DoControl - SaaS Security Platform logo

    DoControl - SaaS Security Platform

    Sold by
    DoControl provides organizations with the automated, self-service tools they require for Software as a Service (SaaS) application data access monitoring, orchestration, and remediation.

    Ratings and reviews

    4.7
    13 ratings
    3 star
    2 star
    1 star
    92%
    8%
    0%
    0%
    0%
    0 AWS reviews
    |
    13 external reviews
    External reviews are from G2 .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (13)
    Kyle D.

    First tool that treats AI agents as identities worth watching

    Reviewed on Aug 17, 2026
    Review provided by G2
    What do you like best about the product?
    The non-human identity angle. We have internal AI agents and copilots touching Google Drive, and until DoControl we had no way to tell a human reading a file from an agent bulk-reading a folder outside its normal pattern. It inventories them alongside OAuth apps, scores them, and flags anomalous access. The identity threat detection baselines per user and per team are solid for humans too. Their newer AI assistant, Dot, is genuinely useful for investigation: I asked it which departing employees had downloaded more than 100 files in their last 30 days and got an answer in seconds.
    What do you dislike about the product?
    The AI agent governance module is young. Detection logic for agent behavior needs more tuning knobs, and documentation trails the feature releases. Dot occasionally needs a question rephrased before it finds the right dataset. Expect some growing pains in this part of the product.
    What problems is the product solving and how is that benefiting you?
    Identity threat detection across human and non-human identities in a SaaS company that deploys AI internally. We wrote our first agent-access policy this quarter, backed by data instead of vibes.
    Sherry C.

    We trust the workflows enough to stop watching them

    Reviewed on Aug 17, 2026
    Review provided by G2
    What do you like best about the product?
    Reliability of the automation. We run 30+ workflows now: expiring external shares after 60 days, revoking access for accounts disabled in Okta, quarantining files that match our secrets patterns, asking owners to re-certify vendor shares quarterly. They fire exactly as configured. That freed my team from being the cleanup crew and let them do detection engineering instead. The playbook library got us 80% of the way on day one; the custom 20% took some iteration but nothing we could not handle.
    What do you dislike about the product?
    Workflow versioning is thin. When you edit a live workflow, there is no clean rollback, so we clone before we change anything. I also want better simulation: show me exactly which 12,000 files this workflow would have touched last month before I turn it on. They have preview, but it could go further.
    What problems is the product solving and how is that benefiting you?
    We are a security company ourselves, so our bar is high. DoControl handles the repetitive data-hygiene work across Google Workspace and Slack that used to eat a quarter of an analyst's week, every week. Our headcount stayed flat while exposure kept dropping.
    Sneha R.

    Caught a departing employee exfiltrating before HR told us they were leaving

    Reviewed on Aug 16, 2026
    Review provided by G2
    What do you like best about the product?
    The ITDR piece. DoControl flagged a senior account manager who downloaded 2,000+ files over a weekend and shared a folder with a personal Gmail address. HR had not even announced the resignation yet; the system picked up the deviation from that person's normal pattern and from their team's baseline. Alerts go to our Slack channel and forward into our SIEM, so the SOC sees them in the same queue as everything else. For a financial services firm, this is the scenario that keeps a CISO up at night, and it works.
    What do you dislike about the product?
    The first month required real tuning.. You need someone who owns alert triage during that window.
    What problems is the product solving and how is that benefiting you?
    Insider risk and data exfiltration across Google Workspace and Box. We have a paper trail now for every anomalous event, which our regulators and our board both ask about. Two incidents contained before data left the building.
    Kiran S.

    Solid context-aware DLP for a HIPAA environment

    Reviewed on Aug 16, 2026
    Review provided by G2
    What do you like best about the product?
    PHI detection that does not cry wolf. We scan Google Drive and SharePoint for health information, and the combination of NLP classifiers plus HRIS context cut our false positive rate by more than half compared to the regex-based DLP we ran before. When a care coordinator shares a patient file with a specialist at a partner clinic, that is the job. When a billing contractor downloads 400 patient records the week their contract ends, that is not. DoControl separates those two events reliably.
    What do you dislike about the product?
    Deployment was not hard, but tuning was. Expect four to six weeks before the anomaly models learn your baselines and the noise settles. The compliance reporting covers HIPAA reasonably well, but some controls still need manual mapping for our auditor.
    What problems is the product solving and how is that benefiting you?
    HIPAA exposure across collaboration tools that our clinicians actually use. We passed our most recent OCR-adjacent review without a single finding on data sharing, which has never happened before.
    Leah M.

    Right answer for Google-first shops; check depth on your other apps

    Reviewed on Aug 15, 2026
    Review provided by G2
    What do you like best about the product?
    We evaluated DoControl against AppOmni and a CASB renewal. DoControl won on remediation: the others found problems well enough, but DoControl fixes them, in bulk, with workflows we control. Box and Slack coverage met our needs, and the Google Workspace depth is the best I have tested. Deployment was API-based and painless, which matters when your team is five people supporting two thousand users.
    What do you dislike about the product?
    Salesforce coverage is thinner than Google's. If your crown jewels live in Salesforce, demo that connector hard before you sign. The misconfiguration module exists but does not yet match a dedicated SSPM's check library on every app. And pricing: not cheap, though still less than the CASB suite we dropped.
    What problems is the product solving and how is that benefiting you?
    External sharing governance and historical exposure cleanup for a manufacturing company in the middle of a cloud migration. We retired a CASB that gave us telemetry but lacked context, and we replaced the manual cleanup queue with scheduled workflows.
    Robert K.

