ThreatLocker
- Company typePrivate
- Founded2017
- HeadquartersOrlando, United States
- Headcount501–1,000
- GTM typeB2B
- OfferingSoftware
ThreatLocker firmographics
Firmographics- Name
- ThreatLocker
- Legal name
- ThreatLocker, Inc.
- Website
- https://threatlocker.com
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 501–1,000 employees
- Ownership category
- akta.pro rank
ThreatLocker industry classification
Industry- Product category
- Endpoint Security
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Endpoint Application Control & Allowlisting (HDADAEAI)
- akta.pro secondary industries
- Endpoint Deception & Anti-Ransomware (HDADAEAL), Access Management & Policy Enforcement (Zero Trust) (BPAMAEAH), Endpoint Security Managed Services (EDR/XDR) (BPAEADAH), Endpoint Security for End Users (EDR/XDR, Patch/Vuln, Zero Trust Endpoint) (BPAEAIAG)
Keywords
Where ThreatLocker is headquartered
LocationHeadquarters
- HQ city
- Orlando
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
ThreatLocker business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- Software Subscription / Platform Licensing: ThreatLocker operates on a subscription/licensing model with custom pricing based on endpoint count, application landscape, and control needs. The pricing page states costs are based on real endpoint count with accurate forecasting. No public pricing tiers are disclosed; all quotes are custom-built per organization.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Custom enterprise licensing based on endpoint count |
Go-to-market motion3 records
Distribution channels3 records
Marketing channels11 records
ThreatLocker product offering
Product offeringCore offering
ThreatLocker provides a unified Zero Trust endpoint protection platform built on a deny-by-default model. Its core offerings include Application Allowlisting, which blocks unauthorized software from executing, and Ringfencing, which controls what approved applications can do. The platform is extended by add-on modules covering network access, cloud/SaaS access, privilege management, storage control, patch management, web content control, configuration management, and 24/7 Managed Detection and Response, sold to enterprises, government agencies, and MSPs.
Product overview
ThreatLocker offers a unified Zero Trust platform with a deny-by-default security model. The core platform is built around Application Allowlisting and Ringfencing as foundational capabilities, supplemented by an integrated suite of add-on modules including Zero Trust Network Access, Zero Trust Cloud Access, Privileged Access Management, Elevation Control, Patch Management, External Storage Device Control, EDR Real-Time Threat Detection, Web Content Control, Data Storage Access Control, Storage Control, Managed Detection and Response (MDR/Cyber Hero MDR), DAC (Defense Against Configurations), Centralized Configuration Management, Controlled Application Testing Environment, Zero Trust Endpoint Firewall, Detect, Network Control, Insights, User Store, Cloud Control, Unified Audit, Learning Mode, Health Report, and Community policies. The platform also includes Third Wall (an acquired Windows security compliance plugin for ConnectWise Automate), and training programs (Cyber Hero Certification and ThreatLocker University). In 2025, the company launched five new solutions (Web Control, Patch Management, Insights, User Store, Cloud Control) and released DAC. In March 2026, the company expanded with Zero Trust Network Access and Zero Trust Cloud Access, backed by 14 new data centers.
Differentiator
Problem solved
Functional benefit
Brands
- Third Wall: A plugin for ConnectWise Automate providing Windows security compliance tools, lockdown policies, ransomware protection, and compliance reporting.
- Cyber Hero Team
- Cyber Hero MDR
- Cyber Hero Certification
Products and services
- ThreatLocker Platform Unified Zero Trust endpoint protection platform providing deny-by-default security across endpoints, networks, and cloud/SaaS environments, integrating multiple security capabilities into a single management console.
- Application Allowlisting Deny-by-default application control solution that permits only pre-approved software to run, blocking ransomware, malware, zero-day exploits, and unauthorized applications regardless of threat signature.
- Ringfencing Application containment technology that controls what approved applications can do after they run, limiting interactions with other applications, files, registry, network, and internet resources to prevent exploitation and lateral movement.
- Zero Trust Network Access Zero Trust Network Access (ZTNA) solution that shifts zero-trust enforcement to the endpoint, requiring valid credentials, an approved device, and connection through ThreatLocker-managed brokers to access network resources.
