Comparison

ShadowLock vs Control D for shadow AI

Control D is a transparently priced DNS filter. ShadowLock is a shadow AI control across three layers - endpoint, browser, and Microsoft 365 tenant. Both are straightforward to buy, but only one of them can read pastes and scan your tenant for AI OAuth grants.

Control D details last verified · sources

The quick verdict

Control D blocks the resolver request. ShadowLock blocks the paste. If your shadow AI policy is binary (allow / deny by domain) and your devices reliably resolve through Control D, the DNS layer is enough. The moment policy needs to be content-aware, you need the endpoint.

7

genAI apps at the average organization by May 2025, up from 5.6 in FebruaryNetskope Threat Labs, 2025 ↗

A DNS blocklist is only as current as its list, and the set of AI apps in an average organization grew by a quarter in a single quarter. ShadowLock identifies AI tools at the endpoint and browser and classifies what is pasted into them, rather than racing to blocklist new domains at the resolver.

More in the State of Shadow AI 2026 report →

Head to head

Side by side

Where it sees AI
ShadowLock
Endpoint clipboard + browser + M365 tenant via Microsoft Graph.
Control D
DNS resolver only.
M365 tenant / Copilot OAuth
ShadowLock
Graph integration scans for AI OAuth grants and Copilot plugins; alerts on new consent.
Control D
Not visible at the DNS layer - OAuth consent never produces a resolver query from the endpoint.
Embedded AI inside approved SaaS
ShadowLock
Caught at the paste layer.
Control D
Not caught - same blind spot as any DNS filter.
Data classification
ShadowLock
Local Shannon entropy + Luhn + tiered confidence on every paste.
Control D
None - DNS is categorical, not content-aware.
Pricing
ShadowLock
Per managed device, billed monthly, no minimum. Rate card emailed on request, usually within five minutes.
Control D
Public SMB self-serve rate of $2/endpoint/month. MSP pricing is arranged through the partnerships programme and is not published.

Easy to buy, but two different layers

What ShadowLock and Control D share is that both are straightforward to buy in an MSP market where most browser-security and DLP competitors route every conversation through a sales cycle. What they don\'t share is layer.

Control D resolves a name, decides allow or block, and the rest of the stack never sees the request. ShadowLock runs after the connection - inside the device - and decides allow or block based on what the user actually pastes. The two are complementary far more than they\'re competitive: most shops that take shadow AI seriously run a DNS layer for the easy categorical wins and an endpoint layer for the nuanced ones.

Fit

Which one fits your situation?

Choose ShadowLock when…

  • You need content-level enforcement - "allow ChatGPT but block sensitive pastes."
  • You use Copilot, Notion AI, or any embedded AI inside approved SaaS that DNS can't separate.
  • You need clipboard-level classification for HIPAA, SOC 2, or GDPR.
  • You can't guarantee every device routes through the Control D client every time.

Control D still fits if…

  • You want a transparently priced DNS filter as a baseline network-edge layer.
  • Your AI threat model is "block every AI domain at the resolver" and that genuinely satisfies your governance team.

FAQ

Frequently asked questions

Do ShadowLock and Control D conflict on the same endpoint?

No. Different layers - Control D is a DNS resolver / roaming client; ShadowLock is a Windows service. They run alongside cleanly.

Can Control D block AI features embedded in approved SaaS?

No - same blind spot as any DNS filter. Copilot, Notion AI, and Einstein all resolve to allowed domains. ShadowLock catches them at the paste layer.

How does the pricing compare?

Control D publishes an SMB self-serve rate of $2/endpoint/month; its MSP pricing runs through the partnerships programme and is not published. ShadowLock is priced per managed device per month on volume tiers with no minimum, and the rate card is emailed on request, usually within five minutes. Different layers, and neither one makes you sit through a sales cycle to get a number.

Sources and verification

Every competitor claim below links to that vendor’s own public documentation. Where a vendor does not publish an answer, we say so rather than presenting silence as proof. Competitor facts on this page were last checked on . Pricing and features change without notice — verify against the vendor before you buy.

  • Control D pricing ↗ — Published SMB self-serve pricing of $2 per endpoint per month. MSP pricing is arranged through the partnerships programme rather than published.

Ready to see it on your own endpoints?