ThreatLocker, a global leader in Zero Trust cybersecurity, has raised $190 million in Series F funding led by Elephant, with continued backing from D. E. Shaw Ventures and Arthur Ventures and a significant new investment from Koch Disruptive Technologies.
Founded in Orlando, Florida, ThreatLocker protects more than 70,000 organizations worldwide with a prevention-first, deny-by-default security model. The fresh capital will fund continued development of its AI-related security controls, improvements to its Zero Trust Platform, and international expansion beginning with a new office in Reading, U.K.
Traditional security tools operate on an "allow-by-default" model — they identify malicious activity after it enters an environment. ThreatLocker inverts this: the platform denies anything that has not been explicitly permitted, giving organizations control over the software, users and devices operating inside their environments.
The funding arrives as organizations face a threat landscape reshaped by the need to secure AI agents and defend against AI-accelerated software exploits. ThreatLocker has broadened its platform to address both conventional and AI-driven activity.
Two products carry the weight of ThreatLocker's AI strategy. Allowlisting blocks unauthorized AI tools and AI-generated code from executing at all. Ringfencing™, the containment layer, governs what an approved application or agent can access, modify and interact with once running. Additional controls cover which AI websites employees can use and what data is allowed to leave the environment.
In March 2026, ThreatLocker launched Zero Trust Network Access and Zero Trust Cloud Access, which require a connection to originate from a device the platform has approved before reaching a network or a SaaS application such as Microsoft 365, Salesforce or GitHub. Stolen credentials plus a phished multi-factor code no longer clear the bar.
The AI work sits on a platform that widened considerably. With one control surface spanning endpoints, networks and cloud resources, ThreatLocker gives managed service providers (MSPs) a single security stack to manage application control, network access and cloud policies.
"Since our initial investment, ThreatLocker has demonstrated strong execution, established itself as a product leader, and consistently anticipated where the cybersecurity market is headed," said Jeremiah Daly, partner at Elephant.
The round signals a broader wave of investor interest in default-deny and prevention-based security as organizations move beyond detection-heavy approaches. For enterprises, the practical takeaway is that Zero Trust is becoming easier to deploy and manage — with a single dashboard controlling endpoints, networks and cloud, and now governing how AI agents and AI-generated code behave.
ThreatLocker's growth reflects a fundamental shift in how enterprises approach security. For decades, the dominant model was "allow-by-default" — organizations identified and blocked malicious activity after it entered the environment. ThreatLocker inverts this with a "deny-by-default" philosophy: anything not explicitly permitted is blocked. This prevention-first approach is increasingly seen as more effective against unknown and zero-day threats, where signature-based detection falls short.
The funding is significant for managed service providers (MSPs) who manage security for small and mid-size businesses. ThreatLocker's single platform lets an MSP manage application control, network access, and cloud policies through one security stack — reducing the operational complexity that has historically made Zero Trust hard to deploy. For partners, this means being able to offer enterprise-grade prevention to a broader client base.
The $190 million round positions ThreatLocker to compete as security vendors add controls for AI applications and machine identities to their platforms. Its next phase will center on turning these capabilities into services that customers and partners can manage without adding policy complexity. As organizations grapple with AI agents operating on their infrastructure, the ability to govern what software, users, devices — and now AI agents — can do becomes a defining capability of enterprise security.