Unapproved AI tools are
putting your organization at risk.

Employees are submitting customer records, credentials, and confidential documents into AI tools, leaving your organization liable.

ShadowLock is the shadow AI detection platform for MSPs and IT teams: the visibility to see it and the controls to stop it.

69%
of organizations suspect employees are using prohibited AI
Gartner, 2025
50%+
of AI use at work happens without employer approval
Salesforce
8
average AI apps in active use per organization
Netskope, 2026
100+
AI tools, services, and desktop apps detected and governed
And growing

Shadow AI is the new Shadow IT,
faster, riskier, and already everywhere.

Employees use unapproved AI with sensitive data, and most organizations have no visibility into it at all.
๐Ÿ’ฌ

Public AI Chatbots

ChatGPT, Claude, Gemini accessed via personal accounts: no enterprise contract, no DPA, no audit trail.

๐Ÿงฉ

AI Browser Extensions

Sidebar assistants and email rewriters that read content across every site employees visit, including clipboard data.

โ˜๏ธ

Embedded SaaS AI Features

Copilot and AI writing features inside approved SaaS apps, activated without any security review.

๐Ÿ’ป

Desktop AI Apps

Claude Desktop, ChatGPT app, Ollama, and LM Studio running entirely outside browser-based controls.

โŒจ๏ธ

AI Coding Assistants

GitHub Copilot, Cursor, and similar tools with broad file access. Proprietary code and credentials directly at risk.

๐ŸŽ™๏ธ

Meeting & Transcription AI

Otter.ai, Fireflies, and similar tools recording and processing internal calls, clinical discussions, and client meetings.

Everyday AI use is creating
legal, compliance, and liability exposure.

๐Ÿฅ

HIPAA & ePHI Exposure

Patient data pasted into public AI tools without a BAA in place triggers HIPAA exposure. No breach required.

HIPAA
๐ŸŒ

GDPR, CCPA & Privacy Frameworks

Customer PII processed through unapproved vendors with no DPA, no lawful basis, and no compliant transfer mechanism.

PRIVACY
๐Ÿ”’

Trade Secrets & IP Risk

Source code, contracts, and product plans submitted to public AI. Failing to control access can weaken trade secret protections.

IP RISK
๐Ÿข

MSP Liability

When a client has an AI-related incident and you had endpoint scope, the gap between "not our job" and "you should have known" is where claims live.

MSP RISK
๐Ÿ“„

Contractual Exposure

Personal-account AI tools run under consumer terms: no DPA, no BAA, no incident notice obligation. The protection you assumed doesn't exist.

CONTRACT
๐Ÿ”

Incident Response Blind Spots

Without prior visibility you can't answer which tool, which account, or what data was involved, breaking triage, notifications, and defensibility.

DEFENSIBILITY

Three layers of coverage.
One place to manage it all.

ShadowLock covers the full AI surface: browser, desktop app, and cloud tool, without enterprise-level deployment complexity or dedicated security engineering.

01
๐Ÿ–ฅ๏ธ
AGENT

Endpoint Agent

Deployed silently to Windows endpoints via your existing RMM. Monitors AI activity, scans browser extensions, and detects local AI apps. Zero user interaction.

โ†’
02
๐Ÿงฉ
EXTENSION

Browser Enforcement Layer

Self-configures once the agent is installed. Intercepts paste events and file uploads before they reach AI tools, classifies sensitive data, and enforces your policies with clear user-facing messages.

โ†’
03
โ˜๏ธ
M365 SCANNER

Microsoft 365 AI App Detection

Connects to each customer's Microsoft 365 tenant via Microsoft Graph and scans for AI apps that have been granted OAuth access: Copilot plugins, third-party AI add-ins, and other AI service principals. New connections trigger a critical alert automatically, with no endpoint required.

Every AI surface detected.
Every enforcement point covered.

๐ŸŒ

AI Website Detection & Blocking

Detects navigation to known AI domains and enforces your access policy before anything is pasted. Domain list stays current automatically.

BlockWarnAllow
๐Ÿ“‹

Sensitive Data Interception

Stops paste events and file uploads before content reaches the AI tool. PII, credentials, SSNs, and card data classified entirely within the browser.

Paste BlockUpload Block
๐Ÿงฉ

Browser Extension Scanning

Flags known AI sidebars and writing tools, plus unknown extensions with high-risk permissions that can read sensitive content on every page.

Known AI ExtensionsPermission Flags
๐Ÿ’ป

Desktop AI App Detection

Surfaces AI exposure that browser controls never reach: offline tools, local LLMs, and developer-facing apps running outside any web policy.

OllamaLM StudioLocal LLMs
๐Ÿ‘ค

Personal Account Detection

Detects personal-account AI sessions on managed devices: the blind spot that enterprise controls and web proxies never reach.

Flag PersonalBlock Personal
๐Ÿข

Multi-Organization MSP Dashboard

Cross-org risk view, alert workflows, device inventory, and policy management: everything an MSP needs to govern AI risk across all customers from one place.

MSP-FirstRMM-ReadyExport Reports

Flexible control.
At every layer.

Set allow, warn, and block policies per AI tool, per organization, and per user. Changes propagate to every online endpoint within minutes.

