Airlock Digital Application Control: In-Depth Review & Analysis

Airlock Digital Application Control is a pure-play application allowlisting platform covering Windows, macOS, and Linux, deployable as vendor-hosted SaaS or fully on-premises, including air-gapped environments, with a single agent and a single SKU.

Last updated on Sep 30, 2026
Joel Witts Written by Joel Witts
Craig MacAlpine Technical Review by Craig MacAlpine
Airlock Digital Logo
5.0
Editor's Score

Expert Insights Verdict

Airlock Digital Application Control is a pure-play application allowlisting platform covering Windows, macOS, and Linux, deployable as vendor-hosted SaaS or fully on-premises, including air-gapped environments, with a single agent and a single SKU. Airlock was founded in Adelaide in 2013 by practitioners who had run allowlisting programs on earlier-generation tools, and the product reads as a direct response to the reasons those programs failed: policy that is brittle at scale, and exception handling that buries the help desk. That practitioner DNA persists in the company’s structure: co-founder David Cottingham chose to step back from leading the business and into product leadership, with a dedicated CEO, Kevin Dunne, brought in to run the company, and the product-first orientation shows in the design decisions below.

Strengths
Trust rules combine publisher certificates, SHA-256 hashes, and metadata rules that stack up to five criteria, including path, parent process, and security group.
Approvers grant a time-limited exception session instead of approving individual files, and the endpoint returns to deny-by-default when the session expires.
Self-service exceptions give developers a logged, local exception path, restricted by security group, with blocklists still enforced.
Trust Builder recommends policy from observed execution data, in either recommend-and-review or fully automatic mode.
The enforcement readiness report uses audit-mode data to show which devices would see blocks before you switch to enforcement.
Every policy change is versioned and attributed, history is kept indefinitely, and everything exports to a SIEM.
Deploys as SaaS or on-premises with feature parity, including air-gapped environments and offline exceptions.
One SKU, priced per endpoint per year, with all features included.
Cautions
The demo ran in Airlock's hosted lab on a single Windows VM, so scale, Linux enforcement, and reporting depth weren't shown.
The "10x less memory" claim comes from a comparison of agent footprints that Airlock compiled itself, rather than being an industry benchmark.
During an exception session, whether approved or self-service, anything not on the blocklist will run. Prevention depends on the security team reviewing session activity afterwards.
Trusted installer rules automatically trust everything a trusted process produces, compiler output included, so rules for developer toolchains need tight scoping.
Mac rules don't support domain or cloud security group criteria yet. Entra ID group support is on Airlock's roadmap.
Pricing is quote-based through the channel.

Platform Overview

The platform’s defining characteristic is that it treats allowlisting as an ongoing operational process rather than a deployment project. Trust can be expressed along a spectrum from strict file hashes through publisher certificates to metadata rules stacking up to five criteria, and the rollout path runs from a learning mode through a data-driven readiness report into deny-by-default enforcement. The strongest material in the demonstration was the exception loop: a blocked user requests a time-bounded exception with a stated reason, an approver grants a temporary audit-mode exception session rather than a permanent rule, and the endpoint returns to deny-by-default when the window closes.

The clearest beneficiaries are development teams: self-service exceptions and trusted process chains let developers keep working inside enforcement without breaking their output, a population most products in this category simply fail.
Buyers should be clear about what the product is. Enforcement decisions are made on file metadata, certificates, paths, and process lineage at execution time. This is preventative execution control, and it is deep and well-engineered, but it is not behavioral detection; Airlock positions EDR as a complementary layer, with CrowdStrike Falcon integrated directly into the console.

Fast Facts

Headquarters
Adelaide, Australia, with US operations
Founded
2013, by David Cottingham and Daniel Schell
Ownership
Private; strategic investment from CyberCX (June 2022)
CEO
Kevin Dunne (previously COO at Valimail, President at Pathlock)
Platforms
Windows, macOS, Linux, plus browser-extension control for Chrome, Firefox, and Edge
Deployment
Vendor-hosted SaaS or fully on-premises, including air-gapped environments
Compliance
NIST SP 800-53 and CMMC mappings published at airlockdigital.com/compliance; ASD Essential Eight heritage
Version reviewed
Cloud console with Enforcement Agent 7.0.0.0 (build June 2026)

Why Would You Use Airlock Application Control?

