Overview

Product video
Scalable, easy-to-manage application control and allowlisting
Airlock Digital's allowlisting model delivers measurable security outcomes by enforcing a strict Deny by Default posture, ensuring only trusted applications, scripts, and processes are permitted to execute. By preventing unauthorized code from running, organizations can significantly reduce ransomware execution risk, shrink their attack surface, and lower incident response workload.
Built for scale and operational efficiency, Airlock Digital enables security teams to strengthen endpoint protection while minimizing management overhead across large and dynamic enterprise environments.
Proactive Deny by Default Protection Enforce a true Deny by Default security model that prevents unauthorized applications, scripts, and processes from executing, stopping threats before they run and significantly reducing your attack surface.
Purpose-built for enterprise environments, Airlock Digital simplifies allowlist management with intuitive, practitioner-developed workflows that scale across large and dynamic IT and OT estates.
Highlights
- Granular Policy and Flexible Exception Control Define trusted applications at the file, path, publisher, or parent process level, with advanced exception handling and secure One-Time Password (OTP) capabilities to maintain operational continuity without compromising security.
- Enterprise Visibility and Intelligence Gain full visibility into what is running, and what has attempted to run, across endpoints, enhanced by integrated file-level intelligence to support informed policy decisions.
- Seamless Integration and Compliance Alignment Integrate with existing security ecosystems, including EDR and SIEM platforms, while supporting regulatory frameworks such as NIST, HIPAA, and PCI-DSS.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/month |
|---|---|---|
Airlock Enterprise | Please contact AWSsales@airlockdigital.com for a custom quote. | $999,999.99 |
The following dimensions are not included in the contract terms, which will be charged based on your usage.
Dimension | Cost/unit |
|---|---|
Overage | $0.01 |
Vendor refund policy
All fees are non-cancellable and non-refundable except as required by law.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
Airlock Digital Support may be contacted through or support page, https://www.airlockdigital.com/contact-us , or by emailing support.airlockdigital.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products
Customer reviews
Application allow listing has strengthened endpoint security and streamlines software approvals
What is our primary use case?
My main use case for Airlock Digital Application Control is to enforce application allow listing across our Windows endpoints so that only approved and trusted software can run. The goal was to reduce the risk of malware, ransomware, and unauthorized applications without disrupting normal business operations.
In our day-to-day work, we use it to review requests for new software, verifying that the application is legitimate and then approve it through the appropriate policy so users can run it without needing local administrator privileges. A typical example is when a business team needs a new finance or engineering application that is not already approved. Instead of giving the user elevated access or creating broad security exceptions, we validate the software, test it on a small group of machines, understand the allow list, and then deploy the policy to the required endpoint. This process has helped us maintain tighter control over our environment while still allowing business teams to get the applications they need in a structured and auditable way. Although there is some ongoing administrative effort, especially when new software versions are released or vendors frequently update their applications, the visibility and control it provides have made endpoint management much more predictable and secure.
What is most valuable?
The best features Airlock Digital Application Control offers that stand out the most for me are the application allow listing capabilities and centralized policy management, and the visibility into what is actually running across endpoints. The allow listing approach gives us much tighter control than relying only on signature-based security tools because only trusted applications are permitted to execute, which significantly reduces the risk of unauthorized software and malware. I also value having a central console where policies can be managed and applied consistently across different groups of devices, as it makes administration much easier than maintaining separate configurations on individual endpoints. Another feature I find valuable is the ability to review application activity before making policy changes, which helps us validate software and avoid disrupting users during deployments. From an operational perspective, the audit trail is useful because it provides clear records of policy changes and application approvals, making troubleshooting and compliance discussions much simpler. These features together provide a good balance between security and day-to-day manageability without making endpoint administration overly complicated, although none of them completely eliminate the need for ongoing policy maintenance, especially in environments where applications are updated frequently.
What needs improvement?
