Skip to content
Blocks

Blocks FAQ

General

How is Blocks free?

We take a cut of what we save you, not what you spend. The 5% group buying discount passes to you in full. On savings plans we take 25% of what we save you. On one-off optimisations we take the first month of the saving, then it is all yours. Major Tom and security findings are free.

What services does Blocks optimize?

Most of what matters: EC2, ECS, EKS, Fargate, Lambda, RDS, ElastiCache, DynamoDB… we optimize more services than anyone else.

Not included are Marketplace purchases, AWS support, Bedrock and taxes. Everything else AWS native is eligible.

How does group buying work?

Big tech negotiates massive AWS discounts. Startups cannot… unless they team up. We consolidate cloud spend across Blocks members to unlock enterprise level rates.

What if we want to cancel Blocks?

There's no lock-in with Blocks. You can switch back to AWS invoicing anytime. We built Blocks the way we wished it existed at our previous startups: win you over with a better product, not with minimum contract terms.

You withdraw the billing transfer in your own console and invoicing returns to AWS on your old billing details.

Savings plans sit in your account and legally belong to you, so you keep the discounted rate for the rest of their term. Where we can, we take them back.

Is there a minimum or maximum AWS spend?

We work with teams spending €1,000 per month and up, with no upper limit on your total spend. The one threshold that matters is per account: under roughly $50,000 a month, the standard discount applies. Above that AWS requires a private pricing agreement, which we can set up through us.

What access do you need?

We use IAM roles to optimize costs. You can review permissions before granting access. No access to your code and data. You stay in control. We stay invisible and deliver savings every month.

Deployment takes under a minute, in your management account, in us-east-1, by someone with admin access.

Everything is read-only except one narrow permission to buy savings plans for you. Our templates are public on GitHub, so your team can read exactly what gets created before anything runs.

What is the impact on my AWS setup?

Zero. We do not touch your infrastructure. Only the invoice will now come from Blocks instead of AWS. We cannot deploy, stop, start, modify, or delete any resources without your approval.

Do you support GCP or Azure?

Coming soon. Right now, we are focused on AWS, where the savings are biggest. GCP and Azure will follow next year.

Setup & savings

How much will we actually save?

We average 27% across our members. About 13 to 15% is automatic: group buying plus the commitments we manage for you. The rest comes from the fixes Major Tom finds, so that part depends on your team acting on them. You see your own number before you commit to anything.

Can I see my potential savings before joining?

Yes. We will send you a private link showing how much you could save and where those savings would come from.

Does our AWS account move under your organisation?

No. Your organisation stays standalone. We never take root access and never pull your account into ours. Most resellers put you underneath their root organisation, which is what makes leaving them hard.

Is AWS okay with this?

Yes. AWS loves Blocks. We are an official AWS partner with Cloud Financial Operations Competency. You can verify us on the AWS website.

Can this cover only some of our accounts?

No. It works at the organisation level, covering the management account and every member account. Single accounts need to become an AWS organisation first.

For agencies this is usually an advantage: the discount applies across every client account and you re-bill as you like.

Do we sign with AWS or with Blocks, and will we get two invoices?

You stay with AWS. Your accounts, setup and support tier are unchanged, and your AWS account manager stays your first point of contact.

You will not get the AWS invoice anymore: AWS bills us, and you get one Blocks invoice instead. Same structure, much easier to read.

Who carries the risk if we end up overcommitted?

We do. We size commitments conservatively and recheck them daily. If a commitment ever means you paid more than on-demand would have cost, we credit you the difference. The risk is spread across our whole member base, and it applies for as long as you are a customer.

What if we already have a private pricing agreement with AWS?

Then we find a joint solution with you. Discounts cannot stack, so the usual route is a reseller private pricing agreement through us instead. We work it out with you and your AWS account manager before anything changes.

Are the savings you show us before or after your fee?

Before. Every estimate is gross of our success fee, so your net saving is a little lower. Ask us and we will walk the net number with you line by line.