- Zero Trust Cloud Access Zero Trust Cloud Access (ZTCA) solution that extends endpoint protection to secure SaaS environments, routing all SaaS connections through a ThreatLocker-managed broker that verifies user identity, device authorization, policy compliance, and device posture.
- Elevation Control Application-centric endpoint privilege management that allows administrators to revoke local administrator rights and grant elevated privileges to specific applications on demand, without giving users administrative credentials. Integrates with Ringfencing to prevent lateral movement after elevation.
- Managed Detection and Response (Cyber Hero MDR) Managed Detection and Response service providing full-time Cyber Hero Team support with 24/7/365 monitoring, typically responding within 60 seconds, including active threat hunting, incident response, and strategic consulting.
- Patch Management Patch management solution that automatically identifies and remediates patching gaps across endpoints to prevent vulnerabilities from being exploited by attackers.
- Web Content Control Web filtering solution that blocks phishing attacks at the browser without requiring an additional security tool, controlling what web content users can access.
- Storage Control Policy-driven control over storage devices including local folders, network shares, and USB drives, providing granular access policies and detailed audit logs of file access including device serial numbers.
- DAC (Defense Against Configurations) Endpoint configuration assessment solution that scans endpoints for security misconfigurations such as outdated protocols, disabled firewalls, and unencrypted drives, available for Windows and macOS (Beta).
- Third Wall Windows security compliance plugin for ConnectWise Automate providing 58 lockdown policies to automate protection, monitors compliance every 5 minutes, offers ransomware protection, USB Wall for device control, and compliance reporting for HIPAA, NIST, PCI, and SOC.
- User Store Approved application store providing users with alternative approved applications when access is denied, including automatic license management and streamlined installation.
- EDR Real-Time Threat Detection Endpoint detection and response capability that automatically isolates compromised machines and protects data in real time, monitoring file read/writes, application executions, and network activity.
- Zero Trust Endpoint Firewall Endpoint firewall providing strict control over device access from anywhere in the world, enforcing zero trust at the endpoint level.
Quantifiable outcome
- 184% ROI and $4.15M net present value over 3 years for composite organization (Forrester TEI 2025)
- +9 more outcomes
Companies that use ThreatLocker
Customer profileNamed customers25 records
Segments7 records
Ideal customer profiles7 records
ThreatLocker technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration4 records
Feature12 records
ThreatLocker partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core.
- ConnectWisecorePlatform integration partner. The ThreatLocker platform integrates with ConnectWise Automate for seamless RMM workflow. The acquired Third Wall product specifically adds controls to ConnectWise Automate with 58 lockdown policies and automated compliance monitoring.
- KaseyacorePlatform integration partner. ThreatLocker integrates with Kaseya's IT management platform, enabling MSPs to manage ThreatLocker's Zero Trust security within their existing Kaseya workflows.
- DattocoreChannel partner. ThreatLocker is integrated with Datto's platform, enabling MSPs using Datto's RMM and business management tools to deploy ThreatLocker's Zero Trust security to their end clients.
Scale indicators13 records
Recent moves6 records
Expansion highlights6 records
ThreatLocker competitors and assessment
Company assessmentBroad incumbents
- Sophos: Sophos provides endpoint, firewall, and managed security services with an extensive MSP-led distribution model — closely mirroring ThreatLocker's MSP/MSSP go-to-market. Its Intercept X endpoint stack and ZTNA offering overlap with ThreatLocker's prevention-first architecture.
- Microsoft (Defender for Endpoint / Microsoft 365 Defender): Microsoft Defender for Endpoint ships with Windows and Microsoft 365, covering EDR, identity, and increasingly application control / device posture. Bundling and pricing make it ThreatLocker's most disruptive mainstream competitor, especially in mid-market and SMB segments where cost is decisive.
- Palo Alto Networks (Cortex XDR / Prisma): Palo Alto Networks competes across endpoint (Cortex XDR), network, and cloud security. Its broad portfolio overlaps ThreatLocker's expanding ZTNA, ZTCA, and MDR offerings, making it a frequent incumbent in large enterprise security consolidation bids.