Application allowlisting fails for operational reasons, not conceptual ones. Deny-by-default is among the most effective preventative controls available, which is why it anchors the ASD Essential Eight and maps cleanly onto NIST configuration management controls, and it is also the control most organizations abandon, because the policy burden grows faster than the team’s capacity to manage it. Airlock’s entire design is aimed at that failure mode.

Deployment starts in a learning mode that blocks nothing and records every executable, script, and DLL across the estate, deduplicated to unique executions. Policy is then built from observed data, and the move to enforcement is made when the readiness report shows untrusted executions, each one a would-be block, have fallen below tolerance. Airlock quotes 45 to 60 days from deployment to enforcement as typical, with honest variance in both directions: fixed-function estates such as ATMs, running the same five things everywhere, can enforce within days, while large developer populations take longer.

Market Position

Airlock describes itself as the only pure-play application control vendor of consequence, and its account of the competitive field, given candidly during the demonstration, matches ours. Carbon Black App Control (the former Bit9, now under Broadcom) is the legacy incumbent it displaces. Microsoft AppLocker and App Control for Business are what enterprises try first because they are included with supported Windows editions, although enterprise management may require additional tooling; Microsoft itself describes AppLocker as a defense-in-depth feature and recommends App Control for Business where robust threat protection is the requirement. ThreatLocker is the loudest name in the category and deserves a functional comparison rather than a channel one: its Ringfencing controls what approved applications may touch across files, registry, and network, and it packages allowlisting with elevation and network control in a broader platform, sold predominantly through MSPs and MSSPs. Airlock reports rarely meeting it in large enterprise deals, though prospects frequently evaluate the two side by side. Trellix Application Control appears occasionally. CrowdStrike and the EDR vendors are positioned as complements rather than competitors, and Falcon process lookups are linked directly from the Airlock console.

The customer base weights toward regulated and operational-technology-heavy sectors: financial services, healthcare, manufacturing, energy, government, and education. A Forrester TEI study commissioned by Airlock models 224% ROI over three years for a composite $10bn organization with 20,000 endpoints, built on four customer interviews; the figures are illustrative rather than independently validated. The Agentic AI Control & Governance capability previewed at Black Hat USA 2026, which extends the same policy engine to govern what AI agents may do on endpoints, is expected in Q3 2026 and signals where the platform is heading, but it was not demonstrated and does not factor into this assessment.

Use Cases

Building trust without boiling the ocean

Every execution in the estate is recorded with full context: file metadata, publisher, path, user, and the parent and grandparent process lineage, with VirusTotal-backed reputation presented alongside as Airlock Intelligence. From that data, trust is assigned at whatever precision fits the workload. Publisher certificates, validated on the endpoint, are the workhorse; hashes remain for static estates; metadata rules handle unsigned or homegrown software by stacking up to five criteria. A fourth mechanism, the trusted installer, trusts a deployment channel such as Configuration Manager, Intune, or Jamf, or a named process such as a developer’s compiler, so that everything arriving through it is trusted automatically; trust inherited this way is powerful and needs deliberate scoping, particularly for compiler rules (see Cautions). Metadata rules can also elevate a matched process to run with administrative privileges, which can reduce the need for standing local-admin rights for applications such as AutoCAD without elevating the user’s session; Airlock does not position this as a replacement for privileged access management.

Airlock bulk add

Assisted policy building

Trust Builder addresses teams new to application control. Pointed at a policy group, it analyzes observed executions and either recommends trust rules for review or applies them automatically, with thresholds for minimum unique endpoints, event counts, and analysis period, and validation flags showing that a publisher or path is commonly trusted across Airlock’s base. Airlock’s framing is that customers should start in recommendation mode and graduate to automatic once they trust the output, leaving only unsigned homegrown applications for manual rules. Asked what drove the feature, Airlock said it is aimed at newcomers who arrive wanting to build a perfect policy on day one, when the workable approach is incremental.

