Founder-led AI governance, built for MSP workflows

ShadowLock was founded by a cybersecurity product leader with years of experience building security products for MSPs, including helping lead a managed security platform that protected more than 2 million endpoints. It is one product, shaped around the partner, organization and device model that MSPs already run on.

Why ShadowLock exists

AI adoption moved faster than the controls around it

Employees adopted generative AI in months. The controls that are supposed to govern where company data goes were designed for email, file shares and sanctioned SaaS, and they do not see a paste into a browser tab, a desktop AI client installed without a ticket, or an OAuth consent granted to an AI app inside a Microsoft 365 tenant.

The result is a gap MSPs get handed by default. A client asks whether their staff are putting customer records into AI tools, and the honest answer is that nobody can tell. That is not a policy problem. Policies already exist and are already being ignored, because nothing measures them.

Blocking every AI tool is not a complete answer either. It can push usage toward unmanaged devices, eliminate legitimate productivity gains, and still leave IT without a practical governance model. What is missing is the middle: see what is actually being used, decide per client what is allowed, stop the specific data that must not leave, and prove to a client or an auditor what happened. ShadowLock is built to be that layer, and nothing else.

Who builds it

A security product background, applied to one problem

ShadowLock is built around direct experience developing cybersecurity products for the MSP channel, including a leadership role on a managed security platform protecting more than 2 million endpoints. That experience shaped the design decisions here: what an agent can and cannot safely do on a client endpoint, how MSPs need to manage policy across many tenants, and how quickly a tool gets abandoned when onboarding takes a day instead of ten minutes.

ShadowLock is founder-led, which keeps product decisions close to the MSPs actually using it. There is one platform, one deployment story, and a direct path from partner feedback to product changes.

What we cover

Three places company data reaches AI

Scope is deliberately narrow. These are the three surfaces employees actually use, and each one needs a different control.

AI apps on the endpoint

Desktop AI applications installed on managed Windows machines. ShadowLock inventories what is there, and can block execution at the file-system level rather than only logging that it ran.

AI in the browser

The AI sites employees use, the AI browser extensions they install, and what leaves with them. Sensitive data is classified on the device, so a paste or upload can be blocked before it reaches the tool.

Microsoft 365 OAuth access

The AI applications employees have granted standing access to a client tenant. An OAuth consent is not a login: it persists until somebody revokes it, and it is invisible unless the tenant is enumerated for it.

Built for the MSP model

The multi-tenancy is the product, not a portal on top of it

Plenty of security tools can be sold to an MSP. Fewer are built the way one operates. ShadowLock assumes from the data model up that you manage many clients under one roof:

  • Partner, organization, device. Three tiers, matching how your customer base is actually structured. A client org is not a workaround using tags or groups.
  • Cascading policy. Set a standard once at the partner level and it applies everywhere. Override it for one client, or one machine, without unpicking the standard.
  • RMM deployment. Silent install through the RMM you already run, with the browser extension force-installed by the agent so there is no per-user step.
  • Client-ready reporting. Executive summaries you can put in front of a client in a QBR without rebuilding them in a spreadsheet first.
  • Per-device billing. Billed on managed devices across your whole book, so volume compounds across clients instead of resetting per tenant.

Security and trust

Check the architecture rather than take our word for it

A tool that watches employee activity has to be able to answer hard questions about its own data handling. The full security architecture is published in the Trust Center, including the parts that are not flattering, such as where ShadowLock does not yet hold a certification a buyer may require.

Classification happens on the device

Prompt text, clipboard contents, and file bytes are never transmitted to ShadowLock. Only the classification result is sent, such as an indication that an API key was detected.

The architecture is published, not summarised

The full security architecture is a public document: data inventory, encryption, endpoint privilege model, and shared responsibility.

Tenant isolation and access control

Every query is scoped to the authenticated partner and organization. Administrative actions are written to an append-only audit log.

Retention and sub-processors are stated

Event and audit data is retained for 365 days by default, configurable per organization, then purged server-side. Every sub-processor is named.

How we operate

What you are actually signing up to

US-based

Built and operated in the United States. The application and its database run in a US region.

Founder-led

Product, engineering, and partner feedback stay closely connected. There is no tiered handoff between a demo and the people building the product.

Built for MSPs, not adapted for them

Multi-tenancy, policy inheritance, and per-device billing are the data model, not a partner portal added later.

Month-to-month

No annual commitment to get started, no minimum seat count. Cancel when it stops earning its place.

Trial without a sales process

Start a 14-day free trial and deploy to a real tenant yourself. No discovery call, no gated demo, no pilot agreement.

MSP pricing

Per device, per month, with volume tiers. Partner pricing is provided directly to MSPs as a wholesale rate designed for resale within your managed service.

We are still building

The product ships continuously, and the roadmap is influenced by partners

ShadowLock is under active development. The AI tool landscape changes every few weeks, so the detection catalogue, the enforcement surfaces and the compliance mappings are maintained rather than shipped once. New tools get added as they appear, and coverage gaps are documented rather than papered over.

Partner requests reach the roadmap directly through the feature request board inside the dashboard. Partners can submit requests, vote on priorities, and follow their status. If something you need is missing, we will give you a straight answer about whether it is planned.

Ready to see what AI use looks like in your client base?

Deploy to one tenant and look at the data. No sales call required.