Airlock Digital implementation partner

Airlock Digital. Decide what can run. Block everything else.

Airlock Digital is Australian-founded application control built on one idea: trust should be explicit. Vectra deploys and runs its Deny by Default control on Windows, macOS and Linux. It helps you lift Essential Eight maturity and stops malware from running.

EDR asks what happened. Application control decides whether it can happen at all.

Endpoint detection and response (EDR) is still essential, but it is built to spot and respond to bad behaviour. Airlock works the other way. You define the software, scripts and processes you trust, and Airlock blocks everything else.

So application control works with EDR, not instead of it. Airlock fits best when you want firm control over what runs - not another score on whether a file might be bad.

  • Deny by Default

    Under enforced policy, only software, files, scripts and processes you approve can run.

  • Granular trust

    Trust can be set by file, path, publisher, parent process and other context.

  • Execution visibility

    See what is really running and use that evidence to build and keep policy up to date.

  • Controlled exceptions

    Time-bound, rule-based workflows allow real change without widening policy for good.

  • Layered security

    Airlock sits alongside EDR, SIEM, identity and IT management tools.

Application control has moved beyond a static whitelist.

The Airlock platform pairs Deny by Default enforcement with context, guided trust, elevation and browser control, plus workflows built for large estates.

Application Allowlisting

Define trusted execution

Let approved apps, scripts and files run, and block anything unknown or not approved by default.

Application Context

Understand what is running

Group related files, publishers and dependencies into clear application views.

Trust Builder

Reach enforcement faster

Turn what runs in your estate into guided trust advice, while admins keep the final say.

Elevation Control

Elevate the app, not the user

Give approved apps admin-level rights without raising the rights of the user or the session.

Browser Extension Control

Control the browser layer

Allow trusted Chrome, Edge and Firefox extensions and stop unapproved or changed ones from running.

Trusted Installer

Keep deployment moving

Trust approved software deployment chains without trusting every file an install creates by hand.

Government and sensitive environments

In August 2026, Airlock Digital completed an independent IRAP assessment at the PROTECTED level.

An ASD-endorsed IRAP assessor checked Airlock’s security controls against the ISM and PSPF. That gives government, defence and critical infrastructure buyers more evidence. It is not an ASD accreditation, certification or Authority to Operate. Each organisation must still judge if it fits its own risk.

Application control succeeds or fails on the implementation.

Airlock can block untrusted code fast. The hard part is knowing the estate, building the right trust policy, moving safely into enforcement and keeping policy current as software changes.

Vectra is the implementation and operations layer around Airlock - from proof of value to production, Essential Eight alignment and ongoing policy support.

  1. 01

    Discover

    We review your endpoint platforms, apps, deployment tools and current application control maturity.

  2. 02

    Audit

    We collect enough execution data to see what really runs in each policy group.

  3. 03

    Build trust

    We write approved rules from what runs, its publishers, paths and process links.

  4. 04

    Pilot

    We move chosen groups into enforcement, check business workflows and refine exceptions.

  5. 05

    Expand

    We extend Deny by Default step by step across the target workstations and servers.

  6. 06

    Operate

    We review exceptions, blocked items, policy changes and new software as an ongoing process.

Airlock fits the wider endpoint stack.

Managed IT + cyber

Airlock + Vectra SONAR

Add Airlock to a wider managed service with patching, EDR, email security and 24×7 monitoring.

Essential Eight

Application control + maturity uplift

Use Airlock for application control while Vectra checks the rest of your Essential Eight work.

Security operations

Airlock + SIEM

Send Airlock events to the SOC so they can be watched, looked into and kept as evidence.

Application control without the old whitelisting baggage.

Is application allowlisting the same as whitelisting?

Yes. Allowlisting is the modern term for what used to be called whitelisting. The idea is the same: define what you trust and block everything else.

How does Airlock support the Essential Eight?

Application Control is one of the ASD Essential Eight strategies. Airlock states its platform is tailored to help you align through Maturity Level 3. It covers workstations, servers, scripts, installers and drivers, including the Microsoft vulnerable-driver blocklist. Your real maturity depends on how it is set up and on your other controls.

Does Airlock replace EDR?

No. Airlock controls whether code may run. EDR detects, investigates and responds to suspicious behaviour. Many organisations use both.

Can Airlock control AI agents?

Airlock is adding Agentic Steering. It can find supported AI agents, check the endpoint actions they propose against your policy before they run, and return the policy decision or an approved alternative.

Can Vectra deploy Airlock Digital?

Yes. Vectra is an Airlock Digital implementation partner. We help with licensing, proof of value, deployment, audit baselines, policy design, enforcement rollout, Essential Eight alignment and ongoing support.

Start with a conversation.

Speak to us about your cyber governance and compliance requirements.