Nuberio Audit · Free AWS Health Check
No alarm means you find out from a customer, not from CloudWatch.
The free Nuberio Audit scans 18 AWS services in parallel, classifies every alarm as GOOD, NOISY, or SUPPRESSED-BAD, and surfaces missing coverage with copy-pasteable CLI to fix each gap. Under 5 minutes.
Read-only if connected · Zero access if local · 5-minute scan · No credit card · what we check ↓
Three steps, five minutes
Enter your email
We send the report here when the scan finishes. No account required.
Deploy a read-only IAM role
One CloudFormation click. Pre-filled template. The role can only read — never write.
Get your report
Score, top fixes, missing alarms with CLI commands. Yours to keep for 30 days.
Step 2 is optional — prefer not to grant AWS access at all? Run a local script instead, paste the output →
See it run.
What the audit checks
18 AWS services, parallel scanning, results in under 5 minutes.
Alarm classification
Every alarm scored GOOD, NOISY, or SUPPRESSED-BAD with specific reasons.
Missing coverage
18 services cross-referenced — missing criticals surfaced with copy-pasteable CLI.
Unmonitored resources
Resources with zero alarms attached, with production gaps flagged first.
Security findings
Active GuardDuty and Security Hub findings with severity context.
Quota warnings
Service limits over 75% surfaced before they cause a hard cap mid-incident.
Hygiene score
Single 0–100 score weighted by severity and environment — comparable across accounts.
Coverage scope
Every resource type scanned and the exact CloudWatch metrics checked for each.
⚠ Memory and disk usage require the CloudWatch Agent installed on the instance — not covered by the metrics above
⚠ Requires S3 request metrics enabled per bucket (FilterId: EntireBucket)
⚠ Requires CloudWatch Container Insights enabled on the cluster
⚠ gp2 volumes only — gp3 does not emit BurstBalance
⚠ Requires 'Receive Billing Alerts' enabled in AWS Billing preferences
Security & compliance
Sample output
This is a real, live audit — not a mockup.
Needs attention
Priority fix #1
Fix 5 noisy alarms
+10 ptsNoisy alarms cause alert fatigue and mask real incidents — fix evaluation periods, thresholds, and TreatMissingData settings.
--alarm-name "convops-baseline-builder-errors" \
--metric-name Errors ...
Common questions about the audit.
Answers about permissions, scan time, data handling, and what happens after you get your report.
What comes next
The audit gives you a one-time snapshot. Here's how to keep it useful.
Ready to see your score?
5 minutes. No account, no credit card. Just your email and one CloudFormation click.
Read-only IAM role · No writes · Cancel any time
From the blog
Further reading
The 12 CloudWatch alarms every small AWS team should have →
A curated list of the alarms that catch real incidents — with exact thresholds, a CloudFormation template, and the decision rules that separate signal from noise.
The 5 CloudWatch alarms most startups accidentally create that are just noise →
The alarm configurations that look correct in documentation but page your team 40 times a month for nothing — and the exact fixes.
The Complete AWS CloudWatch Alarm Setup Guide →
Every CloudWatch alarm your AWS infrastructure needs — ECS, EC2, RDS, Lambda, ALB, API Gateway, SQS, DynamoDB, ElastiCache, and cost alerts.