Doogree
Cloud & identities · Trust model

Cloud Monitoring Without Stealing Your Keys

07/02/2026 · ~5 min read
CSPMITDRAWS/Azure/GCPM365/Google

Most CSPM tools ask you to enter privileged cloud keys into their cloud. In other words: to check whether your cloud is secure, you hand a third party the keys to the kingdom. That's a broken trust model. We built it differently.

The principle: read-only, and the keys stay with you

Doogree scans posture read-only using restricted roles/service accounts that the customer creates themselves:

No key is ever stored in our cloud as plaintext. The connection is made through the admin interface (you paste it once), the credentials are stored encrypted with the organization key (envelope encryption), and the scan-box pulls them only at scan time. You can rotate or delete them at any moment.

What we check

Cloud (CSPM): misconfigurations, open buckets, encryption, overly broad IAM, logs. Identity (ITDR): MFA/2SV coverage, admins without MFA, too many super-admins, stale guest accounts. It all rolls up into the same 0–100 score and the same compliance report as the rest of your assets.

Easy connection — like any major provider

In the "☁️ Cloud & Identities" panel you pick a provider, paste the credentials (with a precise setup hint), and click "Scan." A new provider enters the registry, gets a status and a score, and you can re-run a scan in one click — no SSH, no manual env files.

Why this matters: the "keys stay with you" model isn't just fairness — it's a deal-closer. An organization that (rightly) hesitates to give cloud keys to a third party can adopt cloud monitoring without that risk. The same principle that guides all of Doogree: the keys stay yours.

← Back to the blog · How it works →