#3 Product of the Day
Launched

ShadowLock

Detects and controls unapproved AI use on endpoints, browsers, and Microsoft 365 tenants.

SecurityFreemium
ShadowLock screenshot
ABOUT THE PRODUCT

About ShadowLock

ShadowLock is a shadow AI detection and governance platform for MSPs and IT teams. It is designed to give organizations visibility into how employees use AI tools and to help prevent sensitive data from being sent to unapproved services. The product focuses on AI activity across browser, desktop app, and Microsoft 365 environments, with controls that can block, warn, or allow specific actions.

The platform is built for teams that need to answer audit, compliance, and incident-response questions about AI usage. It detects navigation to known AI sites, scans browser extensions, identifies local AI apps, and checks Microsoft 365 tenants for AI-related OAuth connections and service principals. It also detects personal versus enterprise account usage, intercepts paste events and file uploads, and can redact sensitive values typed into prompts before they are sent.

ShadowLock is presented as suitable for MSPs and IT admins who manage AI risk across one or many organizations. It supports silent deployment to Windows 10/11 endpoints through existing RMM tools, and policies can be managed centrally with event logging, exportable reports, and alert workflows. The company also emphasizes privacy by design: sensitive content is classified locally, file contents are not stored, and keystroke logging is out of scope.

Key features:
- Endpoint agent for Windows devices deployed silently through existing RMM tools
- Browser enforcement layer that intercepts pastes, file uploads, and sensitive data typed into AI prompts
- Microsoft 365 AI app detection through Microsoft Graph and OAuth app scanning
- AI website detection, browser extension scanning, and desktop AI app detection
- Allow, warn, and block policy controls per tool, organization, and user
- Personal account detection and blocking for AI tools
- Exportable reports, alert notifications, and audit-ready event logs
- Privacy-oriented design with local classification and no keystroke logging

COMMUNITY DISCUSSION

Comments

0 comments
No comments yet

Be the first to start the discussion.