Airlock Digital Application Control is a solid product, but there are a few areas where it could be improved. The biggest challenge is the ongoing effort required to maintain allow listing policies in the environment where applications are updated frequently. While the initial deployment can be planned carefully, keeping policies current as vendors release new versions requires regular attention, and that can become time-consuming for IT teams managing a large number of endpoints. I would appreciate seeing more automation around approving trusted software updates and better integrations with common software deployment and vulnerability management tools to reduce manual effort. Reporting is another area that could be enhanced, particularly with more customizable dashboards and easier ways to generate compliance and operational reports for different audiences. From an administration perspective, some troubleshooting workflows could be more intuitive, especially when identifying why an application was blocked or determining the exact policy responsible for the decision. These limitations have not been significant enough to outweigh the benefits of the product, but addressing them would make day-to-day management more efficient, reduce administrative overhead, and improve the overall experience for security and endpoint management teams.
One additional area for improvement is the overall user and administration experience. While the platform is functional, I think some of the management workflows could be simplified so that common tasks such as reviewing blocked applications, approving legitimate software, or tracing the reason behind a policy decision require fewer steps. For organizations with lean IT teams, a more intuitive interface and clearer guidance during policy creation would help reduce the learning curve for new administrators. I would appreciate seeing broader integrations with the endpoint management, SIEM , and IT service management platforms so application events, approval requests, and policy updates can fit more naturally into existing operational workflows. Better APIs and pre-built integrations would reduce manual work and make automation easier for larger environments. More flexible reporting and customizable dashboards would help different teams, whether security operations or compliance, quickly access the information that is most relevant to them without having to manually compile reports. Addressing these areas would improve efficiency and make the product easier to operate as organizations scale their endpoint environments.
For how long have I used the solution?
I have been using Airlock Digital Application Control for a little over two years in a production environment, primarily as a part of our endpoint security strategy for Windows desktops and servers.
What do I think about the stability of the solution?
Regarding stability, the product has been reliable in our environment. We have not experienced any significant outages or stability issues with the platform itself, and once the initial policies were properly tested and defined, policy deployment was consistent across our endpoints. The few issues we encountered were generally related to a newly released application version that had not yet been added to the allow list rather than a problem with the product's reliability. Those situations were resolved by validating the software and updating the appropriate policies. The platform has been stable enough that it has become part of our standard security operation, and any day-to-day challenges have been operational rather than related to system availability or performance.
What do I think about the scalability of the solution?
From my experience, Airlock Digital Application Control has scaled effectively as our endpoint environment has grown. As we added new user devices and business applications, we were able to extend our existing policy framework without having to redesign the entire deployment management approach. It made it straightforward to onboard new groups, apply appropriate policies, and maintain consistent security standards across the environment. We also found that creating separate policies for different departments or user groups allowed us to accommodate changing business requirements without affecting the rest of the organization. As the environment grew larger, the biggest challenge was not the platform's ability to scale but the operational effort required to keep application allow lists current and organized. Regular policy reviews, a standard approval process, and a phased deployment became increasingly important to prevent unnecessary complexity. We have not encountered any major performance or reliability issues related to growth, and the platform has continued to support our expanding endpoint environment reliably. Successful scalability depends not only on the product itself but also on having well-defined governance and policy management processes in place.
How are customer service and support?
My experience with Airlock Digital's customer support has been positive, and I would rate it eight out of ten. We have not had to contact support very often because the platform has been stable, but on the few occasions when we did, mainly during deployment and when we needed clarification on policy behavior or best practices for handling specific application scenarios, the team was responsive and technically knowledgeable. They took the time to understand our environment instead of providing generic answers, and their suggestions helped us resolve issues without resorting to broad policy exemptions. Response times were generally reasonable, although for more complex questions that required investigation, it sometimes took longer to receive a detailed solution, which is understandable for enterprise support cases. The documentation and knowledge resources were also useful for many day-to-day questions, reducing the need to open support cases. The reason I did not give support a score higher than eight is that I think there is still room for improvement in providing even faster turnaround for complex cases, more proactive technical guidance, and a broader library of implementation examples and best practices for different deployment scenarios. The support experience has been professional and has given us confidence that assistance is available when needed.
Which solution did I use previously and why did I switch?
