Almost everything else on this storefront begins by assuming hostile code will run and sets out to catch it. This one begins somewhere else entirely. Each machine keeps a manifest of software it may execute. Anything absent from that manifest never executes, no matter how plausible the file looked or who double clicked on it.
The agent goes on and simply observes for a stretch, blocking nothing. That is how the manifest gets written, out of your own working software rather than off a list assembled by strangers who have never seen your office. Then the door closes, and unfamiliar software has to be argued for.
The arguing arrives at our desk, and in practice it is settled in minutes. Even so it is a step nobody had in their day previously, and printing that here beats you discovering it in week three. A firm forever pulling in new tooling notices. A firm whose bookkeeper and estimator open the same six programs every morning barely does.
Cover the desks where a bad hour costs most. Whoever moves money. Whoever holds the drawings. The server keeping the job files. The laptop carrying the client list. Most firms settle on strict there and lighter elsewhere, and that is a sensible place to land.
Ringfencing is the half nobody discusses. Beyond the question of execution, it decides which helpers a permitted program may summon, which documents it may touch, and which destinations are open to it. That is what keeps a legitimate utility from doubling as a convenient exit for somebody else's records.
Each figure here is pulled out of the billing service as this page opens. Load a line now and it waits in the bag until you have finished reading.
ThreatLocker turns the machine around. Instead of guessing which programs are hostile, it permits the ones on the list and refuses everything else. A stranger arriving at the door with no name on the manifest does not get carried, however convincing the package looks.
| Carried on | ThreatLocker agent, one per endpoint |
|---|---|
| Covers | Managed Windows and macOS endpoints in the enrolled policy |
| Held in transit | Pending approval requests sit with our desk until a person decides them |
| Postmarked by | Fortify 24x7 engineers, working elevation requests around the clock |
| Signed for | One endpoint, one line, one monthly rate |
Execution control rules on software. It has nothing at all to say about the judgment of the human who approves something, and that distinction deserves printing before you order.
Heads up: card statements show FORTIFY 24X7 - Stars and Stripes IT is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.