DoControl - SaaS Security Platform logo

    DoControl - SaaS Security Platform

    Sold by
    DoControl provides organizations with the automated, self-service tools they require for Software as a Service (SaaS) application data access monitoring, orchestration, and remediation.

    Ratings and reviews

    4.7
    23 ratings
    3 star
    2 star
    1 star
    96%
    4%
    0%
    0%
    0%
    0 AWS reviews
    |
    23 external reviews
    External reviews are from G2 .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (23)
    Simon J.

    What our CASB could never tell us, one year in

    Reviewed on Sep 04, 2026
    Review provided by G2
    What do you like best about the product?
    The first scan was the moment. a week after connecting Google Workspace we were staring at roughly 9,440 externally shared files nobody knew about.
    What do you dislike about the product?
    For us, it will not manage SaaS licenses or do IT lifecycle work. For us, that is a different tool category, but people keep asking.
    What problems is the product solving and how is that benefiting you?
    Leadership kept asking how exposed our data was and I kept giving them estimates. Now I give them queries. Exposure is down 53% and the number stays down because the workflows hold the line.
    Jamiuel H.

    Not the cheapest, worth it anyway

    Reviewed on Sep 01, 2026
    Review provided by G2
    What do you like best about the product?
    We thought our sharing hygiene was decent. DoControl’s initial scan said otherwise: roughly 46,000 files shared outside the company, some untouched since 2019. No agents, no proxies, no network taps. API connections and done.
    What do you dislike about the product?
    The simulation before enabling a workflow is good, not great. I want per-file certainty on big actions.
    What problems is the product solving and how is that benefiting you?
    Our auditors asked who had access to what. Before DoControl the honest answer was ‘we think we know.’ We answer access questions in minutes now. Reporting to the board is easier now, too.
    Erik A.

    Came from BetterCloud; different tool for a different problem

    Reviewed on Aug 31, 2026
    Review provided by G2
    What do you like best about the product?
    We ran BetterCloud for IT automation and it did that job fine, but when leadership asked who could see our sensitive files and what random apps were connected to our domain, BetterCloud's answers were shallow. DoControl answers those questions in depth: per-file exposure, per-user behavior, per-app risk scores, plus the context from Okta and our HRIS to tell an accident from a threat. The workflows aim at security outcomes, not admin busywork. Migration of our policies took about three weeks.
    What do you dislike about the product?
    It will not manage licenses or offboard a user across 40 apps the way an SMP does, so do not expect that. We kept a lighter tool for lifecycle work. Also, the pricing conversation required executive involvement; this is not a swipe-the-card purchase.
    What problems is the product solving and how is that benefiting you?
    SaaS data security and shadow app governance for a mid-market software company. We stopped guessing about exposure and started enforcing policy on it, and our security reviews with enterprise customers go smoother now.
    Kevin S.

    Historical cleanup before our audit saved the deal

    Reviewed on Aug 29, 2026
    Review provided by G2
    What do you like best about the product?
    We bought DoControl three months before a customer-mandated security audit that included data governance. The initial scan found years of accumulated mess: client files shared with personal accounts, public links to contracts, ex-employees with live access. We used bulk remediation to clean it and automated workflows to prove it would stay clean. The auditor saw current state plus the remediation log and moved on. That audit closed a contract worth more than ten years of DoControl.
    What do you dislike about the product?
    The first dashboard view is a lot to take in. New admins benefit from the onboarding sessions; skip them and you will flail for a week. I also want saved-query sharing between admins, which apparently is on the roadmap.
    What problems is the product solving and how is that benefiting you?
    Client data governance for an edtech company selling into districts that audit vendors hard. We can now answer any customer's data-handling questionnaire from evidence instead of assertion.
    Bertha F.

    Enterprise-grade SaaS security for a team of two

    Reviewed on Aug 20, 2026
    Review provided by G2
    What do you like best about the product?
    Speed to value was the big win for us. We connected Google Workspace on a Tuesday, and by Thursday we already had a full inventory, exposure numbers, and our first workflows running. There were no agents, no proxies, and no six-week professional services engagement to get started. We’re a consumer brand with a tiny security team, and the pre-built playbooks cover our main risks: external shares, public links, departing employees, and sketchy OAuth apps. The Slack bot also takes care of the long tail of employee mistakes, which helps the two of us stay focused on the real threats.
    What do you dislike about the product?
    The pricing feels geared toward larger companies than ours, and I had to push hard to get the budget approved. Some of the dashboards also seem to assume you have a SOC running in shifts, which we don’t. Still, these are minor gripes considering what we get overall.
    What problems is the product solving and how is that benefiting you?
    We were growing fast, working with hundreds of marketing and agency collaborators, and had no appetite to hire three more analysts. DoControl gave our two-person team the coverage that would normally take six.
    Zachary O.

