation.
Highlights
Sees what workload tools cannot. Direct-to-storage access never crosses a workload, so runtime and posture tools have nothing to observe. The evidence exists only in S3 access logs, which most teams never ingest because SIEM volume pricing makes it uneconomical. reCost.io processes 100 percent of them, with no sampling.
Built for AI agents and MCP. Attributes every AI agent, MCP client, and external crawler touching your storage, including the read-only and consent flags they actually ran with. Detects agents writing where they were assumed read-only, and identifies the true consumer behind presigned URLs when the signing role masks the reader.
Agentless, read-only, and metadata only. Deploys in under an hour with a scoped read-only role. No agents, no per-bucket connectors, no code changes. Object contents are never read. Curated findings flow into your existing SIEM or ticketing system while the full log volume stays in your own account.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This contract prices by the volume of Amazon S3 data you protect. The three tiers scale with your storage footprint. Startup covers up to 500 TB. Business covers 501 TB to 2 PB. Enterprise covers more than 2 PB. You pick the tier that matches your total S3 data size. As your storage grows past a tier's ceiling, you move to the next tier. The tiers are size brackets, not separate products. The same threat-detection service applies across all three; only the covered data volume changes.
Top-of-mind questions for buyers
How is my S3 data volume measured to place me in a pricing tier?
Your tier reflects the total volume of S3 data reCost analyzes. It reads your S3 access logs and inventory through a read-only IAM role. It never reads object contents. Startup covers up to 500 TB, Business covers 501 TB to 2 PB, and Enterprise covers 2+ PB.
What happens to my cost if my S3 storage grows past my tier's ceiling?
You move to the next tier when your data volume crosses the bracket boundary. Startup ends at 500 TB, then Business runs from 501 TB to 2 PB, then Enterprise applies above 2 PB. The service stays the same; only the covered volume bracket changes.
Does the tier price cover all three product views, or do I pay separately for each?
One tier covers the whole platform. All detection runs on a single data source: your S3 access logs and S3 Inventory. That includes data lake observability, S3 access monitoring, and threat detection. There are no separate charges per view; only your covered data volume sets the tier.
www.recost.io+1
Helpful?
Vendor refund policy
reCost.io does not offer refunds. However, we provide a 3-week free trial so customers can evaluate the platform before committing to an annual subscription. If you have any questions or need assistance, please contact us at support@recost.io.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Customers receive email support with response times under 24 hours. Our team assists with onboarding, IAM role configuration, log source validation, detection tuning, and SIEM or ticketing integration. Enterprise customers receive priority support, including direct access to our engineering team for investigation assistance and custom detection development. Documentation and onboarding guides are available through our support portal.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.