๐Ÿšซ
BlockPrevent the action entirely and show a user-facing explanation. Logged with full context.
โš ๏ธ
WarnPermit with a non-blocking notification. Logged with risk score for partner review.
โœ…
AllowPermit and log silently. Approved tools proceed without interruption, with a full evidence trail.
policy-config ยท Acme Corp
AI ToolSurfaceAction
ChatGPTPaste๐Ÿšซ Block
ChatGPTFile Upload๐Ÿšซ Block
ClaudeSite Accessโš ๏ธ Warn
GeminiPersonal Acct๐Ÿšซ Block
PerplexitySite Accessโœ… Allow
OllamaDesktop Appโš ๏ธ Warn

The surface is already large.
Every week it grows.

AI adoption is outpacing governance in almost every organization. Three things make waiting more expensive than acting.

01 / ALREADY DEPLOYED

The tools are already in use.

The average organization already has 8 AI apps in active use. Most of it is happening without approval or any governance framework.

Avg. 8 AI apps/org ยท Netskope 2026
02 / THE BLIND SPOT

Enterprise policies don't cover personal accounts.

Employees on managed devices using AI through personal accounts are completely outside your policies, your logging, and every enterprise control. It looks like personal browsing. The data exposure is not.

Personal accounts bypass all managed controls
03 / AUDITORS ARE ASKING

Governance questions are already arriving.

Security questionnaires, cyber insurance renewals, and compliance reviews now include AI governance questions. "We didn't have visibility" doesn't reduce liability. It creates it.

AI governance now appears in insurance & audit reviews

Built for the people
responsible for AI risk at scale.

๐Ÿข MSP / Partner

One Dashboard. Every Customer.

Cross-organization view of every client's AI exposure. Push policy changes to hundreds of endpoints and generate customer-ready reports, before an incident forces the conversation.

Aggregate risk scores per client, cross-org event feed
Silent deploy via any RMM in minutes
Export reports for business reviews and audits
๐Ÿ”ง IT Admin

Simple Controls. Fast Answers. Low Noise.

See which AI tools employees are using, what data they're pasting, and which extensions are risky. Configure allow/warn/block without a complex rule engine. Alerts that matter, not thousands of low-signal events.

Event timeline with risk scores per user and device
Allowlist approved tools so they're never interrupted
Device inventory with real-time online/offline status

Questions you'll be able to answer.
Questions you can't afford to avoid.

"Do you allow employees to use AI tools? Which ones are approved?"
Documented approved/blocked tool list with enforcement evidence across every endpoint.
โœ“ Answered with evidence
"How do you prevent PII or PHI from entering public AI systems?"
Paste events and file uploads containing PII, credentials, and SSNs intercepted before they reach AI tools, with every event logged.
โœ“ Answered with evidence
"Can you distinguish personal from enterprise AI account usage?"
Personal vs. managed account usage detected on every AI tool, with flagging and blocking available.
โœ“ Answered with evidence
"How do you govern AI browser extensions on employee devices?"
All Chrome and Edge extensions enumerated per endpoint, with known AI tools and high-risk permissions flagged in the dashboard.
โœ“ Answered with evidence
"Do you have logs and evidence of your AI policy enforcement?"
Every action logged with tool, surface, user, account type, and timestamp, exportable for auditors and client reports.
โœ“ Answered with evidence
"How do you handle AI tools embedded inside approved SaaS platforms?"
Embedded AI features surfaced alongside standalone tools. Nothing hides inside an approved app.
โœ“ Answered with evidence

Governance without
turning monitoring into surveillance.

Risk signals, not content. Sensitive data is classified locally and never transmitted. You get the evidence to act, without capturing what employees type or read.

๐Ÿ”

Zero Content Transmission

Sensitive data is never sent to the backend. Only the data type and a reference are logged. You know something sensitive was pasted, but not what it said.

๐Ÿ“‚

File Metadata Only

Upload events log the filename, type, and size. File contents are never read or stored, by design and not just by policy.

โŒจ๏ธ

No Keystroke Logging

Keystroke logging is explicitly out of scope, technically and legally. ShadowLock monitors AI interaction events, not what employees write.

๐ŸŒ

HTTPS / TLS Everywhere

All agent-to-backend communication is encrypted. EU deployments support EEA data residency requirements.

โฑ๏ธ

Configurable Retention

Default 90-day event retention, configurable per organization. Data lifecycle controls built in from day one.

๐Ÿ“‹

Disclosure Workflow

Partners confirm employee disclosure compliance before onboarding each organization. Consent is enforced in the deployment workflow, not just the documentation.

Simple, scalable
MSP pricing.

Pay per managed device. Volume discounts apply automatically. The more devices you monitor, the lower your per-device rate.

Estimate your cost

Drag the slider to see your monthly rate at any scale.

50
Per-device rate$1.00/device/mo
Monthly total (50 devices)$50.00/mo
DevicesRate
1โ€“99 devices$1.00/device
100โ€“249 devices$0.95/device
250โ€“499 devices$0.90/device
500โ€“999 devices$0.85/device
1000+ devices$0.80/device
Start Free Trial

No charge until your trial ends. Cancel anytime.

Stop guessing what's in your AI surface.
Start knowing.

Deploy ShadowLock in minutes via your existing RMM. Get visibility across every AI tool in your customer environments, before an incident, an audit, or a client question forces the conversation.

14-day free trial ยท Cancel anytime

โœ“ Windows 10/11 ยท Silent RMM deploy
โœ“ Zero sensitive data content transmitted
โœ“ No keystroke logging, ever
โœ“ Policy live on endpoints within 10 minutes
โœ“ Export reports for clients and auditors