Airlock Digital Partner Australia

Decide what can run. Block everything else.

Airlock Digital brings preventative endpoint security back to a simple principle: trust should be explicit. Vectra helps organisations deploy and operate Deny by Default application control across Windows, macOS and Linux—supporting Essential Eight maturity, reducing malware execution and giving security teams tighter control over software, browser extensions, privilege and emerging AI agents.

SeeUnderstand what applications, files, scripts and supported browser extensions are executing.
Define trustBuild organisation-approved policy around what is permitted to run.
EnforceMove from audit visibility to Deny by Default execution control.
Manage changeHandle software deployment, exceptions and privilege without opening the whole endpoint.
Extend to AIGovern supported agentic applications and the actions autonomous agents attempt.
Australian-foundedPurpose-built application control with global deployment
Essential Eight alignedDesigned to support Application Control through Maturity Level 3
IRAP assessedIndependent IRAP assessment completed at PROTECTED level in 2026
Cross-platformWindows, macOS and Linux endpoint enforcement
Preventative Endpoint Security

EDR asks what happened. Application control decides whether it can happen at all.

Endpoint detection and response remains essential, but it is designed to detect and respond to malicious behaviour. Airlock takes a different approach: define the software, scripts and execution patterns the organisation trusts, then block execution outside those boundaries.

That makes application control complementary to EDR rather than a replacement for it.

Airlock is strongest when the organisation wants explicit control over what is allowed to execute—not another probability score about whether a file might be malicious.

Deny by DefaultOnly organisation-approved software, files, scripts and processes are permitted to execute under enforced policy.
Granular trustTrust can be defined using file, path, publisher, parent process and contextual metadata.
Execution visibilitySee what is actually running and use that evidence to build and maintain policy.
Controlled exceptionsTemporary and rule-based workflows support legitimate change without permanently widening policy.
Layered securityAirlock can sit alongside EDR, SIEM, identity and IT-management platforms.
Airlock Digital Platform

Application control has moved beyond a static whitelist.

The current Airlock platform combines Deny by Default enforcement with execution context, guided trust, application-level elevation, browser extension control and operational workflows designed for enterprise environments.

Application Allowlisting

Define trusted execution

Allow approved applications, scripts and files to run while blocking unknown or unauthorised execution by default.

Application Context

Understand what is running

Group related execution into recognisable application views including files, publishers, dependencies and runtime relationships.

Trust Builder

Reach enforcement faster

Turn observed execution patterns into guided trust recommendations while keeping policy decisions administrator controlled.

Elevation Control

Elevate the application, not the user

Give approved applications administrative-equivalent privileges without broadly elevating the user or session.

Browser Extension Control

Control the browser layer

Allow trusted Chrome, Edge and Firefox extensions while preventing unapproved or modified extensions from running.

Trusted Installer

Keep deployment moving

Support approved enterprise software deployment chains without manually trusting every file produced during installation.

Essential Eight Application Control

Designed around one of the Essential Eight’s core preventative controls.

Application Control is one of the Australian Signals Directorate’s Essential Eight mitigation strategies. Airlock Digital is designed to help organisations implement and maintain that control across increasingly demanding maturity levels while retaining organisation-defined trust.

Airlock states that its platform is tailored to help customers align with Application Control through Maturity Level 3. Final maturity depends on implementation, scope and the organisation’s wider control environment.

WorkstationsApply application control to endpoints and restrict execution to the organisation-approved set.
ServersExtend control into applicable internet-facing and other server environments as maturity requirements increase.
Scripts & installersControl executables, software libraries, scripts, installers and other relevant file types.
DriversControl driver execution and support the Microsoft vulnerable-driver blocklist requirements.
Event visibilityCentral execution logging supports analysis and integration into broader SIEM workflows.
Built for Real Environments

Security controls only work if operations can live with them.

The historic criticism of allowlisting was operational friction. Airlock’s current platform is increasingly focused on making Deny by Default practical to deploy, maintain and change at enterprise scale.

Audit to enforcement

Build the baseline first

Observe actual execution and progressively move policy groups into enforcement rather than using a disruptive big-bang rollout.

Policy testing

Understand the decision

Contextual policy testing helps administrators explain allow, block and audit outcomes before broad policy changes.

Exceptions

Keep the business moving

Time-bound and controlled workflows support legitimate work without permanently weakening the allowlist.

Least privilege

Reduce standing admin rights

Elevation Control lets approved applications receive needed privileges while users remain standard users.

Software deployment

Trust approved deployment chains

Trusted Installer reduces friction with enterprise deployment systems and complex Windows installer workflows.

Cross-platform

Control mixed estates

Airlock supports Windows, macOS and Linux, including use cases requiring offline or air-gapped operation.

Agentic AI Control

Trusted software can now act autonomously. That needs a new control layer.

Traditional application control answers whether an application is trusted to run. Agentic AI creates a second question: once the approved agent is running, what should it be allowed to do?

Airlock Digital is extending its preventative model into agentic activity by applying company-defined policy to commands and endpoint actions before supported AI agents execute them.

Discover agents 2026Identify supported agentic applications and understand where they are operating across endpoints.
See behaviourReview sessions, commands, policy decisions and endpoint activity instead of treating the AI application as opaque.
Define permitted actionsCreate centrally managed rules for commands and actions supported agents are allowed to initiate.
Enforce pre-executionEvaluate proposed endpoint actions against policy before execution.
Steer the agentReturn policy context or approved alternatives when an action is denied so supported agents can remain inside policy.
Government & Sensitive Environments

Independent assurance for organisations operating at higher sensitivity.

