ThreatLocker

ThreatLocker, Inc. provides a Zero Trust cybersecurity platform built around a deny-by-default model for endpoint, cloud, and network security. Its approach centers on allowing only explicitly approved software, access paths, and behaviors, helping organizations reduce exposure to ransomware, rogue tools, credential misuse, and unauthorized data movement. Rather than relying only on post-execution detection, ThreatLocker, Inc. emphasizes prevention and policy enforcement at the device, application, storage, and access layers.

ThreatLocker, Inc. has broadened its platform from endpoint control into network access, cloud access, threat detection, managed response, patching, web filtering, storage governance, and configuration hardening. The company positions these capabilities as part of a unified operating model that gives security and IT teams centralized administration, granular policy control, and fast operational support while keeping protection aligned across hybrid environments.

Offerings, Capabilities, and Integrations

ThreatLocker, Inc. delivers a policy-driven security platform that combines application control, access governance, threat response, web filtering, storage controls, and configuration hardening in a single management experience. Its core strength is enforcing least privilege and deny-by-default rules across users, devices, applications, and connections so organizations can reduce attack surface instead of chasing every threat after execution.

The platform is built to support hybrid operations spanning endpoints, servers, remote users, internal networks, and cloud services. ThreatLocker, Inc. also extends into Microsoft-centric environments through Microsoft 365 identity monitoring, Microsoft Graph-based policy inputs, Microsoft Sentinel log integration, and a presence in Microsoft Azure Marketplace. For service providers and channel-led deployments, it supports integrations with platforms such as ConnectWise, Kaseya, SolarWinds, and Datto.

Products and Services

  • Allowlisting: Deny-by-default application control that permits only approved software, scripts, libraries, and executables to run on endpoints and servers.
  • Zero Trust Network Access: Brokered, device-validated access to internal resources that helps eliminate exposed services and reduces reliance on traditional VPN-style connectivity.
  • Zero Trust Cloud Access: Device-bound access control for SaaS and cloud platforms so valid credentials or stolen tokens alone are not enough to gain access.
  • Ringfencing: Application containment technology that restricts how trusted applications interact with files, processes, the operating system, and the internet.
  • Privileged Access Management: Just-in-time and application-specific elevation controls that reduce standing administrator rights and limit privilege abuse.
  • Patch Management: Centralized patch monitoring and deployment for applications, including commonly missed third-party and portable applications.
  • EDR Real-Time Threat-Detection: Behavior-based threat detection that can isolate devices, block risky activity, and trigger automated policy actions in real time.
  • Managed Detection and Response (MDR): A managed monitoring and response service delivered by ThreatLocker, Inc. using telemetry from its Zero Trust platform and Cyber Hero support team.
  • Web Content Control: Integrated web filtering that blocks malicious or prohibited websites and enforces browsing policy on and off the corporate network.
  • Data Storage Access Control: Granular policy control over access to local folders, network shares, endpoint file systems, and cloud-connected storage such as OneDrive and SharePoint.
  • External Storage Device Control: Policy-based control for USB and other removable media, including encryption enforcement, read-only access, and file transfer restrictions.
  • DAC (Defense Against Configurations): A configuration risk and compliance dashboard that surfaces misconfigurations, prioritizes gaps, and helps teams harden environments faster.
  • Centralized Configuration Management: Central console for enforcing security baselines and configuration policies across domain-joined and non-domain devices.
  • Controlled Application Testing Environment: An isolated VDI-based environment for evaluating unknown applications before they are approved for production use.
  • Zero Trust Endpoint Firewall: A host-based firewall for endpoints and servers that enforces granular controls by device, IP, port, and policy.

Target Customers

ThreatLocker, Inc. targets organizations that want tighter operational control over what runs, what connects, and what data can be accessed across endpoints, cloud services, and networks. Its platform is suited to enterprises, managed service providers, and managed security service providers that need enforceable policy controls across distributed users, hybrid infrastructure, and multi-tenant or multi-site environments.

The company has clear traction in security-sensitive and compliance-driven sectors, including government, healthcare, finance, education, manufacturing, and MSP/MSSP environments. It is especially relevant for organizations focused on ransomware prevention, least-privilege enforcement, Microsoft 365 and SaaS access protection, data exfiltration controls, and standardized security baselines across remote and on-premises systems.

Cloud Integrations and Marketplace

  • Microsoft Azure Marketplace: ThreatLocker, Inc. maintains a Microsoft Azure Marketplace listing for its Zero Trust platform.
  • Microsoft 365: ThreatLocker, Inc. extends identity threat detection and response into Microsoft 365 and supports policy customization using Microsoft 365 and Microsoft Graph log fields.
  • Microsoft Sentinel: ThreatLocker, Inc. supports integration with Microsoft Sentinel for ingesting Unified Audit Log activity and related security actions.

Key People

  • Danny Jenkins: Chief Executive Officer & Co-Founder
  • Sami Jenkins: Chief Operations Officer & Co-Founder
  • Michael Jenkins: Chief Technology Officer
  • Rob Allen: Chief Product Officer
  • Ross McIntosh: Chief Financial Officer
  • John Carolan: Chief Quality Assurance & Co-Founder
  • Martin Olivo: Chief Information Officer
  • Matthew Van Til: Vice President of Sales
  • Ryan Bowman: Vice President of Solutions Engineering
  • Aliona Groh: Senior Vice President of Brand Marketing
  • Seamus Lennon: Vice President of EMEA Operations

Key Facts

  • Headquarters: Orlando, Florida, United States
  • Employees: 718
  • Annual Revenue: $100M+
  • Parent Company: None
  • Subsidiaries: None
  • Publicly Listed: No (privately held)

Analyst Recognitions

  • Gartner: 2026 Gartner Peer Insights Voice of the Customer: Endpoint Protection Platforms — Strong Performer. 2024 Gartner Vendor Spectrum for Endpoint Protection Platforms — Recognized for strong customer focus, product functionality, and performance.
ThreatLocker

Enter a search