Unapproved AI tools are
putting your organization at risk.

Employees are submitting customer records, credentials, and confidential documents into AI tools, leaving your organization liable.

ShadowLock is the shadow AI detection platform for MSPs and IT teams: the visibility to see it and the controls to stop it.

69%
of organizations suspect employees are using prohibited AI
Gartner, 2025
50%+
of AI use at work happens without employer approval
Salesforce
8
average AI apps in active use per organization
Netskope, 2026
100+
AI tools, services, and desktop apps detected and governed
And growing

Shadow AI is the new Shadow IT,
faster, riskier, and already everywhere.

Employees use unapproved AI with sensitive data, and most organizations have no visibility into it at all.
💬

Public AI Chatbots

ChatGPT, Claude, Gemini accessed via personal accounts: no enterprise contract, no DPA, no audit trail.

🧩

AI Browser Extensions

Sidebar assistants and email rewriters that read content across every site employees visit, including clipboard data.

☁️

Embedded SaaS AI Features

Copilot and AI writing features inside approved SaaS apps, activated without any security review.

💻

Desktop AI Apps

Claude Desktop, ChatGPT app, Ollama, and LM Studio running entirely outside browser-based controls.

⌨️

AI Coding Assistants

GitHub Copilot, Cursor, and similar tools with broad file access. Proprietary code and credentials directly at risk.

🎙️

Meeting & Transcription AI

Otter.ai, Fireflies, and similar tools recording and processing internal calls, clinical discussions, and client meetings.

Everyday AI use is creating
legal, compliance, and liability exposure.

🏥

HIPAA & ePHI Exposure

Patient data pasted into public AI tools without a BAA in place triggers HIPAA exposure. No breach required.

HIPAA
🌍

GDPR, CCPA & Privacy Frameworks

Customer PII processed through unapproved vendors with no DPA, no lawful basis, and no compliant transfer mechanism.

PRIVACY
🔒

Trade Secrets & IP Risk

Source code, contracts, and product plans submitted to public AI. Failing to control access can weaken trade secret protections.

IP RISK
🏢

MSP Liability

When a client has an AI-related incident and you had endpoint scope, the gap between "not our job" and "you should have known" is where claims live.

MSP RISK
📄

Contractual Exposure

Personal-account AI tools run under consumer terms: no DPA, no BAA, no incident notice obligation. The protection you assumed doesn't exist.

CONTRACT
🔍

Incident Response Blind Spots

Without prior visibility you can't answer which tool, which account, or what data was involved, breaking triage, notifications, and defensibility.

DEFENSIBILITY

Three layers of coverage.
One place to manage it all.

ShadowLock covers the full AI surface: browser, desktop app, and cloud tool, without enterprise-level deployment complexity or dedicated security engineering.

01
🖥️
AGENT

Endpoint Agent

Deployed silently to Windows endpoints via your existing RMM. Monitors AI activity, scans browser extensions, detects local AI apps, and locks down the AI built into Chrome, Edge, Brave, and Firefox. Zero user interaction.

02
🧩
EXTENSION

Browser Enforcement Layer

Self-configures once the agent is installed. Intercepts pastes, file uploads, and sensitive data typed straight into prompts, enforces the data-sharing opt-out on each AI tool, and applies your policies with clear user-facing messages.

03
☁️
M365 SCANNER

Microsoft 365 AI App Detection

Connects to each customer's Microsoft 365 tenant via Microsoft Graph and scans for AI apps that have been granted OAuth access: Copilot plugins, third-party AI add-ins, and other AI service principals. New connections trigger a critical alert automatically, with no endpoint required.

Every AI surface detected.
Every enforcement point covered.

🌐

AI Website Detection & Blocking

Detects navigation to known AI domains and enforces your access policy before anything is pasted. Domain list stays current automatically.

BlockWarnAllow
📋

Sensitive Data Interception

Stops paste events and file uploads before content reaches the AI tool. PII, credentials, SSNs, and card data classified entirely within the browser.

Paste BlockUpload Block
🧩

Browser Extension Scanning

Flags known AI sidebars and writing tools, plus unknown extensions with high-risk permissions that can read sensitive content on every page.