Before adopting Airlock Digital Application Control, we relied primarily on a combination of traditional endpoint protection, Microsoft AppLocker for a limited set of systems, and manual administrative controls rather than a dedicated, enterprise-wide application control platform. While that approach provided a basic level of protection, it became increasingly difficult to manage consistently as the environment grew. Policy management was fragmented, visibility into approved and unauthorized applications was limited, and maintaining consistent application control across different endpoint groups required a significant amount of manual effort. We evaluated several application control solutions before selecting Airlock Digital Application Control. We were looking for a product that offered more centralized policy management, better visibility into application activity, and a practical way to implement application allow listings without creating unnecessary operational complexity. The transition required careful planning and policy tuning, but once the deployment was completed, administration became more structured and predictable. Airlock Digital provided a better balance between security, usability, and day-to-day management than our previous approach, which was the primary reason for making the switch.
How was the initial setup?
We deployed Airlock Digital Application Control in an on-premises environment because it aligned with our organization's existing security architecture and endpoint management practice. Most of our critical systems and management infrastructure were already hosted within our own data centers, so keeping the application control management platform on-premises simplified integrations with our existing authentication services, endpoint management tools, and internal security processes. The deployment also gave us greater control over policy management, administrative access, and change management, which was important for us from both a security and a compliance perspective. Once the initial setup and policy configurations were complete, day-to-day administration was straightforward, with the policies being managed centrally and distributed to endpoints as a part of our standard operation process. Although an on-premises deployment requires us to maintain the underlying infrastructure, it has provided the level of control, stability, and predictability we were looking for, and it has integrated well with the rest of our enterprise environment.
What was our ROI?
We have seen positive returns on investment, although it has been more apparent in the reduced operational effort and improved security than in direct headcount savings. Before implementing Airlock Digital Application Control, our IT team spent a noticeable amount of time investigating incidents caused by unauthorized software and responding to requests related to unapproved applications. After introducing application allow listing and establishing a structured approval process, those incidents became much less frequent. We estimated that support tickets related to unauthorized software decreased by around thirty-five to forty percent, and the time spent investigating suspicious or unknown executables was reduced from several hours to less than thirty minutes because administrators could quickly verify application status through centralized policies and audit records. Routine software approval requests also became more predictable, with most standard requests being completed within one business day instead of taking several days. While we did not reduce the size of the IT team, the time saved allowed administrators to focus on higher-value activities such as security improvements, endpoint life cycle management, and proactive projects instead of repetitive troubleshooting. From a business perspective, avoiding even a single significant malware or ransomware incident would justify much of the investment. The improvements in operational efficiency, security, and risk reduction have made the solution worthwhile for us.
What's my experience with pricing, setup cost, and licensing?
The pricing and licensing model for Airlock Digital Application Control was relatively straightforward and easy to understand compared to some other enterprise security products we evaluated. We licensed the solution based on the size of our endpoint environment, which made it easier to estimate costs during budgeting and future planning. The initial setup cost was reasonable because the deployment did not require significant additional infrastructure beyond what we already had in place. Although we did invest time in planning, policy creation, testing, and administrator training to ensure a smooth rollout, the larger investment was in the implementation effort rather than the software itself, particularly during the early stages when we were building and refining application allow listing policies. Once the environment was stabilized, ongoing licensing and operational costs were predictable and fit within our security budget. The overall value was justified by the increased control over application execution, the reduction in security risks, and the operational improvements we gained. The only area where I think there is room for improvement is providing even greater flexibility in licensing options for organizations with mixed environments or rapidly changing endpoint counts, but overall, we found the commercial model fair and transparent.
Which other solutions did I evaluate?
Before selecting Airlock Digital Application Control, we evaluated a few different approaches, including Microsoft AppLocker, Microsoft Defender Application Control , formerly Windows Defender Application Control , and a couple of other endpoint security solutions that included application control capabilities as a part of a broader endpoint protection platform. Our evaluation focused on how easy each solution was to deploy and manage, the level of policy granularity, reporting, day-to-day administration, and the impact on end users. Airlock Digital stood out because it offered a good balance between strong application allow listing capabilities and operational simplicity, making it a better fit for our team's requirements.
