
Sharelock
Sharelock Identity Security Platform unifies identity threat detection (ITDR) and identity security posture management (ISPM). Unsupervised behavioural analytics and autonomous AI agents cover human and non-human identities across on-premises, cloud and hybrid estates, for enterprise security and SOC teams.
What is Sharelock?
Sharelock Identity Security Platform is the product of Sharelock Srl, an Italian vendor that positions it as AI-Native Identity Security under the line “Protect every digital identity, everywhere”. Its starting thesis is that identity has become the security perimeter: attackers increasingly sign in with valid credentials instead of deploying malware. Sharelock quotes market figures in support — identity involved as a vector in 80% of detected attacks, cloud intrusions using valid credentials up 75% in a year, 25% of attacks starting from unprotected identities. These are third-party market statistics cited by the vendor, not measurements of its own product.
The platform is sold as one product built from three modules. Prevention (ISPM) covers identity security posture management: automatic account discovery, policy enforcement, removal of inactive accounts, risk-based access reviews and least-privilege enforcement. Detection (ITDR) applies behavioural analytics to credential access, privilege escalation and lateral movement, across on-premises, cloud and hybrid environments. Response (SIA — Security Investigation Autopilot) puts autonomous AI agents to work: they investigate on their own, correlate context and trigger a response such as blocking access or isolating an account, interfacing with identity systems, SIEM, SOAR and ticketing tools.
The method claimed is “no-rules, no-policies”: unsupervised machine learning builds an individual behavioural baseline for each identity rather than relying on static rules that have to be written and maintained. Coverage extends past people to non-human identities — service accounts, API keys, machine identities and unmonitored AI identities. Integration is described as native with IAM, IGA, PAM, IdP, business applications, cloud and legacy systems, with 20+ IAM, PAM and CIEM systems claimed, though that list is never published. Six use cases are documented: privileged account misuse, lateral movement, insider threat, account profiling, risk-based access reviews, and least-privilege and MFA enforcement. The platform is presented as zero-code.
Sharelock claims repeated analyst recognition: Innovation Leader in the KuppingerCole ITDR Compass 2025, sole European company in the KuppingerCole Leadership Compass ITDR 2024, Leader and Outperformer in the GigaOm Radar 2025, and a mention in a Gartner report on Agentic AI. The founding core comes from CrossIdeas, an IGA vendor acquired by IBM in 2014.
What it does
- Discover and map every account across all identity silos, including orphaned, dormant and over-privileged ones
- Detect access and post-access behavioural anomalies in real time, on-premises, in the cloud and in hybrid estates
- Block sessions, accounts and users when a complex or zero-day identity attack is under way
- Investigate incidents automatically through the SIA module, without writing a single query
- Enforce least privilege and add MFA wherever it is missing
- Run access reviews prioritised by risk rather than by calendar
- Protect non-human identities: service accounts, API keys, machine identities and AI identities
When to use Sharelock / When not to
A quick filter to help you decide if Sharelock is the right fit.
When to use Sharelock
- Enterprises whose identity infrastructure is scattered across several silos — access management, IAM, IGA and PAM — and who need one view over all of them
- Security operations centres worn down by false positives from static, rule-based identity tooling
- Hybrid organisations grown through acquisition, running identities both on-premises and in the cloud: one published case study describes a global fintech with 7,000 employees, 30 countries and four continents
- Companies exposed to insider threat and internal fraud — the Italian food group Fabbri 1905 is cited as a customer on exactly that ground
- Governance and IAM teams that must run recurring access reviews and evidence account hygiene to auditors
When not to use Sharelock
- Individuals and consumers, including anyone looking for something like a password manager: this is an enterprise platform with no individual account and no personal sign-up
- Small businesses with no corporate directory: the platform is designed to plug into an existing identity stack (IdP, IAM, IGA, PAM) rather than to replace it
- Buyers who want a self-service entry point — there is no online registration, no free plan and no free trial, only a mailto link to info@sharelock.ai
- Teams that must compare published prices before engaging a vendor: no rate card, no pricing page and no terms and conditions exist on the site
- Developers or integrators expecting public API documentation or a mobile app: nothing of the sort is published, and no app, console, docs or api subdomain resolves
How to use Sharelock
A typical end-to-end flow, from setup to results.