Enforcement and the exception loop

With a device in enforcement, an untrusted execution is blocked at launch and the user sees a configurable notification: nothing at all, a custom message with embedded links, or a request-exception dialog carrying a free-text reason and a duration menu that the administrator defines. The request lands in the console with hostname, user, IP, blocked file, publisher, and reputation attached, and an approver grants or denies it. On approval, the endpoint checks in within about a minute and enters a temporary audit-mode exception session for the granted window, in which everything the user runs is recorded but not blocked, except for blocklisted items, which remain hard-blocked throughout. When the window expires, deny-by-default resumes. Security can then review everything the user ran and convert the session’s evidence into a proper rule, typically a publisher approval scoped to a group. Blocklists sit above all allowlists and are aimed at living-off-the-land binaries: tooling such as InstallUtil or MSBuild that ships under trusted Microsoft certificates but has no business running for most users.

Self-service for developers and power users

Self-service replaces the request-and-wait loop for users who can justify it. Membership of a designated security group exposes a begin-exception option directly in the block dialog: the user records a reason, selects a duration, and starts the session locally with no approver in the path. The same blocklists apply, and the session’s full execution record flows back to the console. Airlock cites large development organizations as the heaviest users, and the design reads as a considered trade: the alternative in practice is not stricter control but broader standing rules, or developers exempted from the program entirely.

Air-gapped and disconnected estates

Fully on-premises deployment carries feature parity, and a baseline builder inventories an offline machine, every file, hash, and publisher, for import into policy without agent connectivity, supporting golden-image workflows. Endpoints need reach the server only periodically, and exceptions can be issued to fully disconnected devices through one-time pads. For operational technology and defense-adjacent estates this is a genuine differentiator over cloud-first competitors.

The Interface

The management console is a modern dark-theme web application organized into Dashboard, Baselines, Allowlists, Blocklists, Exceptions, Policies, Reporting, and Settings, with policy groups arranged as a tree carrying separate audit, enforcement, and self-service policies per platform. Individual file pages are deep, and CrowdStrike Falcon icons throughout deep-link into a Falcon process lookup for the same file. Reporting includes the enforcement readiness report and an executive report. The endpoint agent presents a local log view mirroring what the server records: action, mode, path, hash, parent process, and publisher per execution, with policy and client version visible. Policy updates ship as diffs rather than full policies, which matters at scale. The console remained responsive throughout the demonstration over a poor hotel connection.

Key Features

  • Deny-by-default execution control across Windows, macOS, and Linux executables, scripts, and DLLs, with browser-extension control for Chrome, Firefox, and Edge.
  • Four trust mechanisms: on-endpoint validated publisher certificates, SHA-256 hashes, metadata rules stacking up to five criteria, and trusted installer channels covering deployment tools and named processes.
  • Process-level privilege elevation on rule match, which can reduce the need for standing local-admin rights without elevating the user session; not positioned as a PAM replacement.
  • Trust Builder recommendation engine with configurable thresholds and optional fully automatic policy generation.
  • Audit-to-enforcement pipeline with deduplicated execution analytics, bulk-add workflows, and an enforcement readiness report.
  • Temporary exception workflows: user-requested, approver-granted sessions with bounded durations, and group-restricted self-service, all fully recorded.
  • Blocklists above allowlists for living-off-the-land binaries, enforced even during exception sessions.
  • Immutable policy versioning with permanent, attributed change history, webhook integrations to ticketing and chat, and SIEM export.
  • Air-gapped operation via baseline builder, golden-image import, and one-time-pad offline exceptions.
  • CrowdStrike Falcon integration with in-console process lookups, plus Splunk and Jamf integrations.