What other advice do I have?
My advice to others looking into using Airlock Digital Application Control would be to spend as much time planning your application control strategy as you do evaluating the product. The technology is only one part of a successful implementation. Having a clear understanding of your software inventory, business-critical software, and an approval process will make the rollout much smoother. I would recommend starting with a pilot group that represents different business functions so you can identify legitimate applications that need to be allowed before expanding the deployment across the organization. It is also important to involve the endpoint management, security, and application owners early in the process so everyone understands how software requests and policy changes will be handled. Once the solution is in production, establish a regular process for reviewing policies, validating new application versions, and removing old rules to keep the environment manageable over time. Application control should not be expected to work as a standalone security measure. It delivers the best results when it is integrated into a comprehensive endpoint security strategy alongside endpoint detection and response, vulnerability management, patching, and user awareness. Approaching implementation with good planning, realistic expectations, and a strong operational process will allow application control to provide effective protection without unnecessary disruption for end users or administrators. I would rate this product an eight out of ten overall.
Application control has improved security visibility and protects remote users from online attacks
What is our primary use case?
My main use case for Airlock Digital Application Control is to provide protection to the application, and I am using it for in-house hosted applications.
I have internal software that is being used for filling up client data, and it was internally developed. Since my users are working from home or over the internet from remote locations, there are chances to be attacked by hackers over the internet. I am using this solution to identify the attack surface and to protect it from being attacked.
What is most valuable?
The best feature that Airlock Digital Application Control offers is the protection against DDoS attacks, which I appreciate most.
What stands out to me about the DDoS protection is that it addresses distributed denial-of-service attacks, so my legitimate application can be unavailable for actual users if a DDoS attack is happening on the application.
Airlock Digital Application Control has positively impacted my organization because I now have more visibility on my application security areas, which is giving my business confidence about the security and confidentiality. Based on this, my customers are able to easily use it, along with employees.
This increased visibility has helped my team and business by helping me understand the current gaps I have to work on to make my application more secure based on the reports and insights I am getting from the tool itself.
What needs improvement?
I think the team is doing well, and if the PS team or another team can help me with more granular technical training, that will be helpful for my team to learn the product and support the product without submitting a ticket with the tech team.
For how long have I used the solution?
I have been using Airlock Digital Application Control for the last one year.
Which solution did I use previously and why did I switch?
I did not previously use a different solution; this one is the first solution that I have implemented in my organization.
What was our ROI?
I have seen a return on investment because I am saving in terms of resources and fewer employees are needed. Earlier, manual tasks were more prevalent, and now because of AI and automation, things are quite easier for my organization.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is definitely good. Although it is a bit on the higher side for a small organization, for a medium or enterprise organization, it is a good choice, and the pricing is very effective.
What other advice do I have?
Regarding Airlock Digital Application Control's AI capabilities, it is maintaining all kinds of logs of the traffic as well as the audit logs, which is helpful for maintaining governance.
For accuracy, I feel Airlock Digital Application Control is providing almost eighty-five percent accuracy, and the results are reliable. I am utilizing it for my daily routine work.
Airlock Digital Application Control is deployed in my organization on the public cloud.
I use AWS as the cloud provider.
I purchased Airlock Digital Application Control through the AWS Marketplace .
My impression of the granular policy control offered by Airlock Digital is that it is impressive, and there are many policies with granular control, giving me a more flexible environment for controlling traffic.
The use of Airlock Digital's policy creation wizard impacts my daily management tasks because it is helping in designing the policies and also giving me suggestions. Even an L1 person can easily configure it because the wizards are very useful and easy to configure.
I am using the policy change history feature in Airlock, and it is helping me because if a policy was created in the past and was working well, and somebody changed it for some reason, I can easily track it to understand if the new changes have created any kind of issues for the environment.
I assess the clarity and speed of the new user interface compared to the previous version as very good. It is very user-friendly, and I am very satisfied with the new user interface.
