Your AI agents now read web pages nobody on your team has checked. What they read shouldn’t become what they obey — Menlo Agent Runtime Security opens each AI agent’s web session in a disposable cloud container, strips hidden instructions and scripts from the page, and logs the run — reached by proxy or MCP.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Menlo Agent Runtime Security (MARS) — Menlo’s runtime for AI agents that browse. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A separate place for an AI agent to browse, so pages it opens are cleaned and contained before the model reads them.
What consolidation actually replaces, dimension by dimension.
| Dimension | Agents browsing from your hosts | Menlo Agent Runtime Security |
|---|---|---|
| Where agent browsing runs | On the server or laptop hosting the agent | A disposable container in the Menlo Cloud |
| Text hidden in a page | Passed straight into the model’s context | Stripped before the agent reads the page |
| Commands versus content | Mixed together in one context window | Instruction/data separation in the runtime |
| Systems with no API | Fragile scripts or a person re-keying data | Read in an isolated session, fields masked |
| Evidence after an incident | Scattered agent and proxy logs | Tamper-proof audit logs per session |
| What it is NOT | — | An LLM app firewall, a public price, or Indian log storage |
The cheapest test is one agent and a dozen booby-trapped pages: see what reaches the model with MARS in the path, and what reached it before.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Every web session an agent opens runs in a remote container that is thrown away afterwards, so page code executes in Menlo’s cloud rather than on the machine hosting the agent.
Before page content reaches the model, Menlo removes malicious scripts, hidden instructions and steganography, and the runtime keeps the agent’s instructions apart from page data.
Menlo documents two ways in: a proxy for agents whose web traffic can be steered, or an MCP integration for agents that call tools; which suits depends on how each agent is built.
Fields pulled from web screens with no API can be masked in transit, and each session is written to tamper-proof audit logs; Menlo lists its logging and Log Export API as global.
Disposable cloud containers for agent browsing — pages cleaned before the model reads them, every session written to an audit log.
Menlo Agent Runtime Security gives AI agents a contained place to browse, cleaning each page before the model reads it.
Agent sessions open in remote containers that are discarded when the job ends, so a hostile page has nothing lasting to hold on to.
Agents can read data held behind web interfaces that expose no API, with the browsing itself done inside Menlo’s isolated runtime.
Steer an agent’s web traffic through a proxy, or wire the runtime in as an MCP integration for agents built around tool calls.
Instructions concealed in a page to hijack an agent are stripped out, so the model receives the content and not the attacker’s orders.
Malicious scripts, and data hidden inside images or files by steganography, are removed from what the agent is handed, per Menlo.
The runtime enforces instruction/data separation, so text read from a website is treated as material to process, not as commands.
When an agent pulls records from a web application, sensitive values can be masked on the way, before they reach the model or its output.
Sessions are written to tamper-proof audit logs, giving risk teams evidence of what each agent opened and what it brought back.
Menlo’s August 2026 update extended MARS to Microsoft Copilot, Gemini in Chrome, Claude Code and Claude Cowork.
Menlo on securing staff and AI agents on one platform, keeping a human in the loop, and its machine-to-machine work with Google Cloud.
Menlo’s framing of staff and AI agents as one workforce that needs browser-level protection.
How the Browser Security Platform extends from people at a browser to agents that browse on their own.
Where a person stays in the decision when an agent acts on the web.
Menlo and Google Cloud on defending machine-to-machine traffic in enterprise settings.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
An agent that browses takes in whatever a page holds, including text no person would ever see. MARS runs that browsing in a disposable container in the Menlo Cloud and strips malicious scripts, hidden instructions and steganography first, so the model is handed cleaned content rather than the raw page.
Indirect prompt injection succeeds when words an agent reads get treated as orders. Menlo builds instruction/data separation into the runtime, so text lifted from a website is processed as material, never obeyed as a command. Run your own injection test set against it before you rely on that claim.
Plenty of supplier portals and older internal systems only offer a web screen. MARS lets an agent read data behind those API-less interfaces from inside the isolated session, masks sensitive fields on the way through, and writes each session to tamper-proof audit logs for later review.
It is young: launched in March 2026 and widened in August. There is no public price, no analyst rating and no named Indian customer. Menlo lists logging as global, so Indian log residency cannot be assumed. It guards agents’ web sessions; screening prompts sent to an LLM app you host is a different job.
Inventory every agent, assistant and script that opens web pages, what sites it visits and what data it can touch.
Decide whether each agent joins through the proxy or an MCP integration, starting with the one that reaches outside sites.
Build test pages carrying hidden instructions and scripts, run the pilot agent through MARS, and record what reaches the model.
Set masking for sensitive fields, export logs to your SIEM, and agree who reviews agent sessions and how often.