In August 2026, Airlock Digital completed an independent IRAP assessment at the PROTECTED classification level. The assessment reviewed Airlock Digital’s security controls against applicable Australian Government ISM and PSPF expectations.

This provides additional evidence for government, defence, critical infrastructure and other security-sensitive organisations evaluating the service.

An IRAP assessment is not an ASD accreditation, certification or Authority to Operate. Each organisation still needs to assess suitability for its own environment and risk profile.

PROTECTED-level assessmentIndependent assessment completed by an ASD-endorsed IRAP assessor.
ISM alignment evidenceAdditional evidence when assessing applicable Australian Government security requirements.
Government use casesRelevant to sensitive government, defence and critical-infrastructure environments.
Essential EightApplication Control remains directly relevant to Essential Eight maturity.
Airlock Digital + Vectra

Application control succeeds or fails on the implementation.

The technology can block untrusted execution quickly. The harder part is understanding the environment, building the right trust policy, moving safely into enforcement and keeping policy current as software changes.

Vectra provides the implementation and operational layer around Airlock—from proof of value through production deployment, Essential Eight alignment and ongoing policy support.

01
DISCOVERUnderstand endpoint platforms, applications, deployment tools and current application-control maturity.
02
AUDITCollect enough execution data to understand what legitimately runs in each policy group.
03
BUILD TRUSTCreate organisation-approved rules using observed execution, publishers, paths and process relationships.
04
PILOTMove selected groups into enforcement, validate business workflows and refine exceptions.
05
EXPANDProgressively extend Deny by Default across the target workstation and server estate.
06
OPERATEReview exceptions, blocked execution, policy changes and new software as an ongoing security process.
Client Outcomes

What defined execution control changes.

Block unknown execution

Prevent unapproved software, scripts and files from running even when there is no known malware signature.

Reduce ransomware paths

Remove the ability for many malicious payloads and tools to execute in the first place.

Strengthen Essential Eight

Implement a purpose-built application-control platform aligned to the maturity requirements.

Reduce admin exposure

Elevate approved applications instead of maintaining broad local administrator rights.

Control browser extensions

Prevent unapproved extensions from introducing unnecessary credential, privacy and software risk.

Improve software visibility

Understand what applications and related processes actually execute across the estate.

Protect legacy environments

Add preventative execution control where modern application options may be limited.

Prepare for agentic AI

Extend explicit trust into the commands and actions supported AI agents are permitted to perform.

Fits the Wider Endpoint Stack

Application control works best as part of layered endpoint security.

Airlock Digital FAQs

Application control without the old whitelisting baggage.

What is Airlock Digital?

Airlock Digital is an Australian-founded preventative endpoint-security platform focused on application control. It uses a Deny by Default model so only organisation-approved applications, scripts, files and processes are permitted to execute under enforced policy.

Is application allowlisting the same as application whitelisting?

Yes. Application allowlisting is the preferred modern term for what was historically called application whitelisting. The principle is the same: explicitly define trusted execution and block everything outside the approved set.

How does Airlock support the Essential Eight?

Application Control is one of the ASD Essential Eight mitigation strategies. Airlock Digital is designed around these requirements and states that the platform is tailored to help organisations align through Maturity Level 3. Actual maturity depends on implementation and the wider control environment.

Does Airlock replace EDR?

No. Airlock controls whether software and code is permitted to execute; EDR detects, investigates and responds to suspicious behaviour. Many organisations use both as complementary endpoint controls.

Can Airlock control browser extensions?

Yes. Browser Extension Control can centrally allow trusted and block unapproved extensions for supported Chrome, Microsoft Edge and Firefox environments.

What is Elevation Control?

Elevation Control allows approved applications and processes to receive administrative-equivalent privileges under policy-defined conditions without broadly elevating the user or session.

What is Trust Builder?

Trust Builder analyses execution activity within the customer environment and generates guided trust recommendations while keeping administrators in control of policy decisions.

Can Airlock control AI agents?

Airlock Digital is extending application control with Agentic Steering capabilities that can discover supported agentic applications, inspect proposed endpoint actions, apply policy before execution and return policy decisions or approved alternatives.

Has Airlock Digital completed an IRAP assessment?

Yes. Airlock Digital completed an independent IRAP assessment at the PROTECTED classification level in August 2026. An IRAP assessment is not an ASD accreditation, certification, endorsement or Authority to Operate.

Can Vectra deploy Airlock Digital?

Yes. Vectra is an Airlock Digital implementation partner and can assist with licensing, proof of value, deployment, audit baselining, policy design, enforcement rollout, Essential Eight alignment and ongoing operational support.

Airlock Digital + Vectra

Take control of what is allowed to execute.

Talk to Vectra about Airlock Digital, Essential Eight Application Control, Deny by Default deployment, browser extension control, least-privilege elevation or agentic AI governance.

Talk to Vectra →
Airlock Digital product features, platform support and release status evolve over time. Essential Eight maturity is an organisational outcome and is not guaranteed by deployment of a single product. IRAP assessment does not constitute ASD accreditation, certification, endorsement or an Authority to Operate.