I am using Airlock Digital's bidirectional REST API, and it definitely helps with integration and automation in my IT processes because Airlock logs can be utilized with the SIEM tool. In a similar fashion, logs collected by other endpoint security technologies can be integrated with Airlock, so both tools can simultaneously synchronize and help me make the environment better.
In my experience, the single SKU licensing model is definitely good for my organization's budgeting and resource allocation for application control because if organizations are small or they want to start with Airlock, it is a great choice in that case.
Utilizing Airlock has helped prevent malware within my systems, and it definitely helps to prevent malware because it easily understands and detects traffic related to the applications. It helps me see if any kind of unintended traffic is there.
I would rate this product a ten out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Application control has enabled granular whitelisting and constrained use of sensitive tools
What is our primary use case?
Application whitelisting has become increasingly important, and ensuring that we’re not running code unknown to our organization is crucial. The organizations I work for have been using it to effectively whitelist applications known to be in use, and then highlight any applications that aren’t within the remit of the service delivery organizations or the infrastructure organizations, ensuring that we’re only executing known code.
One of the use cases for Airlock Digital Application Control that we identified were timer applications; we found applications being used potentially to exfiltrate information. We found people using WhatsApp as well as Signal, which weren’t under the control of the data loss prevention capability within the organization I was working with, so we were able to identify applications that might be missed by DLP .
We have certain use cases where users require using scripting languages and programming languages such as Python to run simulations and modeling; this is not something we want every user to be able to do, but it’s allowed us to select which users are allowed to run certain applications and under what scripting languages and programming languages and under what circumstances they’re allowed to run them. This means that it’s not a blanket on or off; it’s about under what context the application can actually run, allowing users to use Python or PowerShell under constrained use cases as opposed to unrestricted access.
How has it helped my organization?
One of the other capabilities I haven’t mentioned is the ability to have an on-premises as well as a cloud instance; in the industries I work in, having the ability to run disconnected from the internet or running everything on-premises for data sovereignty purposes is really important. Airlock Digital Application Control has given us that flexibility to have both deployments depending on the context in which we’re running the application or needing this capability.
Anybody going on an application control journey is going to realize that they need a maturity uplift; this has allowed us to present information back to the service delivery organizations and the infrastructure organizations, and the application organizations within the companies I’m working with, and help them develop a maturity plan around uplifting their processes and their policies and their workflows. It’s also helping them have justification around limiting Shadow IT, and being able to say no—this application is not appropriate or this application is appropriate. It helps them on that maturity journey.
What is most valuable?
Airlock Digital Application Control is probably the easiest application control that I’ve come across; the product has a GUI-first, web interface-first approach to application control, and the way that it’s able to present exceptions or identify what those untrusted executions are is the best that I’ve seen in the field. It’s easy, it’s very quick, and I think that it reduces that barrier to entry for application control.
One of the best features that Airlock Digital Application Control offers is the ability to create complex rules around what applications are allowed to execute under what circumstances and where. It helps us answer the who, what, where, when, and why, to a lesser extent, applications are being used; it’s absolutely the ability to define complex rule sets.
I appreciate the automated baselines that are in Airlock Digital Application Control; being able to start off with a starting point of what, for example, Windows 10 or Windows 11 or one of the server platforms would normally run means we’re not developing our policies from scratch. I also appreciate the ability for bulk adding and identifying publishers of applications and being able to blanket approve publishers, for example, or I can put complex rules around publishers so that the publisher can only execute under certain circumstances. The flexibility and the way that the product has been designed has been really well thought out.
I love how granular Airlock Digital Application Control is; I think the metadata rules, which allow us to create complex rule sets, are excellent compared to what I’ve seen in other products doing application control. Airlock Digital Application Control is just so far ahead of others.
What needs improvement?
I think there are features that are coming down the pipeline that we don’t have yet; one of which is the ability to have a managed installer process. There is that capability currently, but it’s reliant on WDAC or Windows Application Control , as opposed to being natively within Airlock Digital Application Control. This is something that is coming, but we haven’t actually seen it deployed yet. At the moment, we’re still having to onboard applications individually, and that would be the biggest pain point that we have right now.
