Early Bird Offer !Pay Just 10%Get full Cloud Lens AI access for a limited timeClaim Now
Home/Case Studies/Eliminating NAT Gateway Data Processing Charges Using AWS PrivateLink for Amazon S3 Access (Hybrid SaaS Architecture)
SaaS · AWS

Eliminating NAT Gateway Data Processing Charges Using AWS PrivateLink for Amazon S3 Access (Hybrid SaaS Architecture)

HS
Hybrid SaaS Platform
SaaS platform · 120 employees · Multi-AZ AWS
Eliminating NAT Gateway Data Processing Charges Using AWS PrivateLink for Amazon S3 Access (Hybrid SaaS Architecture)
95%
spend reduced
$500–700
Monthly savings identified
74 → 94
Security score improvement
< 5 min
From upload to full report

A SaaS company hosted its application in private subnets across multiple Availability Zones. The application servers communicated with several AWS managed services including Amazon S3 for document storage, AWS Secrets Manager, AWS Systems Manager Parameter Store, Amazon ECR, and AWS KMS. Since all EC2 instances resided in private subnets, outbound traffic to AWS services traversed a NAT Gateway.

Data Flow Before AWS PrivateLink

   1. EC2 (Private Subnet)
               ↓
    2. Private Route Table
               ↓
        3. NAT Gateway
               ↓
     4. Internet Gateway
               ↓
5. Public AWS Service Endpoint

Although the traffic never left the AWS backbone, every request to Secrets Manager, Parameter Store, ECR APIs, and KMS incurred NAT Gateway data processing charges ($0.045/GB in many regions), along with hourly NAT Gateway charges. The application transferred nearly 12 TB of management and API traffic every month, resulting in significant recurring costs.

Solution

The architecture was redesigned using Interface VPC Endpoints (AWS PrivateLink) for:

  • AWS Secrets Manager
  • AWS Systems Manager
  • Amazon ECR API
  • Amazon ECR DKR
  • AWS KMS

Additionally, an S3 Gateway Endpoint was configured for Amazon S3 access.

Data Flow After AWS PrivateLink

             1. EC2
                ↓
2. Interface Endpoint (Private IP)
                ↓
     3. AWS Private Backbone
                ↓
     4. AWS Managed Service

No NAT Gateway or Internet Gateway was involved.

Outcome

  • Approximately 11.5 TB/month of traffic bypassed the NAT Gateway.
  • NAT Gateway data processing charges were reduced by nearly 95%.
  • Overall networking costs declined by approximately $500–700 per month, depending on regional pricing.
  • Security improved because no public endpoints were accessed.
  • IAM policies could enforce endpoint-specific access using aws:SourceVpce.
  • Compliance teams appreciated that all communication remained entirely within the VPC and AWS private network.

The organization retained NAT Gateways only for genuine internet-bound traffic such as operating system updates and third-party APIs, while all AWS service communication moved to private endpoints, significantly reducing recurring operational costs.

Cost Assessment
Parses AWS Cost and Usage Reports to attribute every dollar to a service, environment, and owning team, then ranks recoverable spend by dollar impact and implementation effort.
Security Posture Score
Evaluates configuration and exposure signals across accounts to produce a single comparable score, highlighting findings where cost risk and security risk overlap.
Board-Ready Reporting
Generates a narrative assessment with an executive summary, trend context, and prioritised recommendations, formatted for finance and leadership audiences, not engineers.
Privacy-First Architecture
Works from billing exports alone. No agents, no cross-account roles, and no access to production workloads or customer data at any point in the assessment.

Key outcomes

  • 95% reduction in targeted AWS processing spend within weeks of deployment.
  • Clear visibility into VPC endpoint and data transfer costs without requiring agents.
  • Security score improved by retiring exposed and unmonitored egress routes.
  • Board-ready reporting turnaround reduced to minutes with automated exports.

Cloud Lens AI didn't just find the savings, it settled the argument. For the first time, engineering and finance were looking at the same number and agreeing on what to do about it.

Cloud Architecture Leadership
#SaaS#AWS#CloudCost#FinOps#CaseStudy

More case studies

See what your bill is hiding

Upload your AWS bills and get a board-ready cost and security assessment in minutes.

Get Started