- Start from the website knowing there is no self-service: no online sign-up, no account creation and no open demo environment
- Use one of the two calls to action present on every page — CONTACT US or ASK FOR A DEMO — both of which are mailto links to info@sharelock.ai with a pre-filled subject
- Read the HOW IT WORKS page and download the datasheets, brochures and guides; the resource form asks only for a name and an email address, and gives access to documents, not to the product
- Scope the deployment with the vendor: the platform is meant to plug natively into the identity infrastructure already in place — IAM, IGA, PAM, IdP, business applications, cloud and legacy systems
- Plan the connections to the SecOps stack as well: SIEM, SOAR and ticketing tools
- Discover: let the platform map every account across the identity silos, orphaned and dormant ones included
- Assess: have findings prioritised by risk rather than reviewed in bulk
- Fortify: remediate and harden — remove inactive accounts, enforce least privilege, add the missing MFA
- Where SailPoint IdentityIQ or One Identity Manager is already in place, signals and keep/review/revoke recommendations can be surfaced inside that tool’s own interface for business managers
- Expect no published timeline: neither deployment duration, nor technical prerequisites, nor a rollout procedure is documented on the site
Pros & Cons
Pros
- ITDR and ISPM in a single platform rather than two separate tools to buy, deploy and reconcile
- Unsupervised approach: no rules to write or maintain, and baselines that follow behaviour as it changes
- Non-human identities are in scope — service accounts, API keys, machine and AI identities — which the vendor presents as the blind spot of endpoint-centric solutions
- Autonomous investigation with neither a query nor a prompt to write, where competing assistants still expect one
- Signals delivered inside the tool the customer already uses, documented for SailPoint IdentityIQ and One Identity Manager, with keep/review/revoke recommendations aimed at business managers
- Auditability is claimed rather than assumed away: audit trails and role-based access control over agent actions, presented as explainable rather than black-box AI
- European vendor with a founding team from CrossIdeas, an IGA vendor acquired by IBM, and recurring independent analyst recognition in 2024 and 2025 (KuppingerCole, GigaOm, a Gartner mention)
Cons
- No public pricing of any kind — no rate card, no tier, not even an order of magnitude — so no budget can be framed without going through sales
- No free trial, no free plan and no self-service demo; the only door is a mailto link, with no contact page and no form anywhere on the site
- No terms and conditions and no legal notice are published: the privacy and cookie policy is the site’s only legal page, so the contractual framework cannot be read before making contact
- No security certification is claimed — neither ISO 27001 nor SOC 2, nor any third-party audit — which is notable for a security vendor
- The privacy policy covers the website only: nothing is published about the hosting, the retention or the ownership of the identity data the platform processes, nor about model training
- No public API documentation and no active docs or api subdomain, for a platform sold as deeply and natively integrated
- The 20+ IAM, PAM and CIEM systems claimed are never listed, only two integrations are documented by name, and the site contradicts itself on the company address — Rome in the footer, Tivoli in the privacy policy, same VAT number
Pricing & Plans
No price is published anywhere on the sharelock.ai website. There is no pricing page: the /pricing URL returns a genuine 404 and the complete sitemap, 53 URLs, contains none. No free plan and no free trial are announced, and no currency, billing unit or tier appears on any page, nor any mention of credits, seats or billed volume. The commercial model is therefore contact-sales: a quotation can only be obtained by writing to info@sharelock.ai, which is the single entry point the site offers.
- the site names no tier
- no service level and no add-on
- The offer is presented as a single platform combining three modules — Prevention (ISPM)
- Detection (ITDR) and Response (SIA) — without saying whether they are sold separately or only as a block
Data, GDPR & hosting
A consolidated view of how Sharelock handles your data.
GDPR overview
GDPR is explicitly addressed, but for the website alone. The policy states that sharelock.ai is operated by Sharelock Srl, an Italian company subject to Regulation (EU) 2016/679, claims Privacy by Design and Privacy by Default, and qualifies Webflow, Cloudflare and Google as Article 28 processors. Transfers outside the EU rely on standard contractual clauses and on those providers’ own Data Privacy Framework adherence — their commitments, not Sharelock’s. Because the company is established in Italy, no Article 27 representative is required. No DPO is named; info@sharelock.ai is the address given for any request about processing. What is missing is substantial: no effective or last-updated date on the policy, no retention schedule, no certification claimed anywhere (neither ISO 27001 nor SOC 2), and nothing about the identity data the platform processes for customers. A separate accessibility statement claims partial conformity with UNI EN 301 549 / WCAG 2.1 AA.
Who owns the data?
Sharelock Srl, with a registered office at Piazza Plebiscito 16, 00019 Tivoli, Rome (Italy) and VAT number 14054121000, is the controller for the sharelock.ai website — and the published policy covers that website only, not the platform delivered to customers. For the site, Sharelock states it collects no personally identifiable information unless a visitor supplies it through a form or direct communication, and that it does not sell personal data. Any visitor, wherever located, may request access, deletion or withdrawal of consent, and may object to processing based on legitimate interest; California and other US residents are told they hold additional rights. Nothing is published about who owns the identity data the platform itself processes.
Reuse rights
The website privacy and cookie policy is the only document available, and it addresses the site alone; there are no terms and conditions to consult, and nothing states what the platform may do with customer data. For the site, data serves technical operation, security, performance and aggregated usage statistics. Sharelock invokes legitimate interest (Art. 6.1.f GDPR) for hosting and CDN, and explicit consent (Art. 6.1.a) for analytics cookies — _ga, _gat and cookie_notice_accepted — which are set only after the banner is accepted. Three processors are named: Webflow Inc. (hosting and CMS, United States), Cloudflare Inc. (CDN, security, performance, United States) and Google Analytics (Google Ireland Ltd and Google LLC). Browser Do Not Track signals are honoured where applicable, and transfers outside the EU rely on standard contractual clauses together with those providers’ own adherence to the EU-U.S. Data Privacy Framework — commitments made by Webflow, Cloudflare and Google, not by Sharelock. No position is published on whether customer data is reused to train models.