I think more guides on how to onboard and bring Airlock Digital Application Control into production would be helpful; these aren’t technical needs, more around documentation and potentially some videos on how to onboard or how to bring it into your organization more efficiently.
For how long have I used the solution?
I have been using Airlock Digital Application Control now for about nine months.
What do I think about the stability of the solution?
Airlock Digital Application Control has been extremely stable for me so far; I haven’t had any problems with the agents when they’re deployed and the policies are stable. It has had some problems with the on-premises deployment, in terms of stability of the server-side components, and there have been some minor problems with upgrades of agents, but nothing insurmountable.
What do I think about the scalability of the solution?
At this stage, the only scaling issues we’ve had with Airlock Digital Application Control have been around the reporting database; everything else has been fine.
Which solution did I use previously and why did I switch?
We were using AppLocker in some use cases, which was really managed by a group policy; we found that it was too coarse, and we weren’t able to get granular policy control with it. That’s why we moved towards Airlock Digital Application Control, and with Airlock Digital Application Control, we are actually installing that on the entire workstation and server estates, whereas previously it was only on very specific application servers.
What was our ROI?
At nine months in with Airlock Digital Application Control, I think we’re still not seeing a return on investment, and that’s partially because the need for application control was more important or timely than the processes were able to keep up with. At this stage, we’re still heavily invested in resources bringing it up and aligning our processes with it, so I think we will have a return on investment, but I don’t think it’s going to be in year zero. I think it’s going to be probably towards the back end of year one.
What other advice do I have?
I think the user experience is quite good for a modern product; the reporting is getting better with every release, and at this stage, I don’t have any specific points on the reporting that I would want to be better. Perhaps some UI performance improvements, but generally, I think that for what Airlock Digital Application Control does, it does extremely well and fits within that scope really well.
I advise others looking into using Airlock Digital Application Control to understand what your software asset register looks like and what is allowed to run in your organization; once you understand what is allowed to run, you can then develop policies and processes to implement Airlock Digital Application Control efficiently. If you don’t have those governance structures in place, you’re really going to struggle to move Airlock Digital Application Control from audit mode into enforcement mode.
I would rate this product a 9 out of 10.
Centralized control has reduced shadow IT and improved endpoint security visibility
What is our primary use case?
We use Airlock Digital Application Control for endpoint management, for protection and management of shadow IT, not in a punitive sense, but if we find people trying to use unapproved software, we try and point them to approved software to minimize our risk profile while maximizing the value. We call all of our employees owners, so when I say owners, that is what I am talking about. For our owners, for example, at one point, BioCryst had 74 different zip tools in their total environment, and by getting it down to one, we reduced license costs, we reduced the risk profile from having lots of different unpatched software. We got all of them up to date, so we were no longer running out-of-date software, and the experience for our owners was better, and the protection for the enterprise was better.
With Airlock Digital Application Control , we have to make sure the versions on the endpoints are up to date, but that is managed as part of the tool. We do tracking and reporting to make sure that all of the systems are up to date, and there are occasional requirements where something broke on an endpoint, and we have to manually reinstall it. But we had 800 endpoints all told, and I think we had to reinstall it less than 20 times manually, so it was not exactly common. But because we could feed the reporting into Splunk, it was easy to catch because Airlock Digital Application Control is not stellar necessarily about giving you a good report that says this machine has not checked in in a timely manner because their window is too small, and it is not really adjustable. Some of our salespeople might not turn their laptop on but once a month. Once it had not checked in for 72 hours, it just stopped doing anything. But we could see in the Splunk instance when their version got out of date, and the reporting, even though we got the data from Airlock Digital Application Control, was easier to do in Splunk. Then we would say, this one is five versions out of current, and our current is two versions off of latest. Then we would see if Airlock Digital Application Control could update it internally, and if not, we told the help desk to go manually reinstall Airlock Digital Application Control. That got it back up to date, but since it is a SaaS product, there was not server maintenance or anything we had to do.
What is most valuable?
