Active laptop theft protection

The moment it's grabbed, it locks.

The cable is just one trigger. Moorlock detects the theft on the device itself — no network, no cloud round-trip — then locks or shuts down instantly, captures who did it, and keeps tracking until you have it back.

Open sourcemacOS · Linux · WindowsAll platforms & source
MOOREDtether attached
How it works

A cord between you and your data.

No agents to babysit, no cloud round-trip in the critical moment. The trigger fires locally, the instant the tether breaks.

Step 01 · Tether

Clip in

A magnetic breakaway USB cable runs from your laptop to your belt. Arm it — or let it auto-arm on wake, on battery, or off trusted Wi-Fi.

Step 02 · Separate

They grab it

The connector breaks away cleanly — no damaged ports, no yanked laptop. That break is the signal. An optional grace period forgives a knock.

Step 03 · Trigger

It defends itself

Instantly locks or shuts down, sounds an alarm, photographs whoever's there, and sends you an alert with the laptop's location.

What it does

Protect. Prove. Recover.

If someone takes your unlocked laptop, Moorlock locks it before they can use it — then proves what happened and helps you get it back. Everything else serves those three outcomes.

01

Protect

Locked before they can use it

The instant your tether breaks, the machine locks or shuts down — faster than a thief can act.

  • Sensor fusion — USB, FIDO2, Bluetooth, power, Wi-Fi, wake
  • Clone-proof FIDO2 tether — the secret never leaves the token
  • Duress PIN and evil-maid watch
  • Self-healing watchdog — restarts if it's stopped, alerts on tamper
02

Prove

Capture who did it

Webcam and screen frames the moment it triggers, delivered off the machine before it's gone.

  • Webcam + screen capture on trigger
  • Encrypted at rest with a per-account key
  • Alerts anywhere — email, Signal, Slack, webhooks
03

Recover

Find where it went

Location with every alert — and it keeps working after the network is gone.

  • Approximate location on every trigger
  • Works offline — reports when connectivity returns
  • Theft mode — keeps tracking until you clear the incident
Where it fits

It reacts at the moment of theft — not after.

Detecting a USB unplug and locking a screen isn't new. Moorlock's edge is everything around it — multi-sensor detection, evidence, recovery and fleet control, all local-first.

vs. kill cords

A kill cord (like BusKill) locks on unplug — and stops there. Moorlock treats the cable as one trigger among many, and adds multi-sensor detection, evidence capture, recovery, remote response and fleet management on top.

vs. recovery apps

Prey, Find My and MDM mostly help after a device is already gone. Moorlock acts at the instant of physical theft — locking the machine before your unlocked session is exposed.

Local-first

Detection, lock, alarm and shutdown run entirely on-device — no network, no cloud round-trip, so they fire even with Wi-Fi cut. The cloud only adds encrypted history, recovery and fleet control.

Hardware

Tether it your way.

Moorlock triggers on whatever tether you choose — a breakaway cable, a security key, your phone, the charger, or a plain USB drive. It's hardware-agnostic: bring your own, or buy the cable.

USB-A / USB-C

Magnetic breakaway cable

The kill cord. A magnetic connector clips you to the laptop and separates cleanly the instant it's grabbed — no damaged ports.

highest assurance

YubiKey / FIDO2 key

The premium tether: a cryptographically authenticated physical tether. The secret is hardware-sealed on the key and never leaves it, so unlike a keyfile it can't be copied or cloned — verified every second.

BLE

Phone or watch

Bluetooth proximity tether. Walk out of range while armed and it triggers — a dead-man's switch with no cable at all.

AC

Power adapter

Charger tether. Snatch-and-run usually yanks the power cable first — unplug it while armed and Moorlock fires.

keyfile

Any USB drive

Cryptographic keyfile. Turn a spare stick into your cord — a random secret re-checked every second. Convenient and free, though a plain keyfile can be copied; for a clone-proof tether, use a FIDO2 key.

No proprietary dock, no subscription to arm. The cable is the only optional purchase, and any magnetic-breakaway USB cable works.

