# DoControl Financial Model

No-code SaaS security platform that automates data access controls across enterprise SaaS applications, modernizing DLP and CASB

- Canonical: https://finamodel.com/startups/docontrol
- Excel download: https://finamodel.com/startup-models/docontrol.xlsx
- Category: Dev Tools
- Model type: SaaS ARR / Valuation
- Funding round: Series B
- Funding: $30M
- Founded: 2022
- Geography: US-focused (all customers described as US customers) [DECK slide 22]
- Customer: B2B

## About the company

DoControl is a no-code security platform that automates data-access controls across enterprise SaaS applications. It provides visibility, anomaly detection, workflows, and remediation for use cases including DLP, third-party access, insider risk, and incident investigation.

The company targets larger organizations with agentless integrations and enterprise security needs. It had dozens of US customers and a 45-person team, with the likely commercial model being annual SaaS contracts priced by employees, applications, or monitored data environments.

The model is an enterprise cybersecurity ARR forecast. New customers, ACV, seats or connected applications, deployment expansion, renewal, and churn build revenue. Enterprise sales cycles, integration coverage, security-support costs, partner channels, and net retention are the important drivers.

## What's included

- 5-year monthly revenue build with stage-appropriate growth assumptions
- Full P&L, headcount plan, and operating-expense schedule
- Cash-flow statement, runway, and burn-rate tracking
- Valuation via exit multiple with a DCF cross-check
- Returns analysis with MOIC and IRR
- Unit economics including CAC, LTV, payback, and cohort retention

## Product & value proposition

No-code platform providing:
- Visibility and control over SaaS data access (who has access to what, across which apps)
- Continuous monitoring with anomaly detection and behavioral analytics
- Automated remediation workflows (no-code workflow builder, Slackbot integration)

Addresses five specific use cases shown in deck: DLP, third-party vendor management, automated remediation, insider threat protection, incident response enrichment, least-privilege enforcement, and security investigation enrichment.

Integrates with: Google Workspace, Microsoft 365, Atlassian, Salesforce, Box, Dropbox, Slack (data sources); Okta, Azure AD, OneLogin, Duo (IDP); CrowdStrike, SIEM, SOAR, EDR, HR systems (security stack).

Positioning: agentless, low-touch, fully automated; replaces/augments CASB, DLP, SSPM.

## Market

- SaaS market projected to grow >20% annually, reaching ~$200B by 2024, ~1/3 of overall enterprise software market
- Average large org (2,000+ employees) deploys 187 SaaS apps
- Average data breach cost: $3.86M (2021)
- 3rd-party breach remediation cost: avg $7.5M; 53% of orgs experienced at least one 3rd-party data breach
- Average company works with ~583 vendors
- No explicit TAM/SAM/SOM numbers or addressable market figures in deck

## Revenue model

- B2B SaaS subscription: enterprise security platforms of this type (CASB/DLP replacement) typically price per seat or per SaaS app monitored, with annual contracts; deal sizes usually $50K–$500K+ ACV for mid-market/enterprise. Rationale: product is agentless and targets organizations with 2,000+ employees; integrates with enterprise identity stacks.

## Traction & metrics

- 45 employees
- "Dozens of US customers" - no specific count, no ARR, no revenue figures
- Established June 2020
- Multiple industry awards (2021–2022): CRN 10 Hottest Cybersecurity Startups 2021, Cyber Defense Magazine Global Infosec Awards 2021, BIG 50 Startup 2021, TiE 50 2021, CRN Emerging Vendors 2021, 2022 Globee Awards Silver Winner
- No ARR, growth rate, NRR, customer logos, or pipeline data disclosed

## Competition / moat

Competitors mentioned: SaaS-native controls (fragmented), CASB (non-granular remediation), DLP (alert fatigue from full PII scanning), SSPM (misconfiguration-focused, no data access remediation)

Moat / differentiation:
- No-code workflow builder - accessible to security/IT teams without engineering
- Metadata-based approach (no inline proxy, agentless) vs. traditional CASB
- HR + IDP + SaaS app integration for insider threat lifecycle automation
- CrowdStrike Falcon Fund backing signals strategic alignment with endpoint leader

## Team & funding ask / use of funds

**Team**:
- Adam Gavish - Co-Founder & CEO
- Omri Weinberg - Co-Founder & CRO
- Liel Ran - Co-Founder & CTO

**Investors**: RTP Global, StageOne Ventures, Cardumen Capital, Insight Partners, CrowdStrike Falcon Fund

---

## Recommended financial model

- **Archetype + why**: SaaS ARR model with new logo and expansion ARR tracking. DoControl is a classic enterprise cybersecurity SaaS - annual contracts, seat/app-based pricing, high NRR potential from expanding app coverage within accounts. No transactional/usage or marketplace mechanics evident.

- **Forecast horizon & granularity**: 3 years (monthly for Year 1, quarterly for Years 2–3). Early-stage company; monthly granularity critical in Year 1 to track cash burn vs. bookings ramp.

- **Key drivers & assumptions**:
  - Starting customer count: ~20 (proxy for "dozens")
  - New logos per quarter (sales capacity): 5–8 in Year 1, ramping to 15–25 by Year 3; rationale: 45 employees, CRO co-founder, US-focused
  - Average ACV: $75K–$150K; rationale: enterprise CASB/DLP replacements, mid-market target segment
  - Net Revenue Retention (NRR): 110–120%; rationale: expansion via additional SaaS app connectors and user growth within accounts
  - Gross margin: 70–75%; rationale: cloud-hosted, API-based architecture, low COGS beyond hosting + support
  - Sales cycle: 60–120 days; rationale: security platform requiring IT/CISO sign-off
  - CAC: $40K–$80K per logo; rationale: enterprise outbound motion, long cycle
  - LTV/CAC: target >3x; rationale: standard SaaS investor benchmark at this stage
  - Headcount: 45 at model start; ~60–70% of OpEx is personnel; hiring plan drives burn
  - Burn rate / runway: - no funding size or runway disclosed; must be input assumption

- **Scenarios (Base / Bull / Bear - which variables flex)**:
  - Base: 8 new logos/quarter by Year 2, $100K ACV, 115% NRR, 72% gross margin
  - Bull: faster land (12+ logos/quarter), higher ACV ($150K+) via upmarket move, 125% NRR as app coverage expands
  - Bear: slower sales cycle, $60K ACV (competitive pricing pressure), churn in early cohorts (90% GRR)

- **Required sheets / outputs**:
  1. Assumptions dashboard (all drivers editable)
  2. ARR bridge (new logo ARR, expansion ARR, churn, net new ARR)
  3. Cohort table (by quarter, tracking expansion and churn per cohort)
  4. P&L (Revenue → Gross Profit → S&M / R&D / G&A → EBITDA)
  5. Headcount plan (by department: Engineering, Sales, CS, G&A)
  6. Cash flow & runway (monthly Year 1)
  7. SaaS metrics summary (ARR, MRR, ACV, NRR, CAC, LTV, LTV/CAC, payback period, magic number)

## Frequently asked questions

### Is the DoControl financial model free?

Yes. The DoControl model is a free Excel download with live formulas.

### Can I change the assumptions?

Yes. The workbook is editable and its live formulas recalculate when assumptions change.
