Founder-led AI governance, built for MSP workflows
ShadowLock was founded by a cybersecurity product leader with years of experience building security products for MSPs, including helping lead a managed security platform that protected more than 2 million endpoints. It is one product, shaped around the partner, organization and device model that MSPs already run on.
Why ShadowLock exists
AI adoption moved faster than the controls around it
Employees adopted generative AI in months. The controls that are supposed to govern where company data goes were designed for email, file shares and sanctioned SaaS, and they do not see a paste into a browser tab, a desktop AI client installed without a ticket, or an OAuth consent granted to an AI app inside a Microsoft 365 tenant.
The result is a gap MSPs get handed by default. A client asks whether their staff are putting customer records into AI tools, and the honest answer is that nobody can tell. That is not a policy problem. Policies already exist and are already being ignored, because nothing measures them.
Blocking every AI tool is not a complete answer either. It can push usage toward unmanaged devices, eliminate legitimate productivity gains, and still leave IT without a practical governance model. What is missing is the middle: see what is actually being used, decide per client what is allowed, stop the specific data that must not leave, and prove to a client or an auditor what happened. ShadowLock is built to be that layer, and nothing else.
Who builds it
A security product background, applied to one problem
ShadowLock is built around direct experience developing cybersecurity products for the MSP channel, including a leadership role on a managed security platform protecting more than 2 million endpoints. That experience shaped the design decisions here: what an agent can and cannot safely do on a client endpoint, how MSPs need to manage policy across many tenants, and how quickly a tool gets abandoned when onboarding takes a day instead of ten minutes.
ShadowLock is founder-led, which keeps product decisions close to the MSPs actually using it. There is one platform, one deployment story, and a direct path from partner feedback to product changes.
What we cover
Three places company data reaches AI
Scope is deliberately narrow. These are the three surfaces employees actually use, and each one needs a different control.
AI apps on the endpoint
Desktop AI applications installed on managed Windows machines. ShadowLock inventories what is there, and can block execution at the file-system level rather than only logging that it ran.
AI in the browser
The AI sites employees use, the AI browser extensions they install, and what leaves with them. Sensitive data is classified on the device, so a paste or upload can be blocked before it reaches the tool.
Microsoft 365 OAuth access
The AI applications employees have granted standing access to a client tenant. An OAuth consent is not a login: it persists until somebody revokes it, and it is invisible unless the tenant is enumerated for it.
Built for the MSP model
The multi-tenancy is the product, not a portal on top of it
Plenty of security tools can be sold to an MSP. Fewer are built the way one operates. ShadowLock assumes from the data model up that you manage many clients under one roof:
- Partner, organization, device. Three tiers, matching how your customer base is actually structured. A client org is not a workaround using tags or groups.
- Cascading policy. Set a standard once at the partner level and it applies everywhere. Override it for one client, or one machine, without unpicking the standard.
- RMM deployment. Silent install through the RMM you already run, with the browser extension force-installed by the agent so there is no per-user step.
- Client-ready reporting. Executive summaries you can put in front of a client in a QBR without rebuilding them in a spreadsheet first.
- Per-device billing. Billed on managed devices across your whole book, so volume compounds across clients instead of resetting per tenant.
Security and trust
Check the architecture rather than take our word for it
A tool that watches employee activity has to be able to answer hard questions about its own data handling. The full security architecture is published in the Trust Center, including the parts that are not flattering, such as where ShadowLock does not yet hold a certification a buyer may require.
Classification happens on the device
Prompt text, clipboard contents, and file bytes are never transmitted to ShadowLock. Only the classification result is sent, such as an indication that an API key was detected.
The architecture is published, not summarised
The full security architecture is a public document: data inventory, encryption, endpoint privilege model, and shared responsibility.
Tenant isolation and access control
Every query is scoped to the authenticated partner and organization. Administrative actions are written to an append-only audit log.
Retention and sub-processors are stated
Event and audit data is retained for 365 days by default, configurable per organization, then purged server-side. Every sub-processor is named.
How we operate
What you are actually signing up to
US-based
Built and operated in the United States. The application and its database run in a US region.
Founder-led
Product, engineering, and partner feedback stay closely connected. There is no tiered handoff between a demo and the people building the product.
Built for MSPs, not adapted for them
Multi-tenancy, policy inheritance, and per-device billing are the data model, not a partner portal added later.
Month-to-month
No annual commitment to get started, no minimum seat count. Cancel when it stops earning its place.
Trial without a sales process
Start a 14-day free trial and deploy to a real tenant yourself. No discovery call, no gated demo, no pilot agreement.
MSP pricing
Per device, per month, with volume tiers. Partner pricing is provided directly to MSPs as a wholesale rate designed for resale within your managed service.
We are still building
The product ships continuously, and the roadmap is influenced by partners
ShadowLock is under active development. The AI tool landscape changes every few weeks, so the detection catalogue, the enforcement surfaces and the compliance mappings are maintained rather than shipped once. New tools get added as they appear, and coverage gaps are documented rather than papered over.
Partner requests reach the roadmap directly through the feature request board inside the dashboard. Partners can submit requests, vote on priorities, and follow their status. If something you need is missing, we will give you a straight answer about whether it is planned.
Ready to see what AI use looks like in your client base?
Deploy to one tenant and look at the data. No sales call required.