- Trend Micro: Trend Micro offers endpoint, network, and zero-trust solutions for enterprises, with particular strength in mid-market and hybrid environments. Its Application Control and Zero Trust Secure Access products are direct competitive comparables to ThreatLocker's allowlisting and ZTNA modules.
- Zscaler: Zscaler is the category-leading Zero Trust Network Access / SSE vendor against which ThreatLocker's new ZTNA and Zero Trust Cloud Access products must compete. It has a large installed base of enterprises replacing VPN with cloud-delivered access controls.
Direct peers
- CrowdStrike: CrowdStrike's Falcon platform is the leading cloud-native endpoint security suite, offering EDR/XDR, device control, and identity protection. As ThreatLocker's natural substitute at the endpoint, CrowdStrike increasingly bundles zero-trust-style controls that ThreatLocker must displace in procurement decisions.
- SentinelOne: SentinelOne's Singularity Platform competes directly with ThreatLocker at the endpoint, combining AI-driven EDR with prevention, application control, and zero-trust-adjacent capabilities. The two vendors compete in MSP-led and mid-market enterprise endpoint deals.
- Tanium: Tanium combines real-time endpoint management with security controls, allowing IT to inventory, allow, and block applications across very large endpoint estates. Its converge-of-management-and-security approach is structurally similar to ThreatLocker's unified console strategy.
- Ivanti: Ivanti (including the legacy HEAT/Appsense Application Control line) is a longstanding vendor of endpoint, application allowlisting, and patch management products. It directly competes in the allowlisting/privileged-management module set that anchors ThreatLocker's platform.
Emerging players
- NinjaOne: NinjaOne is an MSP-first endpoint management and security platform that frequently co-sells or substitutes for ThreatLocker's MSP-side offerings. Its growing automation and security feature set make it a near-term threat inside the MSP channel.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
ThreatLocker social profiles
Digital presenceThreatLocker compliance and trust
Trust signalCompliance13 records
ThreatLocker financial estimates
Financial estimateRevenue estimate
Valuation estimate
ThreatLocker leadership team
Management profileNumber of profiles
Profiles8 records
ThreatLocker subsidiaries and ownership
Company hierarchySubsidiaries1 record
ThreatLocker funding detail
Funding detailFunding overview
Funding rounds7 records
Investors6 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ThreatLocker M&A and investment
M&A and investmentM&A2 records
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ThreatLocker
What does ThreatLocker do?
ThreatLocker provides a unified Zero Trust endpoint protection platform built on a deny-by-default model. Its core offerings include Application Allowlisting, which blocks unauthorized software from executing, and Ringfencing, which controls what approved applications can do. The platform is extended by add-on modules covering network access, cloud/SaaS access, privilege management, storage control, patch management, web content control, configuration management, and 24/7 Managed Detection and Response, sold to enterprises, government agencies, and MSPs.
Is ThreatLocker a public or private company?
ThreatLocker is a private company. It is classified as venture growth investor backed and is currently operating.
When was ThreatLocker founded?
ThreatLocker was founded in 2017. It employs 501 to 1,000 people.
Where is ThreatLocker based?
ThreatLocker is headquartered in Orlando, United States, in the North America region.
How does ThreatLocker make money?
One revenue line is on record: software Subscription / Platform Licensing.
Who are ThreatLocker's main competitors?
Broad incumbents on record are Sophos, Microsoft (Defender for Endpoint / Microsoft 365 Defender), Palo Alto Networks (Cortex XDR / Prisma), Trend Micro and Zscaler. Direct peers are CrowdStrike, SentinelOne, Tanium and Ivanti. NinjaOne is listed as an emerging player.
Does ThreatLocker have an API?
No public API is recorded for ThreatLocker.
What industry is ThreatLocker in?
ThreatLocker's product category is Endpoint Security. Its primary akta.pro industry code is HDADAEAI, Endpoint Application Control & Allowlisting, with a secondary code of HDADAEAL, Endpoint Deception & Anti-Ransomware. Its NAICS code is 54151 and its SIC code is 7372.