Terms, security & data

What are we actually signing?

Click-through terms on our website. Month to month, 30 days' notice, no negotiated contract in the standard case. You cancel it yourself in your own console. There is nothing for us to approve.

Who owns the savings plans you buy?

You do. They are bought in your own account, visible in your own console, held directly with AWS. We buy them under the mandate you give us at onboarding, which is what makes the savings automatic. If one ever costs you more than on-demand would have, we credit you the difference.

Do you have ISO 27001 or SOC 2?

ISO 27001 is in progress and we expect it within a couple of months. SOC 2 has not started. We would rather tell you where we are than imply more than we hold.

What is concrete today: read-only access, a deny policy enforced by AWS, roles you review before granting, public templates, GDPR compliance and a data processing agreement.

What can you actually see, and how is that enforced?

Cost and usage data, your resource inventory and metadata, and CloudWatch metrics. We cannot see inside your resources: no file contents, no databases, no secrets, no code.

That is an explicit deny policy at the AWS permission level, so it holds even where AWS would otherwise allow it. Read it yourself, or paste it into Claude and ask.

Where is our data processed, and do you train models on it?

Your cost and billing data is processed in the EU. The model layer and Major Tom's conversation store are US based, covered by EU standard contractual clauses, and no cost or billing data goes to either.

We do not train models on your data. We do use anonymised resource and spend data to spot patterns across our members, which is how a fix that works for one becomes a finding for another. No personal data, and it is set out in our terms.

What happens if Blocks goes out of business?

Billing defaults back to AWS. Your account never left your organisation and your savings plans sit in your own account, so the failure mode is a billing reversion, not a loss of infrastructure or commitments. Any outstanding balance between us and AWS is chased against Blocks, not against you.

Major Tom

What can Major Tom actually do?

Three things: he cuts your AWS cost, catches security risks, and answers questions about your cloud.

How does Major Tom cut my AWS bill?

He scans every resource and together with you gets rid of inefficiencies like idle instances, orphaned storage, and oversized databases. He automatically optimizes your commitments around savings plans to get the maximum discounts. Group buying does the rest, pooling spend across members to unlock enterprise rates. Together, we guarantee at least 20% off your AWS spend.

What does Major Tom cost?

Major Tom is free for Blocks members. He isn't available as a standalone product right now.

Can I just ask Major Tom a question?

Yes. Ask in plain English in Slack and Major Tom pulls live metrics, logs, costs, and configs from across your accounts and answers in seconds. No dashboards to dig through.

Do we need Slack?

No. Slack is just where the conversation happens, because that is where your team already works. Everything is visible and actionable in the dashboard without it. There is also a Model Context Protocol server in beta if you want Major Tom inside your own environment.

Does Major Tom handle security too?

Yes. He continuously checks for public buckets, open ports, risky IAM, misconfigurations and the attack paths between them, and focuses on the most relevant issues first, so you fix what matters.

Is it safe to let Major Tom into my account?

Yes. Major Tom is read-only, so he can see your cloud but never change any of your infrastructure. When he isn't sure about something, he tells you instead of guessing. And your data stays fully isolated from every other customer's.

What can Major Tom change on his own?

Nothing. Major Tom is read-only and always keeps a human in the loop. He proposes, you decide. Nothing happens in your account without your say-so.

What permissions does Major Tom need?

A read-only IAM role, granted in 1 click. You can review the exact permission set on our GitHub page before you grant anything.

Can I see everything Major Tom has done?

Yes. Blocks keeps detailed journals of every reasoning step and action Major Tom takes, so you get full transparency into how he reached a decision. Every action is also recorded in your AWS CloudTrail.

How is Major Tom different from AWS's own agents?

Three things. Major Tom connects to your Slack in one click, with no project to set up. He's built for startups and the problems they actually hit. And he's free for Blocks members.

Which model runs Major Tom?

The best available Anthropic Claude model, with our own memory, context and playbooks on top. We are not building our own model. We are making the best one better for this job.