Airlock Digital Passes Australia's Toughest Government Security Check

The Australian application control firm has cleared an independent IRAP assessment at PROTECTED level, giving government and critical-infrastructure buyers one more piece of evidence for their due-diligence files.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
An official government security certification document displayed prominently on a desk alongside computer systems, with PROTECTED level clearance seals and audi
Share

Key points

  • Airlock Digital completed an IRAP (Information Security Registered Assessors Program) assessment at the PROTECTED classification level, the rating used for sensitive Australian Government data.
  • An assessor endorsed by the Australian Signals Directorate reviewed the controls against the Australian Government Information Security Manual.
  • The result is relevant to government agencies, defence contractors and critical-infrastructure operators that must verify the security of every tool in their stack.
  • Airlock Digital's software controls which programs are allowed to run on an organisation's computers, blocking everything else by default.

What did Airlock Digital actually pass?

IRAP is Australia's formal process for checking whether a technology product meets the security standards the government sets for handling sensitive information. An independent assessor, approved by the Australian Signals Directorate, reviewed Airlock Digital's controls and found they hold up at PROTECTED level, the classification below TOP SECRET covering data whose release could cause serious damage to national interests.

Clearing that bar means a government agency or a defence supplier can point to the assessment when their own security team asks whether the tool has been independently checked. Vendor self-assessment, however thorough, isn't the same as a stranger with a checklist going through your controls.

We first covered Airlock Digital in August, when the company announced a layer to monitor AI agents command by command in real time on the devices where they do their work.

Why does this matter to anyone outside Canberra?

For ordinary Australians the ripple is indirect but real. Hospitals, energy providers, financial institutions and local councils all handle personal data at scale, and they're among the organisations most likely to use application control software.

Application control works by maintaining a list of approved programs and refusing to run anything not on it. Think of it as a bouncer who checks every piece of software against a guest list before letting it execute. Ransomware, malicious software that locks an organisation's files until a payment is made, almost always depends on running an unapproved program. A strict allowlist stops that before it starts.

The Essential Eight, a set of baseline security controls published by the Australian Signals Directorate, places application control at the top of its list. That framework recommends the controls to all organisations, not just government. The IRAP result gives buyers evidence that Airlock Digital's approach aligns with those expectations.

Should you worry if your employer uses this software?

The IRAP assessment is background assurance, not a guarantee that nothing will go wrong. The real failure mode is complacency: teams see a compliance certificate and assume the hard work is done. Allowlisting still needs someone maintaining the approved list and reviewing the edge cases where a legitimate program gets blocked.

For individuals the practical message is simpler. Organisations that invest in this kind of preventative security are less likely to end up sending breach notifications. That's the whole point of blocking software before it runs rather than hunting for it after the damage is done.

One thing a post-mortem will never say: "We had application control running and the ransomware executed anyway." The model works when it's maintained.

Operational takeaway: An IRAP certificate is a starting point for due diligence, not the end of it. Ask your vendor what the assessment scope actually covered.

© 2026 Threat Vectr