What I like the most about Airlock Digital Application Control is that when I first joined BioCryst, they had an existing relationship to deploy Carbon Black, and Carbon Black was such a screaming nightmare because they got sold and resold and acquired six times in 14 months. So they did not know whether to scratch their ass or wind their watch, so it was kind of crazy, and their service was abysmal. The tool was still the bleeding edge of 1997, had not been updated since; it just kept getting sold. Airlock Digital Application Control is taking that Carbon Black concept, making it cloud-based, making it much more dynamic and scalable, and more reactive in terms of the reporting. Does it still have some growing pains? It does, but even on its worst day, it was head and shoulders above Carbon Black, even though at the most granular level, they did essentially the same thing, but things that we would try to do in Carbon Black would just crash in Carbon Black, and you could do in seconds or minutes in Airlock Digital Application Control.
It handled the scale with very rare exceptions; every once in a while, you would catch them when they were doing an update or something, and it would hang, but I could count that on the fingers of one hand in two years, where I could not tell you how many times a day Carbon Black was crashing because it was well into the dozens. It actually performed better. It had better granularity in reporting because we used Splunk as our SIEM for data aggregation, and it was able to set up direct data feeds, and as the environment changed, those data feeds updated. So it worked very well in a centralized reporting and tools environment, allowing us to better leverage that risk protection. We did not necessarily watch Airlock Digital Application Control every second, but we had a SOC that could run queries against that data and compare it to our CrowdStrike data and compare it to our Zscaler data and some of our other firewall data and see what was going on and where we may have opportunities for excellence.
What needs improvement?
What I dislike about Airlock Digital Application Control is that the whole endpoint management concept as implemented there is silly, and they need to have a better flow so you can appropriately do that type of work at the access control layer, not at the machine layer. If you simply take local admin away from everyone in the company, it is a way of taking local admin away without telling people you are doing that, and I think that is kind of silly. But the biggest challenge is the tool does not let you migrate information between groups, and its export function is not stellar, though it is markedly better than it was when we first started with it. If I built a group and we grew and we decided we need to change how that was organized, I had to take a buttload of screenshots to capture all of the information because there was not a way to migrate them into a new structure. That is one of the things they are working on, and it was due to be released soon, and I got laid off about eight weeks ago now, so maybe they have released it now. But that was a pain because there was no way to export it, even as a CSV, and that was annoying because it did not screenshot easily.
For how long have I used the solution?
I have been a customer for about two years.
How are customer service and support?
I have paid for enhanced support, so we have a weekly call with a technical success manager, and I have never had to call support; I called him.
The support from Airlock Digital Application Control was excellent. I am drawing a blank on his name because we had two of them, but they were top-notch. It took a little while to get the second guy up to speed, but that is normal. We had been working with the first guy for about 10 months at that point, and he got promoted; good for him. We got the new guy up to speed, and once he understood what was going on with our environment and everything, it was great. Having that regular cadence, when we had extra questions, he always responded within a timely manner. From my perspective, it was not the kind of tool that you regularly had to have an instant response, but it was rare not to have a response by the next business day, and typically we got something the same day unless I sent it at about 6:00 at night.
If I were to put their support on a scale from 1 to 10, I would give them an 8. It is not that there was any fault of the support person we had, our technical contact; it is just sometimes things that we wanted as baselines had to go into the development pipeline. He was a good advocate for us getting those into the development pipeline and giving us links so that we could go into the tool that development used to track it, so we could go in and all vote for it to bump it up in the priority.
How was the initial setup?
The initial deployment of Airlock Digital Application Control was just an Intune push, and it was pretty easy. We already had a centralized management tool.
What's my experience with pricing, setup cost, and licensing?
I thought the pricing for Airlock Digital Application Control was good. I was the one that negotiated the contract and was actually successful in suing Carbon Black and getting all of our money back, and then working with Airlock Digital Application Control to get a multi-year contract within that budget. They are much more cost-effective than Carbon Black, both just in terms of the flat pricing and then what you get for the pricing. We did pay extra for some of the customer service support, but it was an excellent investment to get the best return out of the environment, fast.
What other advice do I have?
