Spin.AI Acquires DoControl to Expand SaaS and AI Security in 2026
News | 07.09.2026
Enterprises running Google Workspace, Microsoft 365, Salesforce and Slack face a growing gap between what identities can access and what security teams can actually see. Shadow data sharing, unmanaged AI usage, risky browser extensions and non-human identities are all expanding the SaaS attack surface at the same time. Spin.AI's acquisition of DoControl directly targets this gap by combining SaaS data access governance and DLP with SaaS security posture management, browser security and cyber resilience in a single, layered offering.
What was announced
On August 31, 2026, Spin.AI announced the acquisition of DoControl, an Israeli cybersecurity company specialized in automated SaaS data access governance and data loss prevention. The combined company now protects more than 2,000 organizations worldwide and covers five distinct layers of SaaS and AI risk: access governance and DLP, SaaS security posture management (SSPM), browser security, insider and non-human identity risk, and ransomware resilience.
The transaction builds on K1 Investment Management backing announced in March 2026. Existing DoControl and Spin.AI customers face no product change, no contract change and no migration. Both brands will continue to operate independently for the foreseeable future.
We built Spin.AI around the idea of addressing SaaS and AI security in layers, each reinforcing the others. Adding DoControl's DLP and AI Governance capabilities gives security teams a clearer view of identities accessing data and how it is moving within SaaS and AI
Why this matters
For CIOs, CISOs and IT procurement leaders, consolidating SaaS and AI security under one vendor reduces integration overhead, licensing complexity and blind spots between tools. DoControl brings documented outcomes: Vox Media remediated excessive sharing across 20% of its SaaS documents and automated employee offboarding without additional headcount, while StackAdapt reduced public and external asset exposure by roughly 75% and completed more than 55,000 automated remediations within 90 days.
Spin.AI adds a risk assessment engine that has evaluated more than 550,000 browser extensions and applications, a 4.8/5 G2 rating across 127 reviews, and the SpinOne and SpinCRX platforms covering SSPM, browser security and ransomware resilience. Together they deliver defense-in-depth without forcing customers to rebuild architecture.
Technical details
- Access governance and DLP: automated discovery, remediation and least-privilege enforcement across Google Workspace, Microsoft 365, Salesforce and Slack.
- SaaS Security Posture Management: continuous configuration and risk monitoring via SpinOne.
- Browser security: SpinCRX enterprise browser security plus extension risk assessment across 550,000+ extensions and apps.
- Insider and non-human identity risk: visibility into automated systems that now drive most activity on platforms like SharePoint and OneDrive.
- Ransomware and cyber resilience: backup, recovery and eDiscovery for mission-critical SaaS data.
- AI governance: monitoring and control of AI usage and AI-driven data movement across SaaS environments.
Softprom and Spin.AI
Softprom is the official distributor of Spin.AI. Our team helps enterprises design, deploy and operate SaaS and AI security programs based on the combined Spin.AI and DoControl platform, from initial risk assessment to full defense-in-depth architecture.
Request a consultation and pricing for the combined SaaS and AI security platform from Spin.AI.
This content was prepared as part of the Softprom DistriFlow project — an automated system for monitoring and adapting vendor news. Original source: original article.