    Pushed security responsibility to the people who create the data

    Reviewed on Aug 14, 2026
    Review provided by G2
    What do you like best about the product?
    The end user engagement model, every other tool I have deployed treats employees as the problem and routes everything through my team. DoControl messages the person who overshared, explains the policy, and asks them to fix it or justify it. Most people fix it. That does two things: it closes the ticket and it teaches. Our repeat-offender rate dropped noticeably after the first quarter. From a media company perspective, where journalists share documents with sources and freelancers constantly, this was the only approach that scaled without killing how our people work.
    What do you dislike about the product?
    The Teams bot came later than the Slack bot and it shows. We are a Slack shop so it did not hurt us, but our sister company on Teams had a rougher first month. Admin role granularity could be deeper too.
    What problems is the product solving and how is that benefiting you?
    Hundreds of external collaborators with legitimate access needs, plus the long tail of people who left projects but kept access. DoControl's workflows expire external shares automatically and ask owners to re-approve. My team of four now governs sharing for 2,000 employees without working weekends.
    Wholesale

    If you live in Google Workspace and Slack, seriously consider

    Reviewed on Aug 14, 2026
    Review provided by G2
    What do you like best about the product?
    Our entire company runs on Google Workspace and Slack, and DoControl supports both as if it were built specifically for them. It delivers DLP with real context. The old approach to DLP is basically scanning for credit card and Social Security numbers, then getting buried in false positives. DoControl adds the missing layers: who the person is, what team they’re on, whether they’re about to leave, and who the recipient is. As a result, our alert volume dropped, and the alerts that still come through are actually worth reading.

    The Slack bot that prompts employees to explain a share or undo it is the feature my team mentions most. At this point, about half of our incidents get resolved without even needing a ticket.
    What do you dislike about the product?
    Coverage beyond the core apps feels thinner. For example, our Salesforce instance doesn’t get the same depth of coverage that our Drive environment does. I’d also like to see more out-of-the-box compliance frameworks mapped to the misconfiguration checks, although to be fair, they do keep adding more over time.
    What problems is the product solving and how is that benefiting you?
    We’re an analytics company that holds customer data both in our own environment and across our SaaS stack. DoControl gave us DLP that the business doesn’t hate, because legitimate work isn’t getting blocked. As a result, security stopped being the “department of no.”
    Ronda F.

    Visibility we could not get from our CASB

    Reviewed on Aug 14, 2026
    Review provided by G2
    What do you like best about the product?
    We already had a CASB, and it still couldn’t tell us who inside the company had shared what with whom in Google Drive and Slack. DoControl could—within hours of connecting. Seeing your real exposure number is uncomfortable at first, but then you get to work.

    What I like most is the business context. An alert about a file shared with an external domain means one thing when it’s our CFO sending financials to our auditors, and something else entirely when a departing engineer sends a design doc to a personal account. DoControl can tell those situations apart because it reads our IdP and HRIS. Our CASB couldn’t.
    What do you dislike about the product?
    It is expensive for what started as a single-use-case purchase for us. Reporting is the weaker part. Executives want a monthly one-pager and I still end up exporting and massaging data myself. The pre-built dashboards are fine for operators, less so for a board deck.
    What problems is the product solving and how is that benefiting you?
    Insider risk and external sharing hygiene across Google Workspace and Slack for a consumer electronics company with a lot of contract manufacturers. We caught two genuine pre-departure data grabs in the first year. That paid for it.
    Evan L.

    A K-12 IT director's honest take after one school year

    Reviewed on Aug 13, 2026
    Review provided by G2
    What do you like best about the product?
    The free risk assessment alone was worth the call. It showed us 600,000+ assets shared publicly and student health records sitting in folders any staff member could open. Students and faculty share one Google tenant here, and DoControl let us build what amounts to an ethical wall between them without breaking class projects. The Slack-style notifications that go to the teacher who overshared, instead of to me, changed everything. Teachers fix their own files now. I stopped being the bad guy.
    What do you dislike about the product?
    Some of the terminology assumes a security background that school IT staff don't have. My team learned it fine, but expect a few training sessions before your generalists are comfortable. I also wish the education pricing were more clearly separated from enterprise pricing.
    What problems is the product solving and how is that benefiting you?
    FERPA exposure, substitute teachers and contractors retaining access after they leave, and students wandering into faculty content. We remediated over a million exposed assets in the first semester and automated offboarding for temp staff. Our last audit took days instead of weeks because the evidence was already there.
    Melanie H.

    Cleaned up four years of Google Drive oversharing in a quarter

    Reviewed on Aug 12, 2026
    Review provided by G2
    What do you like best about the product?
    We had north of 40,000 files shared externally or with "anyone with the link" after years of growth and no realistic way to fix it by hand. DoControl inventoried everything in the first day.. let me filter by domain, by department, by sensitivity label, and then remove access in bulk. What would have been a six-month intern project took about three weeks of clicking. The scheduled workflows keep it from regressing, which matters more than the initial cleanup.
    What do you dislike about the product?
    Pricing is driven by data usage, also the workflow builder has a learning curve once you go past the pre-built playbooks. Conditional logic with HRIS attributes took our engineer a week to get right. Not a complaint exactly, but plan for it.
    What problems is the product solving and how is that benefiting you?
    Data exposure in Google Workspace at a company that doubled headcount twice in two years. We cut public and external asset exposure by roughly 70%, and the workflows now handle the routine stuff (external shares older than 90 days, shares to personal Gmail accounts) without anyone on my team touching them. I got two analysts back to actual investigations.