DoControl provides organizations with the automated, self-service tools they require for Software as a Service (SaaS) application data access monitoring, orchestration, and remediation.
DoControl provides organizations with the automated, self-service tools they require for Software as a Service (SaaS) application data access monitoring, orchestration, and remediation. The solution uncovers all SaaS users, 3rd party collaborators, assets/metadata, OAuth apps, groups, and activity events. From there, security teams can create granular data access control policies to reduce the risk of data overexposure and exfiltration. We take a unique, customer-focused approach to the challenge of labor-intensive security risk management and data loss prevention (DLP) in SaaS. DoControl has no agents, no inline redirections, and no slow response times as commonly found in Cloud Access Security Broker (CASB) solutions.
Highlights
End-to-end visibility across SaaS apps
Continuous Monitoring and control all identities in real-time
Automated Security Workflows with Granular data access control policies
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You buy the Core Platform under a contract based on your number of users. Four user bands set your price: up to 500 users, 501 to 2,500 users, 2,501 to 10,000 users, and 10,000 or more users. All four bands include the same core integrations, monitoring, and workflows. The only difference is the user count you fall into. As your user count grows, you move to the band that fits your organization. Pick the band that matches your total users to determine your contract price.
Top-of-mind questions for buyers
What counts as one user for determining which pricing band applies?
Your user count reflects the people across your connected SaaS applications. DoControl builds an inventory of all your SaaS users, assets, and third-party OAuth apps. The total number of users places you into one of the four bands: up to 500, 501 to 2,500, 2,501 to 10,000, or 10,000 or more.
If our user count grows past a band limit, does the price change for all users or only the additional ones?
Pricing is banded, not incremental. Your entire user count sets which single band applies, and the contract price reflects that band. Crossing a boundary moves you to the next band for all users, not just the new ones. Confirm transition timing with the vendor.
Do all four bands include the same features, or do larger bands add capabilities?
All four bands include the same Core Platform: core integrations, monitoring, and workflows. This covers data inventory, data loss prevention, threat detection, remediation workflows, and shadow app governance. The only difference between bands is the user count you fall into, which sets your contract price.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
DoControl is committed to ensuring that its Customers, Prospects, and Partners receive best-in-class support. We do this through constant product improvements, hiring top notch talent, and building scalable processes to enable organizations to best protect their SaaS infrastructure.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Discovers all SaaS users, third-party collaborators, assets, metadata, OAuth apps, groups, and activity events across SaaS applications
Real-time Identity Monitoring
Provides continuous monitoring and control of all identities in real-time across SaaS environments
Granular Access Control Policies
Enables creation of granular data access control policies to reduce data overexposure and exfiltration risks
Automated Security Workflows
Implements automated security workflows for data access orchestration and remediation without agents or inline redirections
Agent-less Architecture
Operates without agents, inline redirections, or performance degradation typical of Cloud Access Security Broker solutions
Identity Threat Detection
Active threat detection and neutralization for SaaS identities with spearphishing blocking and incident response capabilities
Third-Party Integration Risk Management
Discovery and governance of third-party integrations across SaaS applications with risk assessment and mitigation
Data Movement Governance
Monitoring and control of data movement between SaaS applications with visibility into data flows
Application Posture Management
Automated compliance enforcement, privilege reduction, and configuration drift prevention across SaaS platforms
Unified SaaS Security Platform
Integrated platform combining identity security, data governance, and application posture management in a single modular solution
Zero Trust Architecture
Cloud-native zero trust platform that applies zero trust principles to eliminate attack surface and prevent lateral movement across users, applications, and infrastructure.
AI-Powered Threat Detection
AI-powered cyberthreat and data loss prevention services that detect and prevent advanced threats, accidental exposure, theft, and ransomware attacks.
Next-Generation Network Access
Next-generation zero trust network access (ZTNA) platform enabling seamless and secure connectivity to private applications, services, and operational technology devices.
Data Loss Prevention
Data protection capabilities preventing data loss from users, SaaS applications, and public cloud infrastructure through comprehensive loss prevention policies.
End-to-End Digital Experience Monitoring
End-user perspective monitoring and visibility across device, ISP, cloud proxy, and application layers to optimize performance and identify application, network, and device issues.
Speed to value was the big win for us. We connected Google Workspace on a Tuesday, and by Thursday we already had a full inventory, exposure numbers, and our first workflows running. There were no agents, no proxies, and no six-week professional services engagement to get started. We’re a consumer brand with a tiny security team, and the pre-built playbooks cover our main risks: external shares, public links, departing employees, and sketchy OAuth apps. The Slack bot also takes care of the long tail of employee mistakes, which helps the two of us stay focused on the real threats.
