Dossier · Private startup · 1 independent source

DoControl

Cybersecurity Dual-Use Technology Priority Signal Founded 2020

Last updated: Jul 31, 2026

DoControl is a privately held SaaS security and data-protection company that maps sensitive data, identities, sharing relationships, connected applications, and configuration risk across enterprise collaboration platforms. Its platform combines contextual detection with policy workflows and automated remediation for data exposure, insider risk, and excessive access.

Visit Website

Company Overview

DoControl operates in the control layer between enterprise SaaS collaboration and security operations. Its product connects to applications such as Google Workspace, Microsoft 365, Salesforce, Slack, Box, and Zoom to build an inventory of data, users, groups, external collaborators, OAuth applications, and permissions. The important distinction in its positioning is that a file, message, or record is not treated as risky solely because it contains sensitive content: risk is evaluated in relation to the person or non-human identity accessing it, the recipient, the business context, the application, and the activity pattern. The platform is designed to find public or excessive sharing, stale access, risky third-party application permissions, and suspicious downloads, then trigger an approval, notification, access change, or other remediation workflow.

The technical thesis is an event-driven, API-mediated security plane rather than an endpoint agent. DoControl describes inventory, no-code SaaS automation workflows, anomaly detection, data access governance, data loss prevention, identity threat detection and response, SaaS misconfiguration management, and shadow-app discovery as parts of the platform. That architecture can reduce the operational gap between a security finding and an effective response: for example, a workflow can identify a publicly accessible document containing regulated data, check user or identity context, notify an owner, and remove the share under defined guardrails. The same approach can clean up historical exposure, not only block a new action. Its newer messaging emphasizes AI-era collaboration, internal overexposure, AI agents, and non-human identities, but those themes should be evaluated as product positioning until independent evidence demonstrates differentiated model performance.

The customer problem is durable and concrete. Enterprises use many SaaS systems with different permission models, while collaboration links and external access often outlive the project, vendor, employee, or business need that created them. Conventional DLP can be strong on content classification but weaker on application-specific relationships and business context; identity tools can show who a user is without fully understanding the data model inside each SaaS system. DoControl therefore sells into overlapping budgets that may include data security, insider-risk management, SaaS security posture management, security operations, identity, and compliance. This breadth is an opportunity but also creates positioning risk because Microsoft Purview, Netskope, CrowdStrike, Cyera, Nightfall, and other vendors increasingly combine adjacent controls.

Public traction signals are credible but incomplete. DoControl announced a $30 million Series B led by Insight Partners in April 2022, with participation from StageOne Ventures, Cardumen Capital, RTP Global, and CrowdStrike's Falcon Fund; the company said at the time that it had raised about $45 million in total and had grown to more than 50 people. Its current website remains active, lists a substantial integration and use-case surface, publishes current security content, and presents customer case studies and testimonials. LinkedIn currently places the company in the 51–200 employee range and identifies New York as headquarters, while the company has Israeli roots and leadership. These are useful signals of continued operation and commercial effort, but they do not establish revenue scale, retention, deployment depth, profitability, or a financing event after Series B.

The defense and national-security relevance is real but indirect. Government, defense, and critical-infrastructure organizations increasingly depend on cloud collaboration suites, and their sensitive information can be exposed through stale permissions, compromised accounts, unmanaged external collaborators, OAuth grants, or automation identities just as in commercial environments. Contextual access governance, audit trails, and controlled remediation could support zero-trust and insider-risk programs without requiring a mission operator to abandon ordinary collaboration. The strongest dual-use case is defensive protection of SaaS data in regulated or government-cloud environments; there is no evidence here of offensive cyber capability or a dedicated defense program. Diligence should therefore focus on supported deployment boundaries, data residency, tenant isolation, logging, integration permissions, approval and rollback controls, independent security attestations, public-sector procurement readiness, and evidence that automation reduces exposure without disrupting legitimate mission workflows.

Dual-Use Assessment

Military & Commercial Applications

DoControl has substantive defensive dual-use potential because government, defense, and critical-infrastructure organizations also depend on collaboration SaaS where stale permissions, compromised identities, external sharing, OAuth applications, and AI or automation identities can expose sensitive information. The fit is strongest for access governance, insider-risk reduction, auditability, and controlled remediation; it is not an offensive cyber capability and no dedicated defense program is publicly verified.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

DoControl remains a credible strategic priority signal for a dual-use cybersecurity database because it targets a persistent enterprise control gap and has a defensible adjacency to insider risk, SaaS security posture, and data loss prevention. The case depends on evidence that its context and remediation layer produces better outcomes than native Microsoft or Google controls and converging security suites. Key diligence questions are recurring revenue quality, customer retention, connector depth, remediation safety, unit economics, post-Series-B capitalization, and readiness for regulated or government-cloud deployments; this flag is not an investment recommendation.

Strategic Value to U.S.-Israel Alliance

DoControl can provide a neutral control and response layer across collaboration systems that otherwise expose security teams to fragmented permission models and slow manual cleanup. That is strategically relevant to zero-trust and data-centric security because it links data exposure to identity, behavior, application, and business context, then turns findings into auditable actions. Its value for national-security users would rise with sovereign or government-cloud options, strong tenant isolation, granular least privilege, durable audit logs, and procurement evidence. Without those capabilities, the company is better understood as a commercially useful SaaS-security vendor with indirect public-sector adjacency rather than a defense-native platform.

Key Technologies

  • SaaS application API connectors and permission graphing
  • Sensitive-data discovery and contextual classification
  • Identity, user, group, external-collaborator, and non-human identity risk modeling
  • Event-driven anomaly detection for sharing, access, downloads, and OAuth activity
  • No-code policy and automation workflows with approval gates
  • Automated permission revocation and historical exposure remediation
  • SaaS posture, shadow-app, and misconfiguration monitoring

Use Cases & Applications

  • Find and remediate publicly accessible or externally shared Google Workspace and Microsoft 365 files
  • Remove stale access for departing employees, former contractors, and inactive collaborators
  • Detect bulk downloads, unusual access, risky sharing, and possible insider-driven exfiltration
  • Inventory and govern OAuth applications and other third-party access to SaaS data
  • Apply contextual DLP policies that distinguish legitimate business sharing from risky exposure
  • Monitor SaaS misconfigurations and shadow applications across a distributed enterprise
  • Protect sensitive government, defense, or critical-infrastructure collaboration data where supported by deployment and compliance controls
  • Assess access by AI agents, bots, and other non-human identities as automation expands

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 6 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

  • docontrol.io Public source used for profile verification.
  • docontrol.io Public source used for profile verification.
  • docontrol.io Public source used for profile verification.
  • LinkedIn company page Public source used for profile verification.
  • Company announcement Public source used for profile verification.
  • docontrol.io Public source used for profile verification.
  • Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.