    Good for SaaS posture and SOC 2 evidence, with room to grow on frameworks

    Reviewed on Aug 20, 2026
    Review provided by G2
    What do you like best about the product?
    The misconfiguration module maps checks to CIS controls and shows impact by app and domain, so my team fixes the worst things first instead of reading a 200-item list. Auditors like the evidence trail. Every remediation is logged with a timestamp and an actor, which ended the annual screenshot scavenger hunt. Guided remediation steps are specific enough that a junior analyst can follow them without Slack-ing an engineer.
    What do you dislike about the product?
    Framework coverage is still growing. SOC 2 and CIS are fine; some of the mappings we need for ISO 27001 required manual work. The misconfiguration module is also clearly newer than the data access side, and the check library per app varies. Google Workspace is deep, some others are shallow.
    What problems is the product solving and how is that benefiting you?
    SaaS misconfigurations and compliance drift across Google Workspace, Microsoft 365, and Slack. Audit prep time for our SaaS controls dropped from about three weeks to four days, and posture stays current between audits instead of once a year.
    Leona M.

    Shadow app cleanup that actually finishes

    Reviewed on Aug 20, 2026
    Review provided by G2
    What do you like best about the product?
    The OAuth app inventory found 340 third-party apps connected to our Google Workspace, and I had personally approved maybe 30 of them. Each app gets a risk score based on its scopes, its usage, and where it comes from. Removing a bad one is one click, and you can bulk-remove or set a workflow that blocks new installs of unapproved categories. We killed a handful of abandoned apps that still had full Drive read access. One had been requesting email scopes since 2021.
    What do you dislike about the product?
    The risk scoring is a black box at times. I can see the inputs but not always why two similar apps land on different scores. Smaller niche SaaS connectors are missing, though the big five are covered well. No browser extension telemetry, so a tool used only in the browser without OAuth can slip past it.
    What problems is the product solving and how is that benefiting you?
    Shadow SaaS and over-permissioned third-party apps in a retail company where every department buys its own tools. We went from no inventory at all to a governed approval process in about two months.
    Brandon G.

    Drive DLP that quarantines instead of just alerting

    Reviewed on Aug 19, 2026
    Review provided by G2
    What do you like best about the product?
    When a file containing credentials or customer PII lands in a public Slack channel or gets shared outside our approved domains, DoControl can quarantine it or strip the share in real time instead of opening a ticket for a human to handle hours later. The classification is good. It uses our HRIS data, so it knows a contractor from an employee, and it knows which external domains are our partners versus random Gmail. That context is the difference between a DLP people work around and one they barely notice.
    What do you dislike about the product?
    Alert tuning took about a month of weekly adjustments. The default thresholds were too sensitive for a company our size. Also, custom keyword lists and regex management could use a friendlier interface; right now it feels built for engineers.
    What problems is the product solving and how is that benefiting you?
    Sensitive data exposure in Google Drive and Slack for an identity-verification company where a leak is existential. Mean time to remediate an overshared file went from days to minutes, and most remediations happen without my team lifting a finger.
    Dominic W.

    Handles billions of assets without flinching

    Reviewed on Aug 18, 2026
    Review provided by G2
    What do you like best about the product?
    Scale. We are a global payments company with an enormous Google Workspace and Microsoft 365 footprint, and most tools we piloted choked during ingestion. DoControl indexed everything and stayed fast. Queries over our asset inventory return quickly, and bulk remediations that touch six figures of files complete in minutes. The architecture was clearly built for Fortune-scale data. Support is strong too; our customer success engineer knows our environment better than some of our own staff.
    What do you dislike about the product?
    Enterprise procurement is a slog, but that is on us as much as them. The product itself: misconfiguration management lags the data side in maturity, and I want more granularity in admin roles for a global team with regional data restrictions.
    What problems is the product solving and how is that benefiting you?
    Data access governance and insider risk at a scale where manual review is a fantasy. We run continuous, automated controls over sharing behavior that previously got audited once a year by sampling. Sampling is over.
    Matthew M.

    Offboarding contractors and subs stopped being a spreadsheet

    Reviewed on Aug 18, 2026
    Review provided by G2
    What do you like best about the product?
    Schools run on temporary labor: substitutes, consultants, coaches, contractors. They all got access to shared drives with their personal Gmail accounts, and when they left, the access stayed. DoControl flags every share to a personal domain, ties it to HR data, and our workflow now revokes access automatically when someone leaves the district. We also use it to keep students out of faculty content in our shared tenant. The district's exposure dropped over 90% in the first semester, and I did not hire anyone.
    What do you dislike about the product?
    Honestly, the hardest part was change management with principals, not the product. On the product side, I would like simpler reporting aimed at school boards rather than security professionals.
    What problems is the product solving and how is that benefiting you?
    FERPA compliance, contractor offboarding, and student data protection across a district with thousands of shared files created daily. We can finally answer the question "who can see this student's records" with a query instead of a guess.