Monitoring, remote control, backup, a credential vault and a helpdesk. One login, one bill, unlimited devices. Built by the MSP that runs its own desk on it.
Australian owned and hostedMelbourne, AustraliaData in ap-southeast-2Est. 2026
0+
Endpoints under management today
$0
Per technician, per month, plus GST. Every feature, unlimited devices
One bill
Instead of five vendors, five renewals and five support queues
The consoleapp.lockmsp.com
app.lockmsp.com/devices
Australian owned and hostedISO 27001 certification in progressSOC 2 certification in progressAES-256-GCM credential vaultRSA-signed agent releasesBackups land in your own AWSMulti-tenant isolationEvery vault reveal audited
Australian owned and hostedISO 27001 certification in progressSOC 2 certification in progressAES-256-GCM credential vaultRSA-signed agent releasesBackups land in your own AWSMulti-tenant isolationEvery vault reveal audited
01
Remote monitoring
One line installs the agent. From then on it streams CPU, memory and disk, and raises the alert before the customer picks up the phone. Machines group into sites, so every client has a clean view of their own estate.
Immutable, always-on, one-click restore
04
Credential vault and helpdesk
Passwords, secrets and live TOTP codes encrypted with AES-256-GCM, with every reveal on the audit trail. Tickets arrive at a per-tenant address or the public portal, and the reply goes out under your own name.
AES-256-GCM, every reveal audited
Live scrolling 2FA codes
Email-in tickets and public portal
Your from-name and signature
02 / Structure
One console, however the estate is carved up
Sites for an MSP are customers. For an internal team they are offices, departments or campuses. Same structure either way. One console above, isolated tenants below.
LockMSP consoleOne login / one bill / role-based access
Site 01Head office
Servers, workstations, the domain controller
104 devices
Site 02Warehouse
NAS, scanners, the backup target
38 devices
Site 03Clinic
Reception, consult rooms, one print server
61 devices
Site 04Remote and field
Laptops on home and mobile networks
45 devices
A diagram of how tenants and sites are structured. Device counts are an example estate.
03 / Who it is for
An MSP tool that internal IT teams can live in too
The job is identical: keep the machines patched, get on them fast when they break, hold the credentials safely, answer whoever raised the ticket. An internal team just does it for one organisation instead of thirty, and pays for technicians, not machines.
Managed service providers
Every customer isolated: their own devices, documentation, credentials and ticket queue. Taking on a client costs nothing extra in licensing.
Internal IT teams
One organisation, nothing switched off. Split by site, department or campus, and pay for the technicians who use it.
Either way, the same platform
No editions, no modules to buy back. Every seat has the whole thing from the first day of the trial.
04 / In every seat
Also in every seat
Six more, no upsell
01Script toolboxes
Saved PowerShell and batch scripts, run on any machine in seconds. Clear the print queue, restart the service, done.
02AI auto-documentation
Remote sessions are written up automatically from the recording, ready to file. The knowledge base builds itself.
03One-time contractor links
A time-limited link to one machine, dead after they connect or when it expires. No account to create.
04Access control and audit
MFA, IP allow-listing, role-based access and super-admin impersonation, with the whole trail behind it.
05Self-updating agent
Updates itself from RSA-signed releases, verifying signature and hash before it swaps a binary.
06Asset and app inventory
What is installed, where, and on which build, with event logs, services and scheduled tasks a click away.
05 / Security
You hold the keys to every client you look after
An RMM is the most privileged software an MSP runs: it can reach any machine, on any client site, at any hour. We build it as though somebody is already inside, because the controls that matter are the ones that hold when they are.
Locked by default
Multi-factor is mandatory on every account, not a setting an owner can forget. Add IP allow-listing, roles scoped to individual customers, and a remote-access level per technician: unattended, or the person at the machine accepts first.
Credentials never sit in the clear
The vault seals each secret under its own key, and those keys under a master held in AWS KMS. Reading one is an auditable act, and the trail records who opened what and when.
The sensitive actions ask why
Joining a customer's tenant, restoring their mail, watching a recorded session: each writes an audit entry, and the ones that warrant it will not run until the technician states a reason. That is what you hand an auditor.
06 / On a schedule
Security that does not wait to be remembered
Running while you sleep
Every control below runs on a timer rather than a good intention. The point of a posture screen is not that somebody looks at it; it is that the platform keeps looking when nobody does.
01Patch compliance
Every machine reports what it is missing and how severe. Windows updates install inside the maintenance window you set, per policy, per site.
02Encryption posture
BitLocker across the whole fleet on one screen: which disks are protected, and whether anybody could actually recover them.
03Threshold alerting
Rules evaluated continuously against live telemetry, raising a ticket on the rising edge rather than every minute it stays wrong.
04Retention that enforces itself
Recordings, activity history and metrics are pruned to the periods you set. There is deliberately no "keep forever": a schedule the product does not honour is not a schedule.
05Backups that prove themselves
Endpoint backups run to their own schedule, and the console reports what could actually be restored rather than whether a job ran.
06Signed agent updates
New agent releases roll out from RSA-signed manifests, with the signature and hash verified on the endpoint before a binary is replaced.
07Stale access expires
Contractor links die on use or on expiry, one-time shares open once, and offline machines age out on the schedule you choose.
Click a machine and you are on it before you have finished sitting forward. The mouse feels wired in, not posted overseas. That speed is engineered, not promised.
01 / Connect
Woken, not waited on
Your click wakes the machine itself. No polling, no spinner: a live screen in a second or two.
02 / Control
A relay near every fleet
Relays run in AWS regions around the world and every session pairs on the nearest one. Round trips stay under 50 milliseconds, and remote stops feeling remote.
<50ms
Round trip for a fleet near one of the relay regions, instead of an ocean crossing on every mouse movement.
A$77 a month all up on a tax invoice. Every seat carries the whole platform, including RMM, remote control, backup, vault, helpdesk and AI auto-docs, with unlimited managed devices. Monthly billing, cancel any time, no card to start the trial.
Charged on usage
The heavy lifting that costs real money is metered, pooled across the account and itemised on the invoice. A quiet month costs less.
Device backup
File and full-image backup. Point it at your own AWS bucket, or use ours.
$2per device + storage*
AI auto-documentation
Every recorded remote session written up. Flat rate, any volume.
$5per month
* We encourage you to use your own AWS bucket: point backups at it and you pay us nothing for storage. Our storage is charged monthly at $0.20 per gigabyte, with usage visible in-platform before it reaches the bill. All amounts are AUD and exclude GST; 10% is added and itemised on your tax invoice.
09 / Get started
Start the trial.Bring one client.
Create your account, verify your email, and your trial starts on the spot. Nothing to pay up front, no card, and we will help you migrate off the stack you are on.
Live in minutes on a one-line agent install
We help you migrate off your current tools
Australian owned and hosted, and you can talk to us