Add further agents, then get the quote in INR with GST that names the package, add-ons and the support tier you need.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our procurement agent reads supplier portals that have no API. Running those sessions in Menlo’s containers kept page code off our servers.”
“We planted hidden instructions in a test page and the agent’s view arrived without them. Build your own injection set before trusting anyone.”
“The audit log answered what our risk committee kept asking: which pages did the agent open, and what did it carry back?”
“It is early days. The quote took weeks, and routing our in-house agent framework through the proxy needed real engineering time.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the AI agent security market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Launched March 2026; quote-only.
The grid nobody publishes — how much of an agent’s work it covers (browsing, tools, MCP) vs how deeply it defends against content-borne injection.
Isolates agent browsing; strips hidden page text.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Palo Alto Prisma AIRS, SentinelOne Prompt Security, Akamai Firewall for AI, Azure AI Content Safety and Amazon Bedrock Guardrails — on agent coverage, injection depth, price, audit, India and exit.
| Dimension | Menlo Agent Runtime Security | Palo Alto Prisma AIRS | SentinelOne Prompt Security | Akamai Firewall for AI | Azure AI Content Safety | Amazon Bedrock Guardrails |
|---|---|---|---|---|---|---|
| What it is | Isolated agent browsing | AI security platform | AI usage and agent guard | Firewall for LLM apps | Moderation service | Configurable guardrails |
| Deployment | Cloud, proxy or MCP | Intercepts plus MCP | Browser, desktop, MCP | Edge, REST or proxy | REST or Foundry | Inline or by API |
| Agent coverage | Agents that browse | Agents and MCP tools | Four touchpoints | Apps, not agents | Foundry agents | Model calls only |
| Pricing model | Products and users | Tokens per month | Not published | Quote, unit unknown | Per 1,000 records | Per 1,000 text units |
| Published entry price | Not published | No public rate | Not published | Demo form only | $0.375 per 1K records | $0.15 per 1K units |
| Included vs add-on | Packaging unstated | SCM, DLP, logging | Singularity module | Own SKU | Shields in free tier | Policies billed apart |
| Published limits | None published | 2 MB sync, 5 MB async | Coverage, not caps | None published | 5 documents a call | 1,000-character units |
| Threat depth | Scripts, hidden text | Agent-specific threats | Injection, leakage | OWASP LLM Top 10 | Harms plus attacks | Six policy types |
| Integrations | Proxy, MCP, log export | Strata stack, SDK | Singularity Platform | Edge, REST, proxy | Foundry and REST | Bedrock, SageMaker, EC2 |
| Audit and governance | Tamper-proof logs | Strata Logging | Agent action log | Behind login | Your thresholds | AWS resources |
| India region | Mumbai node; logs global | India region, Aug 2025 | Not published | Not documented | South India meters | Mumbai Region |
| Support | Basic or Care360 | Not on product pages | Via SentinelOne | Set per contract | Paid plan from $29 | Paid AWS plan |
| Lock-in and exit | Sessions in Menlo Cloud | Region-bound keys | Tied to Singularity | Edge mode on Akamai | Microsoft’s categories | Checks run in AWS |
| Best fit | Agents on the open web | Palo Alto estates | Workforce AI plus agents | Public LLM apps | Azure Foundry builders | Builders on AWS |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
TechBag has no AI agent security guide yet, so Menlo Agent Runtime Security sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →
Drag the sliders (AI agent workflows that browse; security-team hour cost). Estimates model security and engineering time spent reviewing what browsing agents read, investigating suspected injections and assembling evidence at an assumed 1.5 hours per workflow a year, with 70% of it removed by an isolated runtime and session audit logs. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: Menlo prices by the products deployed and the number of user licences, with add-ons on top, and names no rate or licence unit for MARS. Its EchoQuote estimator gives budgetary figures. TechBag inventories your browsing agents first, then gets the quote in INR with GST.
Best for proving injection defence
Best for a broader rollout
Best for assistants plus in-house agents
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which agents and assistants browse the web today, and which ones read pages from sites you do not control?
Can each agent’s traffic be steered through a proxy, or does it call tools over MCP and need that integration?
Do you have your own pages with hidden instructions and scripts to test what MARS lets through to the model?
Which portals or legacy screens will agents read, and which fields there must be masked before the model sees them?
Where will audit logs go? Menlo lists logging as global, so plan a SIEM export for retention you control in India.
Do you run Microsoft Copilot, Gemini in Chrome, Claude Code or Claude Cowork, the ones named in the August expansion?
Which Menlo package or add-on carries MARS, what is the licence unit, and is it priced per agent or per user?
Which features are generally available today, and which are roadmap? Ask Menlo to confirm it in writing.
List the agents that open web pages for you, or let a TechBag advisor scope a pilot that runs one agent through MARS against crafted injection pages.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.