Known AI ExtensionsPermission Flags
💻

Desktop AI App Detection

Surfaces AI exposure that browser controls never reach: offline tools, local LLMs, and developer-facing apps running outside any web policy.

OllamaLM StudioLocal LLMs
👤

Personal Account Detection

Reads the signed-in identity on any AI site and blocks personal or unauthorized accounts from sending prompts until a corporate account is verified. Website-agnostic, no per-site setup.

Flag PersonalBlock Personal
🏢

Multi-Organization MSP Dashboard

Cross-org risk view, alert workflows, device inventory, and policy management: everything an MSP needs to govern AI risk across all customers from one place.

MSP-FirstRMM-ReadyExport Reports
✍️

AI Prompt Protection

Catches sensitive data as it's typed into a prompt, not just pasted, and redacts the value from the request before the model sees it. The user keeps their flow; the secret never leaves.

Detect on TypeRedact at Send
🚦

AI Data-Sharing Control

Reads each AI tool's real "train on my data" setting and blocks prompts until it's switched off. Grounded for ChatGPT, Claude, Perplexity, Le Chat, Copilot, and Grok.

Block Until Off6 AI Tools
🔒

Browser AI Lockdown

Disables the AI built into browsers by enterprise policy: Gemini in Chrome, Copilot in Edge, Leo in Brave, and Firefox AI. Locked, with drift detection if anyone re-enables it.

Chrome GeminiEdge CopilotBrave Leo
🔎

Google Search AI Mode Control

Blocks Google Search's conversational AI Mode, redirecting it back to standard results while ordinary search stays untouched. A surface no browser policy can reach.

Block AI ModeSearch Untouched

Flexible control.
At every layer.

Set allow, warn, and block policies per AI tool, per organization, and per user. Changes propagate to every online endpoint within minutes.

🚫
BlockPrevent the action entirely and show a user-facing explanation. Logged with full context.
⚠️
WarnPermit with a non-blocking notification. Logged with risk score for partner review.
AllowPermit and log silently. Approved tools proceed without interruption, with a full evidence trail.
policy-config · Acme Corp
AI ToolSurfaceAction
ChatGPTPaste🚫 Block
ChatGPTFile Upload🚫 Block
ClaudeSite Access⚠️ Warn
GeminiPersonal Acct🚫 Block
PerplexitySite Access✅ Allow
OllamaDesktop App⚠️ Warn

The surface is already large.
Every week it grows.

AI adoption is outpacing governance in almost every organization. Three things make waiting more expensive than acting.

01 / ALREADY DEPLOYED

The tools are already in use.

The average organization already has 8 AI apps in active use. Most of it is happening without approval or any governance framework.

Avg. 8 AI apps/org · Netskope 2026
02 / THE BLIND SPOT

Enterprise policies don't cover personal accounts.

Employees on managed devices using AI through personal accounts are completely outside your policies, your logging, and every enterprise control. It looks like personal browsing. The data exposure is not.

Personal accounts bypass all managed controls
03 / AUDITORS ARE ASKING

Governance questions are already arriving.

Security questionnaires, cyber insurance renewals, and compliance reviews now include AI governance questions. "We didn't have visibility" doesn't reduce liability. It creates it.

AI governance now appears in insurance & audit reviews

Built for the people
responsible for AI risk at scale.

🏢 MSP / Partner

One Dashboard. Every Customer.

Cross-organization view of every client's AI exposure. Push policy changes to hundreds of endpoints and generate customer-ready reports, before an incident forces the conversation.

Aggregate risk scores per client, cross-org event feed
Silent deploy via any RMM in minutes
Export reports for business reviews and audits
🔧 IT Admin

Simple Controls. Fast Answers. Low Noise.

See which AI tools employees are using, what data they're pasting, and which extensions are risky. Configure allow/warn/block without a complex rule engine. Alerts that matter, not thousands of low-signal events.

Event timeline with risk scores per user and device
Allowlist approved tools so they're never interrupted
Device inventory with real-time online/offline status

Questions you'll be able to answer.
Questions you can't afford to avoid.