Popular setups
Field reporter

On the move

  • Magnetic cable on a belt clip
  • Encrypted keyfile on the drive
  • Evidence capture + location
At the desk

Cable-free

  • Power-adapter tether
  • Bluetooth phone in range
  • Auto-arm off trusted Wi-Fi
Border crossing

Coercion-ready

  • YubiKey pinning
  • Duress PIN + soft-shutdown
  • Evil-maid wake watch
Open by design

Trust is earned in the source.

Security software that watches your camera and location has to be auditable. Ours is — every line of the client is open.

Open-source client

Read it, build it, verify it does exactly what it says — nothing hidden.

Encrypted at rest

Evidence and location are encrypted with a per-account key, so a database or storage breach doesn't expose them.

No lock-in, no telemetry

The client works fully on its own with your own alert channels. The cloud is optional.

moorlock — zsh
# arm the kill cord, pinned to your cable
$ moorlock arm --device 046d:c52b
status: MOORED
trigger: lock-screen
keyfile: verified
tether: power + bluetooth
# a disconnect now fires in ~2 seconds
$ moorlock test
✓ USB monitoring hotplug active
✓ Keyfile pinning present & verified
✓ Duress PIN decoy armed
✓ Evidence cam + screen ready
The console

See every device. Act in one click.

The hosted console shows live protection posture, incident timelines, encrypted evidence and last-known location for every device — and lets you sound the alarm, re-arm or disarm remotely.

moorlock.io/app
Moorlock team console showing fleet protection posture, the device list and an open incident with evidence and location
Pricing

Free to protect. Paid to see everything.

The client is free and open source forever. The hosted console adds reporting, encrypted storage, and fleet control.

Show prices in
Client

Free

$0
The full open-source protection engine, on your own machine.
  • Every trigger & protection factor
  • Your own alert channels
  • Local evidence capture
  • macOS · Linux · Windows
Download
Most popular

Personal Pro

$6 /mo
A private hosted console for your own devices.
  • Everything in Free
  • Encrypted evidence & location history
  • Push alerts & remote panic
  • Up to 3 devices
Start free trial
Organizations

Team

$5 /seat
Fleet protection for newsrooms, NGOs, security teams, investigators and travelling execs — anyone handling sensitive devices.
  • Everything in Pro
  • Fleet dashboard & roles
  • Audit log & SSO
  • Priority support
Open console
Questions

Before you tether in

Does it work offline?

Yes. Detection, lock, alarm and shutdown run entirely on the device — no network involved. Alerts and location reports queue while you're offline and deliver when connectivity returns.

What if I forget to disarm before unplugging?

An optional grace period forgives a knock or an honest unplug — reconnect within it and nothing fires. You can also disarm in one action, and auto-arm rules mean you only arm when it matters: on wake, on battery, or off trusted Wi-Fi.

What do I get without paying?

The whole protection engine, forever. Every trigger, every protection factor, local evidence capture and your own alert channels are free and open source. Paying adds the hosted console: encrypted evidence and location history, push alerts, remote actions and fleet management.

Can't a thief just wipe the machine?

No software can stop a wipe — that's what disk encryption is for, and we recommend FileVault or BitLocker alongside Moorlock. What Moorlock protects is the moment of theft: your unlocked session and data are locked away before they can be used, and evidence and location are captured while they still can be.

What hardware do I need?

None that you don't already own. Any magnetic-breakaway USB cable, FIDO2 security key, your phone or watch over Bluetooth, the power adapter, or a plain USB drive can be the tether. Bring your own, or buy a cable from any hardware vendor.

Who can see my evidence and location?

Only your account. Evidence and location are encrypted at rest with a per-organisation key. Our servers can decrypt them to show them in your dashboard — we say that plainly rather than claim end-to-end encryption. The client is open source, so you can verify exactly what leaves your machine.

Get protected

Don't wait for the grab.

Set up in under a minute with a guided dry-run. Then tether in, and stop thinking about it.