reCost.io delivers object-level threat detection and access intelligence for Amazon S3. Agentless and read-only, it reveals every identity, AI agent, and MCP client reading your data. The platform detects unusual identities, dormant data becoming active, abnormal reads and writes, denied-access patterns, credential misuse, and direct activity from AI agents, crawlers, and automated tools. reCost analyzes metadata and behavior only, never object contents, and forwards high-signal findings into your existing security stack.
When an identity, an AI agent, or a stolen credential calls the Amazon S3 API directly, the request never crosses a workload. There is no process to instrument and no network path to inspect. Runtime and posture tools have nothing to observe. The only evidence is the S3 server access log, and most organizations never ingest those logs because the volume makes SIEM ingestion uneconomical. The result is an entire access layer that goes unmonitored.
reCost.io turns those logs into a queryable, object-level record of who and what read, listed, wrote, or deleted every object, and when. Every request is attributed to an IAM identity and user agent through assume-role chains. Each identity is baselined so that deviations in volume, operation mix, timing, and assets touched become findings rather than noise. The record supports investigation years after the fact: supply an object key or a date and receive the complete access history.
The platform is built for the agentic era. reCost.io identifies AI agents, MCP clients, and external crawlers touching your storage, including the read-only and consent flags they actually operated with. It surfaces agents performing writes where they were assumed read-only, roles declared read-only attempting to copy or delete, and the true consumer behind a presigned URL when the signing role masks the reader.
Detections span destructive and evasive behavior that only appears in access logs: encryption-based ransomware patterns, bulk deletions and delete-marker floods, lifecycle rules scheduling silent data deletion, versioning or object-lock changes that remove recovery, logging configuration changes, and denied writes from AWS logging services that quietly break log integrity. It also covers enumerate-then-retrieve sequences, dormant prefixes suddenly read, cross-account and cross-region copies, anonymous requests, end-of-life SDKs with known CVEs, and direct object reads that bypass Iceberg, Delta Lake, or Hudi catalogs.
Deployment takes under an hour with a scoped read-only role. No agents, no per-bucket connectors, no code changes, no CloudTrail data-event costs, and object contents are never read. Curated findings route into your existing SIEM, SOC, or ticketing workflow while billions of log lines remain in your own account. reCost.io operates at hundreds of billions of objects and roughly 100 billion requests per month, with retention long enough to support audit and investigation.
Highlights
Sees what workload tools cannot. Direct-to-storage access never crosses a workload, so runtime and posture tools have nothing to observe. The evidence exists only in S3 access logs, which most teams never ingest because SIEM volume pricing makes it uneconomical. reCost.io processes 100 percent of them, with no sampling.
Built for AI agents and MCP. Attributes every AI agent, MCP client, and external crawler touching your storage, including the read-only and consent flags they actually ran with. Detects agents writing where they were assumed read-only, and identifies the true consumer behind presigned URLs when the signing role masks the reader.
Agentless, read-only, and metadata only. Deploys in under an hour with a scoped read-only role. No agents, no per-bucket connectors, no code changes. Object contents are never read. Curated findings flow into your existing SIEM or ticketing system while the full log volume stays in your own account.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing uses contract pricing based on the volume of Amazon S3 data you monitor. You choose one of three tiers by total storage size. Startup covers up to 500 TB. Business covers 501 TB to 2 PB. Enterprise covers more than 2 PB. The tiers work as brackets, so you pick the one matching your object storage footprint. Pricing scales as your monitored data volume grows. All tiers deliver the same threat detection capability for Amazon S3, differing only by the amount of data covered.
Top-of-mind questions for buyers
What counts toward the storage volume that sets my pricing tier?
Your tier is set by the total Amazon S3 data monitored, measured in TB or PB. Startup covers up to 500 TB. Business covers 501 TB to 2 PB. Enterprise covers more than 2 PB. You pick the bracket matching your object storage footprint.
What happens to my cost if my monitored S3 data grows past my tier limit?
The tiers work as brackets by total storage size. If your monitored data grows past your current bracket, you move to the tier covering that volume. For example, crossing 500 TB moves you into the Business range. Contact the vendor to confirm how transitions are handled.
What does this product actually do with my S3 data at each tier?
All tiers connect read-only to your S3 activity and audit telemetry. The product records who accessed what, when, and how, ties each event to an identity or workload, learns normal behavior, and flags deviations. It stays searchable for investigations and compliance. Tiers differ only by data volume covered.
www.trailox.io
Helpful?
Vendor refund policy
reCost.io does not offer refunds. However, we provide a 3-week free trial so customers can evaluate the platform before committing to an annual subscription. If you have any questions or need assistance, please contact us at support@recost.io.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Customers receive email support with response times under 24 hours. Our team assists with onboarding, IAM role configuration, log source validation, detection tuning, and SIEM or ticketing integration. Enterprise customers receive priority support, including direct access to our engineering team for investigation assistance and custom detection development. Documentation and onboarding guides are available through our support portal.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Industry experts recommend storing 3 copies of your data, on 2 types of media, with 1 offsite. This is often referred to as the 3-2-1 strategy.
Two different types of media are important, as the factors that can lead to hardware failure can affect all media types.
An offsite backup is important, as an event such as a natural disaster or unauthorized intrusion can affect all resources at that site.
With speed-to-market for your application always paramount in creating a competitive advantage, it must not come at the expense of stability. An unreliable application is a tremendous risk to your revenue and your reputation. InfoObjects Cloud Security Architects are standing by to support your rapid drive to production on the AWS Cloud while still delivering a reliable Product.
CostPulse watches your AWS spend and alerts your team in Slack, Microsoft Teams, or email when any service spikes above its baseline - before the invoice arrives. Read-only, no agents.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.