# ShadowLock > ShadowLock is the shadow AI detection and AI governance platform for MSPs and IT teams. It gives complete visibility into unauthorized AI tool usage across every endpoint, blocks sensitive data before it reaches ChatGPT, Claude, or Gemini, and produces audit-grade logs that map to SOC 2, HIPAA, and GDPR controls. ShadowLock combines a Windows endpoint agent and a managed Chrome/Edge browser extension to detect AI tool usage at the layers where it actually happens: browser, desktop, and clipboard. Content classification runs locally on the endpoint; clipboard content never leaves the device. The platform is multi-tenant by design with a partner → organization → device hierarchy built for MSPs serving multiple clients. ## Product - [Shadow AI Detection](https://shadowlock.io/features/shadow-ai-detection): Detection of every unauthorized AI tool — browser-based, desktop, signed-in or anonymous — across every managed endpoint - [Shadow AI Discovery](https://shadowlock.io/features/shadow-ai-discovery): One-time inventory of every AI tool, browser extension, and Microsoft 365 AI OAuth grant already in use, before ongoing detection begins - [AI Governance Platform](https://shadowlock.io/features/ai-governance): Complete AI governance platform with visibility, policy enforcement, vendor inventory support, and audit logging - [AI Data Loss Prevention](https://shadowlock.io/features/ai-data-loss-prevention): Endpoint-based AI DLP that classifies content on paste and blocks sensitive data from reaching AI tools - [AI Prompt Protection](https://shadowlock.io/features/ai-prompt-protection): Detects sensitive data typed into ChatGPT, Claude, and Gemini and redacts it from the request before the model receives it - [AI Data-Sharing Control](https://shadowlock.io/features/ai-data-sharing-control): Detects whether each AI tool's train-on-my-data setting is enabled and blocks prompts until it is switched off - [Browser AI Lockdown](https://shadowlock.io/features/browser-ai-lockdown): Disables built-in browser AI by enterprise policy — Gemini in Chrome, Copilot in Edge, Leo in Brave — and blocks Google's AI Mode in search - [AI Risk Reporting](https://shadowlock.io/features/ai-risk-reporting): Turns shadow-AI activity into a board-ready executive risk report, exportable to PDF and audit-ready ## Solutions - [For MSPs](https://shadowlock.io/solutions/msp): Multi-tenant AI governance for MSPs — protect every client from a single dashboard - [For Internal IT Teams](https://shadowlock.io/solutions/internal-it): Shadow-AI visibility, enforcement, and board-ready reporting for in-house IT and security teams, with no E5 license required - [Block AI Tools](https://shadowlock.io/solutions/block-ai-tools): How to block ChatGPT, Gemini, Claude, and Copilot for employees at the endpoint, browser, and Microsoft 365 tenant, while allowing the AI you approve - [AI Compliance](https://shadowlock.io/solutions/ai-compliance): AI compliance coverage for HIPAA, SOC 2, GDPR, and cyber insurance - [Healthcare](https://shadowlock.io/solutions/healthcare): Detecting and blocking shadow AI in healthcare, stopping PHI reaching unapproved AI tools and producing HIPAA audit evidence ## Pricing - [Pricing](https://shadowlock.io/pricing): Volume-tiered per-device pricing. Request the rate card on the page and it is emailed in about five minutes; 14-day free trial, no sales call required ## Comparisons - [Compare ShadowLock to seven MSP shadow AI tools](https://shadowlock.io/compare): Hub page indexing every head-to-head comparison and the alternatives roundups, with a capability matrix. Every competitor claim links to that vendor's own documentation and carries a last-verified date - [ShadowLock vs Kipling Secure](https://shadowlock.io/compare/shadowlock-vs-kipling-secure): Focused shadow AI control with M365 tenant scanning vs broad AI-native XDR - [Kipling Secure alternatives](https://shadowlock.io/alternatives/kipling-secure): Five ranked Kipling Secure alternatives for MSPs, including the option that scans the Microsoft 365 tenant and prices per device - [ShadowLock vs DefensX](https://shadowlock.io/compare/shadowlock-vs-defensx): Endpoint clipboard/data-classification vs browser-extension secure workspace for MSP shadow AI delivery - [DefensX alternative](https://shadowlock.io/alternatives/defensx): ShadowLock as an endpoint-native DefensX alternative for MSPs - [ShadowLock vs ThreatLocker](https://shadowlock.io/compare/shadowlock-vs-threatlocker): Default-deny application allowlisting vs prompt-data classification for shadow AI - [ShadowLock vs DNSFilter](https://shadowlock.io/compare/shadowlock-vs-dnsfilter): DNS-layer blocking vs endpoint AI usage and data-leak detection - [ShadowLock vs Control D](https://shadowlock.io/compare/shadowlock-vs-controld): DNS filtering vs endpoint shadow AI detection, compared layer by layer - [ShadowLock vs Conceal](https://shadowlock.io/compare/shadowlock-vs-conceal): Browser isolation vs endpoint shadow AI detection for MSP-channel buyers - [ShadowLock vs Microsoft Purview](https://shadowlock.io/compare/shadowlock-vs-microsoft-purview): Enterprise M365 E5 data governance vs focused, endpoint-native shadow AI control with no E5 requirement - [Microsoft Purview alternatives for shadow AI](https://shadowlock.io/alternatives/microsoft-purview): Six ranked Purview alternatives for shadow AI for MSPs and lean IT teams — the options that need no Microsoft 365 E5 license ## Reference - [AI Governance & Shadow AI Glossary](https://shadowlock.io/glossary): Definitions for the shadow AI, AI governance, AI DLP, and compliance terms IT teams and MSPs need to know ## Free Resources and Tools - [AI Acceptable Use Policy Template](https://shadowlock.io/resources/ai-acceptable-use-policy-template): Free, modifiable AI AUP template covering approved tools, prohibited data, monitoring, and enforcement - [AI Risk Acceptance Form Template](https://shadowlock.io/resources/ai-risk-acceptance-form): Free one-page form for MSPs to record an identified AI exposure, the business risk it creates, the recommended control, and whether the client authorized remediation or formally accepted the remaining risk - [Shadow AI Risk Calculator](https://shadowlock.io/tools/shadow-ai-risk-calculator): Free interactive calculator producing a directional shadow AI risk score and recommended next steps ## Living trackers - [AI Regulation Tracker for MSPs](https://shadowlock.io/resources/ai-regulation-tracker-for-msps): Living, primary-source tracker of AI laws creating obligations for businesses using AI — EU, US federal, state, and sector — each with the MSP liability read - [Cyber Insurance and AI Tracker](https://shadowlock.io/resources/cyber-insurance-ai-tracker): Dated, primary-sourced record of how cyber and adjacent insurance lines are changing around AI — affirmative endorsements, exclusion filings, subrogation against IT providers, and application questions. Each entry carries its source, date added, date last verified, and whether it is confirmed, reported or commentary - [Shadow AI Risk for Cyber Underwriters: A Technical Field Guide](https://shadowlock.io/resources/cyber-insurance-ai-tracker/underwriter-field-guide): Technical reference on the five AI access surfaces (browser AI sites, desktop AI applications, browser extensions, OAuth-connected AI, embedded and agentic AI), what each makes detectable, the structural blind spots none of them cover, personal vs corporate account detection, and what an organization or its IT provider can truthfully attest to - [Shadow AI Incidents](https://shadowlock.io/resources/shadow-ai-incidents): Sourced, running list of real shadow-AI incidents — data leaks, breached AI vendors, agentic-AI exploits, and enforcement actions ## Foundational guides - [What Is Shadow AI?](https://shadowlock.io/blog/what-is-shadow-ai/): Plain-English definition of shadow AI, the risks, and how to detect and stop it - [What Is AI Governance?](https://shadowlock.io/blog/what-is-ai-governance/): The four pillars of AI governance — visibility, policy, enforcement, and audit - [What Is AI Data Loss Prevention?](https://shadowlock.io/blog/what-is-ai-data-loss-prevention/): How AI DLP works and why traditional DLP cannot cover the AI threat surface - [Shadow AI vs Shadow IT: Key Differences Explained](https://shadowlock.io/blog/shadow-ai-vs-shadow-it/): How shadow AI emerged from shadow IT and where the governance playbook needs to change ## How-to and detection - [How to Detect Shadow AI: A Practical Guide](https://shadowlock.io/blog/how-to-detect-shadow-ai/): The canonical methods guide - the five layers shadow AI is detected at (network/DNS, browser, endpoint, identity/OAuth, prompt content), what each one can and cannot see, why no single layer is sufficient, and a detection checklist - [How to Detect Unauthorized ChatGPT Usage on Corporate Devices](https://shadowlock.io/blog/detect-unauthorized-chatgpt-usage/): A practical guide to detecting ChatGPT and other AI tool usage on company endpoints - [How Employees Are Leaking Sensitive Data via AI Tools](https://shadowlock.io/blog/employees-leaking-data-ai-tools/): The patterns of AI data leakage and what works to stop it without breaking productivity - [Shadow AI Examples: How Employees Use Unauthorized AI at Work](https://shadowlock.io/blog/shadow-ai-examples/): Real-world department-by-department scenarios of AI data leakage ## Frameworks and checklists - [AI Governance Framework: Step-by-Step Guide](https://shadowlock.io/blog/ai-governance-framework/): A six-component framework for building an AI governance program from scratch - [AI Governance Checklist for IT and Security Teams](https://shadowlock.io/blog/ai-governance-checklist/): Eighteen items mapped