DoControl
A New York-based SaaS data access governance platform, backed in part by CrowdStrike's Falcon Fund, that automates discovery and remediation of overexposed files and access across Google Drive, Salesforce, Slack, GitHub, and other SaaS apps.
Visit Website ↗ + Add to CompareOverview
DoControl automates the discovery, monitoring, and remediation of data access across an organization’s SaaS applications — Google Drive, Box, Microsoft OneDrive, Salesforce, Slack, Jira, BambooHR, GitHub, and similar tools. The core problem it targets is SaaS data sprawl: files and records shared too broadly, stale third-party app permissions, and overprivileged access that traditional network-centric security tools and generic CASB products don’t reliably catch or auto-remediate.
Founded in 2020 and headquartered in New York, DoControl raised $13.35 million across its earliest rounds before closing a $30 million Series B in 2022 led by Insight Partners, with participation from CrowdStrike’s early-stage investment arm, the CrowdStrike Falcon Fund. That strategic backing turned into a real product integration: DoControl’s application is listed in the CrowdStrike Store, where it ingests Falcon endpoint telemetry to cross-reference CrowdStrike detections against the same files sitting in corporate SaaS applications, enabling automated remediation when a flagged file shows up somewhere it shouldn’t.
The CrowdStrike ecosystem tie-in is a genuine differentiator versus SaaS security posture management (SSPM) tools that operate purely on their own telemetry, giving DoControl a credible technical hook beyond typical vendor messaging. Independent, third-party efficacy testing of its detection and remediation accuracy is still limited, but the combination of institutional and strategic cybersecurity-vendor investment is a meaningful signal in a still-maturing SaaS security subcategory.
Innovation Matrix Assessment
Moved from a $13.35M early raise to a $30M Series B within about a year and shipped a live CrowdStrike Store integration, a meaningfully fast product and go-to-market cadence for the stage.
Automates discovery, monitoring, and remediation across a wide range of major SaaS platforms (Google Drive, Salesforce, Slack, GitHub, and more), a real operational capability, though independent data on remediation scale or accuracy is limited.
Strategic investment and a product integration from CrowdStrike's Falcon Fund is a credible momentum signal beyond the capital raised, reflecting validation from an established cybersecurity vendor rather than financial investors alone.
SaaS data access governance addresses a gap that traditional network-centric DLP and CASB tools handle poorly, representing a real, if incremental, shift in how data exposure risk is managed.
No independent third-party efficacy testing was found; claims about detection and remediation effectiveness come from the company and its investors' own press materials.
SaaS data sprawl and overprivileged file sharing are increasingly cited enterprise risks as organizations spread sensitive data across dozens of cloud collaboration tools.
Why CISOs Should Care
Gives CISOs automated visibility and remediation for who has access to what data across sprawling SaaS environments (Google Workspace, Salesforce, Slack, GitHub, and more), a gap traditional network-centric security tools don't address well.
What Makes It Different
A CrowdStrike Falcon Fund-backed integration that cross-references CrowdStrike endpoint detections with SaaS file exposure to drive automated remediation differentiates it from generic SSPM tools operating on their own telemetry alone.
The Matrix Verdict
55/100 — INCREMENTAL INNOVATOR
A credible, well-capitalized SaaS data access governance vendor with a genuine strategic integration into the CrowdStrike ecosystem; real momentum, though independent efficacy validation remains limited.
Editorial Note: Claims vs. Verified Findings
Funding amounts ($13.35M seed/Series A, $30M Series B) and the CrowdStrike Falcon Fund investment and CrowdStrike Store listing are independently reported via PR Newswire and CrowdStrike's own materials. Claims about remediation speed and detection effectiveness are vendor-sourced and were not independently benchmarked in this research.
Sources
Alternatives to DoControl
Wiz
Agentless, graph-based cloud security platform that maps multi-cloud risk end-to-end, now owned by Google after a record $32B…
Chainguard
Provides hardened, minimal, continuously-rebuilt container images and software packages to eliminate vulnerabilities before they reach production.
Microsoft Defender for Cloud
Microsoft's built-in cloud-native application protection platform, unifying CSPM, workload protection, and DevOps security natively across Azure, AWS, and…
Obsidian Security
Obsidian Security provides a SaaS security posture management (SSPM) platform that detects identity-centric threats and misconfigurations across enterprise…
Sysdig
The company behind Falco, the CNCF's runtime security standard, offering an eBPF/kernel-level CNAPP built on live syscall-based threat…
Tigera
Creator and commercial steward of Project Calico, the most widely adopted Kubernetes networking and network-policy engine, extended into…