Cloud Monitoring Without Stealing Your Keys
Most CSPM tools ask you to enter privileged cloud keys into their cloud. In other words: to check whether your cloud is secure, you hand a third party the keys to the kingdom. That's a broken trust model. We built it differently.
The principle: read-only, and the keys stay with you
Doogree scans posture read-only using restricted roles/service accounts that the customer creates themselves:
- AWS — a read-only role (SecurityAudit) that runs Prowler.
- Azure — a Reader-level service principal.
- Google Cloud — a Viewer/Security-Reviewer-level service account.
- Microsoft 365 — an Entra app with read permissions (Directory.Read.All / Reports.Read.All).
- Google Workspace — an Admin-SDK service account, read-only, to check 2SV and admins.
What we check
Cloud (CSPM): misconfigurations, open buckets, encryption, overly broad IAM, logs. Identity (ITDR): MFA/2SV coverage, admins without MFA, too many super-admins, stale guest accounts. It all rolls up into the same 0–100 score and the same compliance report as the rest of your assets.
Easy connection — like any major provider
In the "☁️ Cloud & Identities" panel you pick a provider, paste the credentials (with a precise setup hint), and click "Scan." A new provider enters the registry, gets a status and a score, and you can re-run a scan in one click — no SSH, no manual env files.