Pricing

Licensing is per endpoint per year on a single SKU covering the full feature set, with one agent and no modules or add-ons; new features are delivered to all customers as released. Pricing is quote-based through partners and the channel, with no published list. On Agentic AI Control & Governance, Airlock’s written response of 10 August states that packaging is not finalized but the internal expectation is that it ships within the single SKU, with general availability estimated informally at late summer or fall 2026. We note this as stated intent rather than a commitment.

Strengths And Cautions

Strengths

  • Trust is expressed along a genuine spectrum. Publisher certificates are validated on the endpoint, so a forged publisher fails the certificate chain and a legitimate update inherits trust automatically; SHA-256 hashes remain available for static estates; and metadata rules stack up to five criteria, including path, parent and grandparent process, domain or cloud security group, and minimum product version.
  • The exception workflow was demonstrated end to end and holds up. A blocked user submits a reason and a bounded duration, the approver grants a temporary audit-mode exception session rather than a file approval, and the endpoint drops back to deny-by-default at expiry. Approving a session rather than an executable avoids the DLL-by-DLL approval chains that make traditional allowlisting unworkable.
  • Self-service exceptions give developers and power users a local, logged exception path, restricted by security group membership, with blocklists still enforced during the session and every execution recorded for later review.
  • Trust Builder generates policy recommendations from observed execution data, with configurable thresholds and a choice of recommend-and-review or fully automatic operation, flagging publishers and paths as commonly trusted for validation.
  • The enforcement readiness report reframes the switch to enforcement as a data question: untrusted executions recorded in audit mode are, in effect, simulated blocks, and the report lists which devices fall under a chosen threshold over a chosen period.
  • Every policy change increments an immutable version with full attribution. There is deliberately no rollback button; reverting is itself a recorded forward change, history is retained indefinitely, and everything is exportable to a SIEM.
  • Deployment flexibility is unusual: vendor-hosted SaaS or fully on-premises with feature parity, air-gapped support through a baseline builder that inventories an offline machine for import, and offline exceptions through one-time pads.
  • Commercially simple: per endpoint per year, one SKU, one agent, all features included, with new capabilities delivered to all customers.

Cautions

  • The demonstration ran in Airlock’s own hosted lab against a single Windows VM. Scale behavior, Linux enforcement, and reporting depth were described rather than shown.
  • The performance claim is best read as agent footprint. Airlock’s written follow-up supplied a vendor-compiled comparison from public documentation: its agent at 20–50MB RAM with a 9MB native C++ binary, no dependencies and no reboot, against Carbon Black App Control at 50–1000MB and ThreatLocker at 200–800MB with a reboot required. That substantiates the “10x less memory” claim; it is not an independent performance benchmark, and largest-deployment endpoint counts were not provided.
  • An approved request places the endpoint into a temporary audit-mode exception session for the granted window: everything the user runs that is not blocklisted will execute. Visibility is retained, but prevention is deferred, and the model depends on the security team actually reviewing session activity afterwards.
  • Self-service deliberately widens the exception surface. Scoping by security group and persistent blocklists contain it, but the trust decision moves to the user for the duration of the session.
  • Trusted installer rules confer inherited trust: everything produced by a trusted process, compiler output included, is trusted automatically. Operationally valuable, and also a meaningful loosening if scoped carelessly; developer toolchain rules in particular need tight scoping to named processes, groups, and paths.
  • macOS rule criteria lag Windows: domain and cloud security groups are not available in Mac rules. Airlock’s written response schedules Entra ID group support for the mid-August 2026 minor release; organizations with substantial Mac estates should verify parity at evaluation.
  • Pricing is quote-based through the channel with no published list, and the statement that Agentic AI Control & Governance will ship inside the existing SKU came from pre-sales knowledge of an unreleased product rather than a commercial commitment.

Our Thoughts

The category’s central problem has never been whether deny-by-default works; it is whether an organization can live with it. Judged against that, the demonstration was persuasive where it most needed to be. The exception loop, block, reasoned request, bounded session, review, durable rule, is the difference between allowlisting as a control and allowlisting as a help desk fire, and approving sessions rather than files is the specific mechanism that breaks the DLL-by-DLL approval spiral that killed earlier-generation deployments.