Airlock Digital Application Control has helped me to prevent malware within our systems. The policy change history feature did not exist when I started, but they had auditing; that is part of the policy change history. We did look and see, if something happened, who did it, so we did use the auditing.
I have indeed had experience with the bidirectional REST API; that is how Airlock Digital Application Control updated itself and updated the dashboard. We played with that a lot, especially when we were first setting it up, but once we had the key set up, it worked pretty well.
The single SKU licensing model has not affected our organization's budgeting and resource allocation for the application control. What we had was not technically one SKU because we had one SKU for the service and then we had one SKU for the support. But it is not a tool that is so granular or so fractional that you need a bunch of other SKUs. It is kind of binary; you either buy it or you do not. You either buy support or you do not. It is not like Oracle or SAP where there are 12 billion subcomponents that you have to buy individually and track, so you do not need a billion SKUs or a Microsoft SKU-of-the-week model.
If I am looking for that type of tool in another environment, I am going to reach out to them. Overall, I give Airlock Digital Application Control a solid 8.
Application control has strengthened endpoint security and now needs better performance
What is our primary use case?
My use case for Airlock Digital Application Control is application control.
What is most valuable?
The best features of Airlock Digital Application Control include the ability to block using publishers, path rules, and many features that fit our purpose. The main thing would be blocking all and allowing only specific applications, which is the approach we are following.
Airlock Digital Application Control helps improve my auditability and governance over policies because it can be logged and we can see who made changes and for what purpose. We have our own internal standards defined so that whenever people make changes, they should have obtained all the approvals and the comments are updated with the request details and all those things.
I have noticed that Airlock Digital Application Control has improved the way my organization functions as it is more of a security tool. With technology transitioning so fast with artificial intelligence, we wanted to be careful about what is getting executed in each and every endpoint device. In that aspect, we were looking at a solution where only what we allowlist is getting executed.
What needs improvement?
In Airlock Digital Application Control, there are areas for improvement which, more specifically being a security tool, relate to the performance issues that end-user devices are experiencing because of the tool. It is getting improved on a version-to-version upgrade basis, but I would say that is one major area to improve. Otherwise, whatever is defined on the product works as expected.
The performance aspect of Airlock Digital Application Control could be improved.
For how long have I used the solution?
I have been using Airlock Digital Application Control for almost a year.
What do I think about the stability of the solution?
So far, I have not had any issues with the stability of Airlock Digital Application Control, so I would rate it about eight or nine.
What do I think about the scalability of the solution?
The scalability of Airlock Digital Application Control depends on the problem statement or the use case that we come up with. There were some challenges initially, but I think with the current version, it is quite scalable now.
I would rate the scalability of Airlock Digital Application Control as seven because there are still some features upcoming which will improve the scalability much more.
How are customer service and support?
I would rate the technical support of Airlock Digital Application Control as nine.
How was the initial setup?
I find that the deployment of Airlock Digital Application Control was very straightforward.
The deployment of Airlock Digital Application Control was staged, but otherwise, we did not have any issues during the deployment. Everything went smooth. We have devices across the regions, so we usually stage it by regions such as APAC and EMEA.
What was our ROI?
Time-wise, I would say that Airlock Digital Application Control saves a lot of time. Monitoring a fleet of devices will take a team's effort, but we three or four people are working on this, and it is quite easy. Integrating to other monitoring tools saves a lot of time.
I would say Airlock Digital Application Control saves around thirty percent of our time.
Which other solutions did I evaluate?
I compare Airlock Digital Application Control with other vendors such as ThreatLocker, Carbon Black, and BeyondTrust based on the proof of concept we did with other competitive tools. What made Airlock Digital Application Control different is the features and options we had to approach a single problem. We have the capability of blocking or allowing publishers or even more granularly, up to a device or a device group, which gives us that agility.
What other advice do I have?
Approximately three thousand to four thousand devices use Airlock Digital Application Control.
The users of Airlock Digital Application Control are global, not just based in India.
I would recommend Airlock Digital Application Control to people who are looking to manage endpoint computers to enhance their security. I gave this review a rating of seven out of ten.