"Do you allow employees to use AI tools? Which ones are approved?"
Documented approved/blocked tool list with enforcement evidence across every endpoint.
Answered with evidence
"How do you prevent PII or PHI from entering public AI systems?"
Paste events and file uploads containing PII, credentials, and SSNs intercepted before they reach AI tools, with every event logged.
Answered with evidence
"Can you distinguish personal from enterprise AI account usage?"
Personal vs. managed account usage detected on every AI tool, with flagging and blocking available.
Answered with evidence
"How do you govern AI browser extensions on employee devices?"
All Chrome and Edge extensions enumerated per endpoint, with known AI tools and high-risk permissions flagged in the dashboard.
Answered with evidence
"Do you have logs and evidence of your AI policy enforcement?"
Every action logged with tool, surface, user, account type, and timestamp, exportable for auditors and client reports.
Answered with evidence
"How do you handle AI tools embedded inside approved SaaS platforms?"
Embedded AI features surfaced alongside standalone tools. Nothing hides inside an approved app.
Answered with evidence

Governance without
turning monitoring into surveillance.

Risk signals, not content. Sensitive data is classified locally and never transmitted. You get the evidence to act, without capturing what employees type or read.

🔐

Zero Content Transmission

Sensitive data is never sent to the backend. Only the data type and a reference are logged. You know something sensitive was pasted, but not what it said.

📂

File Metadata Only

Upload events log the filename, type, and size. File contents are never read or stored, by design and not just by policy.

⌨️

No Keystroke Logging

Keystroke logging is explicitly out of scope, technically and legally. ShadowLock monitors AI interaction events, not what employees write.

🌍

HTTPS / TLS Everywhere

All agent-to-backend communication is encrypted. EU deployments support EEA data residency requirements.

⏱️

Configurable Retention

Default 90-day event retention, configurable per organization. Data lifecycle controls built in from day one.

📋

Disclosure Workflow

Partners confirm employee disclosure compliance before onboarding each organization. Consent is enforced in the deployment workflow, not just the documentation.

Simple, scalable
MSP pricing.

Pay per managed device. Volume discounts apply automatically. The more devices you monitor, the lower your per-device rate.

See the full pricing breakdown, or compare ShadowLock to DNS filters, DLP suites, and browser-isolation tools.

Estimate your cost

Drag the slider to see your monthly rate at any scale.

50
Per-device rate$1.00/device/mo
Monthly total (50 devices)$50.00/mo
DevicesRate
1–99 devices$1.00/device
100–249 devices$0.95/device
250–499 devices$0.90/device
500–999 devices$0.85/device
1000+ devices$0.80/device
Start Free Trial

No charge until your trial ends. Cancel anytime.

Frequently asked questions

What is shadow AI?

Shadow AI is the use of AI tools, like ChatGPT, Gemini, Claude, or Copilot, by employees without IT approval or oversight. It is the AI-era equivalent of shadow IT and creates risk because sensitive company data can be pasted into AI services that have no data processing agreement, no audit trail, and no compliance coverage.

How does ShadowLock detect unauthorized AI tools?

ShadowLock combines a Windows endpoint agent and a managed browser extension to detect both desktop AI apps and web-based AI usage. It identifies which tools employees are using, flags pastes of sensitive data into AI prompts, and reports every event to your central dashboard in real time.

Does ShadowLock work on personal AI accounts?

Yes. ShadowLock detects AI tool usage at the endpoint and browser layer, so it sees activity regardless of which account is signed in: corporate SSO, a personal Google account, or no account at all. This closes the most common shadow AI gap that network-only tools miss.

Is ShadowLock HIPAA and SOC 2 compatible?

ShadowLock helps IT and security teams meet the access control, audit, and data protection requirements relevant to HIPAA and SOC 2. By preventing sensitive data from being pasted into unapproved AI tools and producing an audit trail of every event, ShadowLock supports the technical controls auditors increasingly expect for AI usage.

Stop guessing what's in your AI surface.
Start knowing.

Deploy ShadowLock in minutes via your existing RMM. Get visibility across every AI tool in your customer environments, before an incident, an audit, or a client question forces the conversation.

14-day free trial · Cancel anytime

Windows 10/11 · Silent RMM deploy
Zero sensitive data content transmitted
No keystroke logging, ever
Policy live on endpoints within 10 minutes
Export reports for clients and auditors