The architecture story largely holds up, correctly framed. Validating certificates on the endpoint instead of maintaining an ever-growing local hash database is the plausible basis for a light agent, and Airlock’s written follow-up substantiates the footprint comparison from public documentation: a 9MB native binary using 20–50MB of RAM against competitors measured in hundreds of megabytes with reboots required. What it does not establish is measured performance at scale, and largest-deployment endpoint counts remain unanswered.

The audit-first construction of the allowlist, built brick by brick from observed execution data rather than declared upfront, is the right approach for large environments, and Trust Builder’s guided recommendations address the category’s other classic failure: misconfiguration by teams new to allowlisting, who otherwise write over-broad rules to get finished. Guardrails that prevent a bad initial policy are worth as much as features that enrich a good one.

The honest trade in the design is that friction relief is purchased with bounded windows of reduced prevention. An approved request or self-service exception is a temporary audit-mode exception session in which anything not blocklisted runs. Airlock’s counterweights, blocklists that never lift, group-scoped self-service, and complete session recording, are the right ones, but the model assumes someone reviews the record. Organizations without that operational discipline will erode the control quietly.

We would also caution against the behavior-aware framing that occasionally attaches to this category. Airlock’s enforcement is execution control on file, certificate, path, and process-lineage attributes, with context-rich telemetry. That is what it should be; buyers wanting runtime behavioral detection should plan for EDR alongside, which is precisely how Airlock positions the CrowdStrike relationship.

Summary

Airlock Digital Application Control is the most operationally credible implementation of application allowlisting we have reviewed in this category. The trust model spans hash-strict to workflow-flexible, the path from audit to enforcement is data-driven, and the exception machinery addresses the precise reasons these programs historically fail. Claims around performance at scale remain to be verified, and the exception model demands review discipline from the buyer.

Best for: mid-market and enterprise organizations with internal security teams, particularly in regulated, government, and OT-heavy sectors, seeking deny-by-default execution control that can be rolled out incrementally and run sustainably, including in air-gapped environments.

Look elsewhere if: you are an MSP or small team seeking a bundled endpoint suite, in which case ThreatLocker’s packaging may fit better; your requirement is behavioral threat detection rather than execution control, which is EDR territory; or a Windows-only estate with strong Microsoft licensing may justify attempting AppLocker or App Control for Business first, accepting the management overhead.

Endpoint Security Resources

Further reading on endpoint security from Expert Insights — buyers' guides, comparison articles, and platform-specific shortlists.

Written By Written By
Joel Witts
Joel Witts Content Director

Joel is the Director of Content and a co-founder at Expert Insights; a rapidly growing media company focused on covering cybersecurity solutions.

He’s an experienced journalist and editor with 8 years’ experience covering the cybersecurity space. He’s reviewed hundreds of cybersecurity solutions, interviewed hundreds of industry experts and produced dozens of industry reports read by thousands of CISOs and security professionals in topics like IAM, MFA, zero trust, email security, DevSecOps and more.

He also hosts the Expert Insights Podcast and co-writes the weekly newsletter, Cyber Weekly. Joel is driven to share his team’s expertise with cybersecurity leaders to help them create more secure business foundations.

Tested by Tested by
Craig MacAlpine CEO and Founder

Craig MacAlpine is CEO and Founder of Expert Insights. Before founding Expert Insights in August 2018, Craig spent 10 years as CEO of EPA Cloud, an email security provider that rebranded as VIPRE Email Security following its acquisition by Ziff Davis, formerly J2Global (NASDAQ: ZD) in 2013.

Craig is a passionate security innovator with over 20 years of experience helping organizations to stay secure with cutting-edge information security and cybersecurity solutions.

Using his extensive experience in the email security industry, he founded Expert Insights with the singular goal of helping IT professionals and CISOs to cut through the noise and find the right cybersecurity solutions they need to protect their organizations.