Define trusted execution
Let approved apps, scripts and files run, and block anything unknown or not approved by default.
Airlock Digital is Australian-founded application control built on one idea: trust should be explicit. Vectra deploys and runs its Deny by Default control on Windows, macOS and Linux. It helps you lift Essential Eight maturity and stops malware from running.
Endpoint detection and response (EDR) is still essential, but it is built to spot and respond to bad behaviour. Airlock works the other way. You define the software, scripts and processes you trust, and Airlock blocks everything else.
So application control works with EDR, not instead of it. Airlock fits best when you want firm control over what runs - not another score on whether a file might be bad.
Under enforced policy, only software, files, scripts and processes you approve can run.
Trust can be set by file, path, publisher, parent process and other context.
See what is really running and use that evidence to build and keep policy up to date.
Time-bound, rule-based workflows allow real change without widening policy for good.
Airlock sits alongside EDR, SIEM, identity and IT management tools.
The Airlock platform pairs Deny by Default enforcement with context, guided trust, elevation and browser control, plus workflows built for large estates.
Let approved apps, scripts and files run, and block anything unknown or not approved by default.
Group related files, publishers and dependencies into clear application views.
Turn what runs in your estate into guided trust advice, while admins keep the final say.
Give approved apps admin-level rights without raising the rights of the user or the session.
Allow trusted Chrome, Edge and Firefox extensions and stop unapproved or changed ones from running.
Trust approved software deployment chains without trusting every file an install creates by hand.
In August 2026, Airlock Digital completed an independent IRAP assessment at the PROTECTED level.
An ASD-endorsed IRAP assessor checked Airlock’s security controls against the ISM and PSPF. That gives government, defence and critical infrastructure buyers more evidence. It is not an ASD accreditation, certification or Authority to Operate. Each organisation must still judge if it fits its own risk.
Airlock can block untrusted code fast. The hard part is knowing the estate, building the right trust policy, moving safely into enforcement and keeping policy current as software changes.
Vectra is the implementation and operations layer around Airlock - from proof of value to production, Essential Eight alignment and ongoing policy support.
We review your endpoint platforms, apps, deployment tools and current application control maturity.
We collect enough execution data to see what really runs in each policy group.
We write approved rules from what runs, its publishers, paths and process links.
We move chosen groups into enforcement, check business workflows and refine exceptions.
We extend Deny by Default step by step across the target workstations and servers.
We review exceptions, blocked items, policy changes and new software as an ongoing process.
Airlock sets what can run. CrowdStrike Falcon finds, investigates and stops bad behaviour.
Add Airlock to a wider managed service with patching, EDR, email security and 24×7 monitoring.
Use Airlock for application control while Vectra checks the rest of your Essential Eight work.
Send Airlock events to the SOC so they can be watched, looked into and kept as evidence.
Yes. Allowlisting is the modern term for what used to be called whitelisting. The idea is the same: define what you trust and block everything else.
Application Control is one of the ASD Essential Eight strategies. Airlock states its platform is tailored to help you align through Maturity Level 3. It covers workstations, servers, scripts, installers and drivers, including the Microsoft vulnerable-driver blocklist. Your real maturity depends on how it is set up and on your other controls.
No. Airlock controls whether code may run. EDR detects, investigates and responds to suspicious behaviour. Many organisations use both.
Airlock is adding Agentic Steering. It can find supported AI agents, check the endpoint actions they propose against your policy before they run, and return the policy decision or an approved alternative.
Yes. Vectra is an Airlock Digital implementation partner. We help with licensing, proof of value, deployment, audit baselines, policy design, enforcement rollout, Essential Eight alignment and ongoing support.
Speak to us about your cyber governance and compliance requirements.