Data retention & training
Hosting summary
The only hosting Sharelock documents is that of its website, not of the platform it sells. The privacy and cookie policy names Webflow Inc. for hosting and CMS and Cloudflare Inc. for CDN, security and performance, both located in the United States, plus Google Analytics supplied by Google Ireland Ltd and Google LLC, whose analytics data may be processed on servers outside the EU. For those transfers the policy invokes standard contractual clauses and the providers’ own adherence to the EU-U.S. Data Privacy Framework — safeguards offered by Webflow, Cloudflare and Google, not commitments made by Sharelock. The domain’s IP address, 198.202.211.1, resolves to a Cloudflare anycast node, which says nothing about where any application actually runs. Nothing at all is published about the hosting of the platform delivered to customers: no country, no region, no data residency option. Readers should not infer from the United States appearing above that their identity data would be processed there — the site simply does not say.
Things to keep in mind
Risks and trade-offs to weigh before adopting Sharelock.
- The site contradicts itself on the company address: every page footer shows Via Gustavo Giovannoni 76, 00128 Rome, while the privacy policy gives a registered office at Piazza Plebiscito 16, 00019 Tivoli — same VAT number, 14054121000. Ask which entity and which address a contract would name.
- The founding date is inconsistent as well: the About page shows a 2017 timeline while the first Wayback capture dates from 16/11/2018, so no founding date is stated here.
- No security certification is claimed by a security vendor — no ISO 27001, no SOC 2, no third-party audit. The DPAs and Data Privacy Framework memberships visible on the site belong to Webflow, Cloudflare and Google, the website’s providers, and say nothing about Sharelock itself.
- The privacy policy covers the website only. It is silent on what the platform does with customer identity data — among the most sensitive data an organisation holds — on how long that data is kept, and on whether models are trained with it.
- No terms and conditions are published, so the contractual framework cannot be read before making contact, and the site offers no way to reach the vendor other than an email link.
- The performance figures — accuracy up to 98%, investigation time cut by 80%, 27 hours saved per analyst per week, investigations 37% more exhaustive — are vendor claims with no published methodology. Treat them as hypotheses to test in a proof of concept, not as measured results, and note that the 20+ IAM, PAM and CIEM systems claimed are never listed.
- Automation carries its own human risk: agents that block sessions, isolate accounts and rank access reviews can quietly take the place of the team’s own judgement, and analysts who stop investigating lose the reflex. Sharelock claims audit trails and role-based access control over agent actions — worth testing rather than assuming.
Setup & Integrations
Technical difficulty
High, and impossible to size from the public site. There is no self-service: implementation starts with a sales conversation. The platform assumes an identity infrastructure already in place — IAM, IGA, PAM, IdP, business applications, cloud and legacy systems — plus connections to SIEM, SOAR and ticketing. Sharelock describes the integration as native and the platform as zero-code, but behavioural analytics needs a learning period to build individual baselines and no duration is published. No installation time, no hardware or software prerequisite and no rollout procedure appears anywhere. A security or SOC team is required, not an end user.
Integrations
Behind Sharelock
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Sharelock.
Frequently asked questions
What is the Sharelock Identity Security Platform?
How much does Sharelock cost?
Is there a free trial or a free plan?
How do I get a demo?
Does the platform protect non-human identities?
Which systems does it connect to?
Is there a public API?
Which certifications does the vendor hold?
Where is the data hosted?
Who publishes the tool?
Should you pick Sharelock?
Sharelock is a mature enterprise product with an unusually clear position: identity threat detection and identity security posture management in one platform, driven by unsupervised behavioural analytics rather than by rules, and extended by agents that investigate on their own. Three analyst houses recognised it across 2024 and 2025 — KuppingerCole, GigaOm and a Gartner mention — and the founding team comes from CrossIdeas, an IGA vendor acquired by IBM. The product side is genuinely well documented: three modules, six use cases, a named integration perimeter and two integrations described in detail.
The commercial and legal side is the opposite. No price, no rate card, no order of magnitude. No terms and conditions, no legal notice, no API documentation. No security certification claimed, which is worth pausing on for a security vendor. The privacy and cookie policy — the site’s only legal page — covers the sharelock.ai website and nothing else, so a prospective customer learns nothing about where the platform is hosted, how long it keeps identity data, who owns that data, or whether it feeds model training. The DPAs and Data Privacy Framework memberships cited in that policy belong to Webflow, Cloudflare and Google, the website’s own providers.
The performance figures on display — investigation time cut by 80%, accuracy up to 98%, 27 hours saved per analyst per week — are vendor claims published without methodology, and the site even contradicts itself on the company’s own address. None of that makes the product weak; it makes it impossible to evaluate from a distance. Anyone interested will have to write to info@sharelock.ai and ask, in the very first conversation, for the contractual and data-processing documents the website does not publish.
- Choosing a selection results in a full page refresh.
- Opens in a new window.