Doogree
OVERVIEW · GROUND ZERO

What We've Built So Far — and Why We Built It This Way

30/06/2026 · ~6 min read
StrategyArchitectureSMB

This is our baseline — "GROUND ZERO." Before we push forward with improvements, it's worth pausing to document what already exists and why each choice was made. This is the first post in a living blog that will accompany every future upgrade.

The problem: a small business faces four separate problems

A typical small-to-medium business in Israel runs a handful of computers, maybe a server, and clients with sensitive data — and faces four distinct needs: remote support, security, backup, and password management. The market solves each one separately: one remote-control tool, a second EDR vendor, a third backup solution, and a fourth vault — four subscriptions, four consoles, four accounts to manage.

And on top of all that, Israel landed Amendment 13 to the Protection of Privacy Law (effective August 2025): requirements for encryption, access control, monitoring, and incident reporting, backed by fines and personal liability. A small business simply isn't built to assemble all of this on its own.

What we chose: one product, one agent, one pane of glass

Instead of four products — a single platform. One agent that sits on the box and unifies everything into a single 0–100 score and a single compliance report:

Why this way — three founding principles

1. The keys stay with the client

We do not hold the client's secrets. A cloud-connection or identity credential stays with the client as a "reference," while the secret itself lives on their box. This is a liability-limiting guarantee that any accountant or lawyer immediately understands: a breach of us does not expose your data.

2. Hebrew-native + Amendment 13

Our compliance report maps every finding to the CIS Controls, and from there to ISO 27001 / SOC 2 / Amendment 13 — in Hebrew. No global vendor translates Israeli law into the product itself.

3. Marginal cost ≈ zero

The heavy lifting (security scans, P2P video) runs on the client's box or on free open-source engines — not on expensive compute of ours. The result: ~95% margins, and that's what lets us offer a price a small business can afford.

The rule that cuts across every competitor: no remote-control tool bundles real security inside the tool, and no security tool unifies vuln + cloud + attack-surface + compliance-score into a single pane of glass with the keys held by the client. That combined square — is empty.

Where we don't play — and that's deliberate

We do not enter the Enterprise space: massive-scale SIEM, SASE, or a SOC with a 24/7 human analyst team. That's where CrowdStrike, SentinelOne, Palo Alto, and Splunk play. Our arena is the unified SMB — and there we hold an angle no one else holds.

How we keep improving this — continuous quality control

"GROUND ZERO" isn't a finish line but a starting line. Every capability is measured and improves automatically: our code scanner runs on every commit, research agents continuously map the field, the compliance report updates with every state change on a device, and a self-integrity check verifies that all controls are truly alive. This blog documents every step.

This article describes strategy and architecture at the level of principle. It does not reveal keys, secrets, or implementation details that could aid an attacker.

← All posts