Arc-Guard enforces hard spending caps on AWS (EC2 and ECS today — GCP and Azure coming). When you hit your limit, we suspend the resources you've tagged as sacrificial, not just send you an email that arrives 8 hours too late.
It won't prevent the first dollar of a spike, but it will stop a runaway process from billing your account for hours while you sleep.
Suspends what you tag as sacrificial. In-prod blowups (recursive Lambda, runaway egress) are out of scope for now.
Founder rate · No credit card · No spam
Every month, a dev wakes up to "Ask HN: I got a $47k AWS bill overnight, what do I do?" AWS sent an alert. It arrived 18 hours later.
Alert delay
AWS Cost Anomaly Detection sends an email hours after the spike. By then, the damage is done.
Native hard caps
AWS, GCP, and Azure have no built-in spending cap, only soft budget alerts you can't enforce.
Cheapest that enforces caps
CloudThrottle starts at $600/mo. Built for governments, not your side project running on a $20 budget.
The suspend switch never runs on our servers. Here's exactly what happens when Arc-Guard fires.
Deploy a single Docker container in your own cloud account. It runs there, with your credentials, and never phones home with sensitive data.
Arc-Guard only holds read access on your billing API. It sees spend numbers, nothing else. No write permissions, no access to your workloads.
The suspend-switch agent is fully open source. Audit every line before deploying. Trust the code, not our word.
Run the Arc-Guard Docker container in your own cloud account and create a read-only billing IAM role. Takes 10–15 minutes; no root credentials needed.
Define a monthly spending limit: $20, $50, whatever your threshold is. Per project, per service, or per account.
Arc-Guard polls your spend on a schedule: every 15 min on Free, every 5 on Builder, every minute on Hacker. If your cap is hit, we suspend the resources you tagged as sacrificial and notify you instantly.
Vantage gives you dashboards. CloudZero charges $10k/yr. The tools that actually act are SaaS that take your keys. Arc-Guard runs in your own account, and you audit it before it touches anything.
When you hit your cap, Arc-Guard suspends the resources you've tagged as sacrificial. An action, not a reminder—and reversible once you're back in control.
See exactly which resources would be suspended before Arc-Guard takes any action. Validate your rules without touching anything.
Alerts at 80% of your cap, and again at the moment of suspension. Get notified wherever you actually are.
Free checks every 15 min, Builder every 5, Hacker every minute. Not once per day like native AWS Cost Anomaly Detection.
Arc-Guard only suspends what you explicitly tag as sacrificial (batch, dev/staging, nightly jobs). Everything else is protected by default and never touched. Your prod stays up because it's never in scope unless you say so.
Uses least-privilege IAM roles. We publish the exact policy, you audit it before connecting. Your keys stay yours.
One click in the dashboard. The agent receives the signal and stops the instance on AWS. In seconds.
All plans include the suspend switch. No surprise charges. Cancel anytime.
Building now. Be among the first to get access when it launches.
Building now. Early access coming.