Airlock Digital brings preventative endpoint security back to a simple principle: trust should be explicit. Vectra helps organisations deploy and operate Deny by Default application control across Windows, macOS and Linux—supporting Essential Eight maturity, reducing malware execution and giving security teams tighter control over software, browser extensions, privilege and emerging AI agents.

Endpoint detection and response remains essential, but it is designed to detect and respond to malicious behaviour. Airlock takes a different approach: define the software, scripts and execution patterns the organisation trusts, then block execution outside those boundaries.
That makes application control complementary to EDR rather than a replacement for it.
Airlock is strongest when the organisation wants explicit control over what is allowed to execute—not another probability score about whether a file might be malicious.
The current Airlock platform combines Deny by Default enforcement with execution context, guided trust, application-level elevation, browser extension control and operational workflows designed for enterprise environments.
Allow approved applications, scripts and files to run while blocking unknown or unauthorised execution by default.
Group related execution into recognisable application views including files, publishers, dependencies and runtime relationships.
Turn observed execution patterns into guided trust recommendations while keeping policy decisions administrator controlled.
Give approved applications administrative-equivalent privileges without broadly elevating the user or session.
Allow trusted Chrome, Edge and Firefox extensions while preventing unapproved or modified extensions from running.
Support approved enterprise software deployment chains without manually trusting every file produced during installation.
Application Control is one of the Australian Signals Directorate’s Essential Eight mitigation strategies. Airlock Digital is designed to help organisations implement and maintain that control across increasingly demanding maturity levels while retaining organisation-defined trust.
Airlock states that its platform is tailored to help customers align with Application Control through Maturity Level 3. Final maturity depends on implementation, scope and the organisation’s wider control environment.
The historic criticism of allowlisting was operational friction. Airlock’s current platform is increasingly focused on making Deny by Default practical to deploy, maintain and change at enterprise scale.
Observe actual execution and progressively move policy groups into enforcement rather than using a disruptive big-bang rollout.
Contextual policy testing helps administrators explain allow, block and audit outcomes before broad policy changes.
Time-bound and controlled workflows support legitimate work without permanently weakening the allowlist.
Elevation Control lets approved applications receive needed privileges while users remain standard users.
Trusted Installer reduces friction with enterprise deployment systems and complex Windows installer workflows.
Airlock supports Windows, macOS and Linux, including use cases requiring offline or air-gapped operation.
Traditional application control answers whether an application is trusted to run. Agentic AI creates a second question: once the approved agent is running, what should it be allowed to do?
Airlock Digital is extending its preventative model into agentic activity by applying company-defined policy to commands and endpoint actions before supported AI agents execute them.
In August 2026, Airlock Digital completed an independent IRAP assessment at the PROTECTED classification level. The assessment reviewed Airlock Digital’s security controls against applicable Australian Government ISM and PSPF expectations.
This provides additional evidence for government, defence, critical infrastructure and other security-sensitive organisations evaluating the service.
An IRAP assessment is not an ASD accreditation, certification or Authority to Operate. Each organisation still needs to assess suitability for its own environment and risk profile.
The technology can block untrusted execution quickly. The harder part is understanding the environment, building the right trust policy, moving safely into enforcement and keeping policy current as software changes.
Vectra provides the implementation and operational layer around Airlock—from proof of value through production deployment, Essential Eight alignment and ongoing policy support.
Prevent unapproved software, scripts and files from running even when there is no known malware signature.
Remove the ability for many malicious payloads and tools to execute in the first place.
Implement a purpose-built application-control platform aligned to the maturity requirements.
Elevate approved applications instead of maintaining broad local administrator rights.
Prevent unapproved extensions from introducing unnecessary credential, privacy and software risk.
Understand what applications and related processes actually execute across the estate.
Add preventative execution control where modern application options may be limited.
Extend explicit trust into the commands and actions supported AI agents are permitted to perform.
Use Airlock to define what can execute and CrowdStrike Falcon to detect, investigate and respond to malicious behaviour.
Explore CrowdStrike EDR →Bring preventative endpoint control into a wider managed environment alongside patching, EDR, email security and 24×7 monitoring.
Explore SONAR →Use Airlock as the application-control technology while Vectra assesses the broader Essential Eight programme.
Essential Eight Services →Forward application-control events into the SOC to support monitoring, investigation and evidence requirements.
Next-Gen SIEM →Airlock Digital is an Australian-founded preventative endpoint-security platform focused on application control. It uses a Deny by Default model so only organisation-approved applications, scripts, files and processes are permitted to execute under enforced policy.
Yes. Application allowlisting is the preferred modern term for what was historically called application whitelisting. The principle is the same: explicitly define trusted execution and block everything outside the approved set.
Application Control is one of the ASD Essential Eight mitigation strategies. Airlock Digital is designed around these requirements and states that the platform is tailored to help organisations align through Maturity Level 3. Actual maturity depends on implementation and the wider control environment.
No. Airlock controls whether software and code is permitted to execute; EDR detects, investigates and responds to suspicious behaviour. Many organisations use both as complementary endpoint controls.
Yes. Browser Extension Control can centrally allow trusted and block unapproved extensions for supported Chrome, Microsoft Edge and Firefox environments.
Elevation Control allows approved applications and processes to receive administrative-equivalent privileges under policy-defined conditions without broadly elevating the user or session.
Trust Builder analyses execution activity within the customer environment and generates guided trust recommendations while keeping administrators in control of policy decisions.
Airlock Digital is extending application control with Agentic Steering capabilities that can discover supported agentic applications, inspect proposed endpoint actions, apply policy before execution and return policy decisions or approved alternatives.
Yes. Airlock Digital completed an independent IRAP assessment at the PROTECTED classification level in August 2026. An IRAP assessment is not an ASD accreditation, certification, endorsement or Authority to Operate.
Yes. Vectra is an Airlock Digital implementation partner and can assist with licensing, proof of value, deployment, audit baselining, policy design, enforcement rollout, Essential Eight alignment and ongoing operational support.
Talk to Vectra about Airlock Digital, Essential Eight Application Control, Deny by Default deployment, browser extension control, least-privilege elevation or agentic AI governance.