What do you dislike about the product?
The pricing feels geared toward larger companies than ours, and I had to push hard to get the budget approved. Some of the dashboards also seem to assume you have a SOC running in shifts, which we don’t. Still, these are minor gripes considering what we get overall.
What problems is the product solving and how is that benefiting you?
We were growing fast, working with hundreds of marketing and agency collaborators, and had no appetite to hire three more analysts. DoControl gave our two-person team the coverage that would normally take six.
Zachary O.
Good for SaaS posture and SOC 2 evidence, with room to grow on frameworks
Reviewed on Aug 20, 2026
Review provided by G2
What do you like best about the product?
The misconfiguration module maps checks to CIS controls and shows impact by app and domain, so my team fixes the worst things first instead of reading a 200-item list. Auditors like the evidence trail. Every remediation is logged with a timestamp and an actor, which ended the annual screenshot scavenger hunt. Guided remediation steps are specific enough that a junior analyst can follow them without Slack-ing an engineer.
What do you dislike about the product?
Framework coverage is still growing. SOC 2 and CIS are fine; some of the mappings we need for ISO 27001 required manual work. The misconfiguration module is also clearly newer than the data access side, and the check library per app varies. Google Workspace is deep, some others are shallow.
What problems is the product solving and how is that benefiting you?
SaaS misconfigurations and compliance drift across Google Workspace, Microsoft 365, and Slack. Audit prep time for our SaaS controls dropped from about three weeks to four days, and posture stays current between audits instead of once a year.
Leona M.
Shadow app cleanup that actually finishes
Reviewed on Aug 20, 2026
Review provided by G2
What do you like best about the product?
The OAuth app inventory found 340 third-party apps connected to our Google Workspace, and I had personally approved maybe 30 of them. Each app gets a risk score based on its scopes, its usage, and where it comes from. Removing a bad one is one click, and you can bulk-remove or set a workflow that blocks new installs of unapproved categories. We killed a handful of abandoned apps that still had full Drive read access. One had been requesting email scopes since 2021.
What do you dislike about the product?
The risk scoring is a black box at times. I can see the inputs but not always why two similar apps land on different scores. Smaller niche SaaS connectors are missing, though the big five are covered well. No browser extension telemetry, so a tool used only in the browser without OAuth can slip past it.
What problems is the product solving and how is that benefiting you?
Shadow SaaS and over-permissioned third-party apps in a retail company where every department buys its own tools. We went from no inventory at all to a governed approval process in about two months.
Brandon G.
Drive DLP that quarantines instead of just alerting
Reviewed on Aug 19, 2026
Review provided by G2
What do you like best about the product?
When a file containing credentials or customer PII lands in a public Slack channel or gets shared outside our approved domains, DoControl can quarantine it or strip the share in real time instead of opening a ticket for a human to handle hours later. The classification is good. It uses our HRIS data, so it knows a contractor from an employee, and it knows which external domains are our partners versus random Gmail. That context is the difference between a DLP people work around and one they barely notice.
What do you dislike about the product?
Alert tuning took about a month of weekly adjustments. The default thresholds were too sensitive for a company our size. Also, custom keyword lists and regex management could use a friendlier interface; right now it feels built for engineers.
What problems is the product solving and how is that benefiting you?
Sensitive data exposure in Google Drive and Slack for an identity-verification company where a leak is existential. Mean time to remediate an overshared file went from days to minutes, and most remediations happen without my team lifting a finger.
Dominic W.
Handles billions of assets without flinching
Reviewed on Aug 18, 2026
Review provided by G2
What do you like best about the product?
Scale. We are a global payments company with an enormous Google Workspace and Microsoft 365 footprint, and most tools we piloted choked during ingestion. DoControl indexed everything and stayed fast. Queries over our asset inventory return quickly, and bulk remediations that touch six figures of files complete in minutes. The architecture was clearly built for Fortune-scale data. Support is strong too; our customer success engineer knows our environment better than some of our own staff.
What do you dislike about the product?
Enterprise procurement is a slog, but that is on us as much as them. The product itself: misconfiguration management lags the data side in maturity, and I want more granularity in admin roles for a global team with regional data restrictions.
What problems is the product solving and how is that benefiting you?
Data access governance and insider risk at a scale where manual review is a fantasy. We run continuous, automated controls over sharing behavior that previously got audited once a year by sampling. Sampling is over.