Skip to content

ThreatLocker

CISO Reviewed

Zero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.

Visit Website ↗ + Add to Compare
83/100Meaningful Innovator

Editorial: 78/100 · includes 1 verified CISO review

Overview

ThreatLocker builds a Zero Trust endpoint protection platform built around default-deny application allowlisting: instead of trying to detect malicious software after the fact, it blocks any application, script, or executable that hasn’t been explicitly approved. The platform layers on “Ringfencing” (limiting what approved applications are allowed to do, such as preventing Word from spawning PowerShell), storage control, elevation control for admin privileges, and network access controls, all managed centrally by IT and MSP teams.

Founded in 2017 by Danny Jenkins, Sami Jenkins, and John Carolan, ThreatLocker grew primarily through the managed service provider (MSP) channel before expanding into direct enterprise sales. The company is headquartered in Orlando, Florida, and has scaled to roughly $100 million in annual revenue and a reported valuation north of $1.6 billion as of its Series D round, with a $190 million Series F closed in mid-2026 to fund international expansion and AI-related risk controls.

The core differentiator versus traditional endpoint detection and response (EDR) tools is philosophical: rather than trying to identify bad behavior among everything that’s allowed to run, ThreatLocker starts from nothing being allowed to run until it’s been vetted. That approach trades some administrative overhead for a materially smaller attack surface, which is why it has found strong traction among MSPs securing many client environments with limited staff.

Innovation Matrix Assessment

Innovation Velocity 7/10

Steady, multi-year expansion from core allowlisting into ringfencing, elevation control, storage control, patch management, and newly announced AI-risk controls funded by the 2026 Series F.

Operational Value 8/10

Default-deny application control materially shrinks the executable attack surface for MSPs and lean IT teams managing many endpoints, a genuinely different operational posture than detect-and-respond tooling.

Market Momentum 9/10

Independently reported: $190M Series F (2026) led by Elephant with Koch Disruptive Technologies participating, prior $115M Series D, ~$100M ARR per CEO statements, and a reported $1.6B+ valuation. Sustained MSP-channel and enterprise expansion since the Series F further strengthens this signal.

Category Disruption 8/10

While application allowlisting itself isn't new, ThreatLocker's default-deny-by-default operating model — inverting the industry's default-allow posture at scale across MSP and enterprise endpoints — represents a more structural shift in endpoint security practice than a typical point tool; revised upward to reflect that.

Real-World Efficacy 7/10

Named a Strong Performer in Gartner's 2024 Voice of the Customer for Endpoint Protection Platforms with a 4.9/5 rating and 100% willingness-to-recommend among reviewed vendors. A growing base of MSP deployments with consistently strong peer-review feedback supports a somewhat higher efficacy assessment.

Enduring Relevance 8/10

Application control remains foundational against ransomware and supply-chain attacks, and the company is extending the model toward AI-related endpoint risk, suggesting continued relevance as threats evolve.

Why CISOs Should Care

Cuts the number of things that can execute on an endpoint down to an explicit allowlist, which blocks entire classes of ransomware and living-off-the-land attacks that evade signature- or behavior-based EDR.

What Makes It Different

Default-deny-first architecture rather than detect-and-respond-after-the-fact, paired with a channel model built specifically for MSPs managing many client environments at once.

The Matrix Verdict

83/100 — MEANINGFUL INNOVATOR

A Meaningful Innovator: ThreatLocker didn't invent application allowlisting, but it productized and scaled it effectively, with strong independent customer satisfaction signals and real revenue traction. Its disruption score is held back by its own success — at $100M+ ARR and a multibillion-dollar valuation it now competes as an established incumbent, not a scrappy category-definer.

What CISOs Are Saying

“Many breaches would have been stopped in their tracks if the companies had already deployed the Threat Locker zero trust agent.”

— Anonymous CISO, Cyber Defense Genius reviewer network

Editorial Note: Claims vs. Verified Findings

CEO claims of 3,000% three-year revenue growth and specific ARR figures are self-reported and not independently audited; Gartner Peer Insights ratings and funding round terms, by contrast, are independently documented.

Sources