to SOC 2, HIPAA, and GDPR controls - [How to Build an AI Acceptable Use Policy](https://shadowlock.io/blog/ai-acceptable-use-policy/): Structure, common mistakes, and rollout pattern for AI AUPs ## Compliance and regulation - [AI Data Leakage and SOC 2 Compliance](https://shadowlock.io/blog/ai-data-leakage-soc2-compliance/): How shadow AI creates SOC 2 gaps under CC6.1, CC7.2, CC9.2 — and how to close them - [HIPAA and AI Tools](https://shadowlock.io/blog/hipaa-ai-tools-compliance/): What healthcare organizations need to know about PHI exposure to AI tools - [GDPR and Employee AI Use](https://shadowlock.io/blog/gdpr-employee-ai-use/): The specific GDPR articles that apply to employee AI use and the compliance pattern that works - [Cyber Insurance and AI](https://shadowlock.io/blog/cyber-insurance-ai-requirements/): The AI questions appearing on cyber applications and AI supplements, where each is documented, and how to prepare answers you can substantiate ## Buyer's guides - [Best Shadow AI Detection Tools for Enterprise [2026]](https://shadowlock.io/blog/best-shadow-ai-detection-tools/): Ten named platforms compared by detection layer, enforcement, MSP fit, and pricing, with every capability linked to the vendor's own documentation and a disclosure that ShadowLock publishes the guide - [Best AI Governance Platforms for Enterprise [2026]](https://shadowlock.io/blog/best-ai-governance-platforms/): Comparison of leading AI governance platforms - [Best AI DLP Tools [2026]](https://shadowlock.io/blog/best-ai-dlp-tools/): Comparison of AI-specific DLP platforms - [Best AI Governance Tools for MSPs [2026]](https://shadowlock.io/blog/best-ai-governance-tools-for-msps/): Multi-tenant AI governance platforms for MSP delivery - [AI Compliance Tools for HIPAA, SOC 2, and GDPR [2026]](https://shadowlock.io/blog/ai-compliance-tools-hipaa-soc2-gdpr/): Comparison of AI compliance platforms by framework coverage ## Statistics and research - [State of Shadow AI 2026 (Flagship Report)](https://shadowlock.io/reports/state-of-shadow-ai-2026): ShadowLock's annual synthesis of published shadow AI research on adoption, leakage, detection methodology, and compliance pressure, drawing on Gartner, Microsoft, Cyberhaven, Netskope, IBM, and NIST. Every statistic links to its publisher; the analysis is ShadowLock's. Contains no first-party telemetry - [Shadow AI Statistics 2026 (Running Index)](https://shadowlock.io/blog/shadow-ai-statistics-2026/): Granular running record of individual shadow AI statistics, refreshed quarterly ## MSP-specific - [MSP AI Governance Sales System](https://shadowlock.io/resources/msp-ai-risk-assessment-kit): How an MSP sells AI governance to clients, as a repeatable five-step system: start the conversation with the pressure the client already feels, prove their exposure with a free read-only AI risk assessment (up to ten machines, no admin rights, nothing installed), sell one recurring Managed AI Governance service with per-device economics, put the rules in a written AI acceptable-use policy backed by enforcement, and get a decision. Includes copyable outreach and sales language, a sample AI Exposure report, and four downloadable assets: a co-brandable education deck, an assessment runbook, a client leave-behind, and an MSP close kit - [How to Price Managed AI Governance](https://shadowlock.io/resources/msp-ai-governance-revenue-playbook): MSP pricing guidance for one recommended offer — a free AI risk assessment as the door opener, a one-time onboarding fee, and managed AI governance at roughly $3-$5 per device per month with a quarterly review included. Includes worked example economics, vertical positioning, and objection handling. Figures are resale guidance for the partner's own rate card, not prices ShadowLock sets - [How MSPs Can Manage AI Risk Across All Their Clients](https://shadowlock.io/blog/msp-ai-risk-management/): Operational pattern for delivering AI governance as a managed service - [MSP AI Compliance Checklist](https://shadowlock.io/blog/msp-ai-compliance-checklist/): The controls MSPs roll out across every client - [AI Governance as an MSP Service](https://shadowlock.io/blog/ai-governance-msp-service/): How MSPs package, price, and sell AI governance as a service line ## Company - [About ShadowLock](https://shadowlock.io/about): Founder background, why ShadowLock exists, what it covers, and how the company operates - [Editorial Standards](https://shadowlock.io/about/team): How ShadowLock content is produced, what claims are based on, and the sources cited - [Security & Trust Center](https://shadowlock.io/security): Full security architecture - what ShadowLock collects and never collects, tenant isolation, encryption, sub-processors, retention, personnel access, and the 72-hour breach notification commitment - [Contact](https://shadowlock.io/contact): Get in touch with ShadowLock