Talk to us
by Menlo SecurityTechBag Intel Page

Menlo Agent Runtime Security

Your AI agents now read web pages nobody on your team has checked. What they read shouldn’t become what they obey — Menlo Agent Runtime Security opens each AI agent’s web session in a disposable cloud container, strips hidden instructions and scripts from the page, and logs the run — reached by proxy or MCP.

Agent browsing in disposable containersHidden instructions strippedProxy or MCP integration

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
No MARS figure on Menlo’s pricing page, which quotes by products deployed and user count
Quote
Maturity
Launched in March 2026 and widened in August; confirm what is generally available for your agents
New in 2026
Analysts
No analyst report rates MARS; Menlo’s 2025 GigaOm and Frost placements cover browsing and ZTNA
None yet
India
Proxy and isolation appear in Mumbai on Menlo’s status page, while its logging is listed as global
Mumbai node

Quick answer

Menlo Agent Runtime Security (MARS) opens an AI agent’s web sessions in remote, disposable containers in the Menlo Cloud and strips malicious scripts, hidden instructions and steganography before the agent reads a page. Agents reach it through a proxy or an MCP integration, and sessions leave tamper-proof audit logs. It launched on 18 March 2026, carries no public price, and Menlo lists its logging as global, not Indian. Read more ↓ Show less ↑
Part 01 · Orient

The Menlo Security platform family

This page covers Menlo Agent Runtime Security (MARS) — Menlo’s runtime for AI agents that browse. The rest:

Quick facts

30-second orientation
Product
A cloud runtime that runs each AI agent’s browsing in a remote, disposable container
Maker
Menlo Security, Inc., Mountain View, California; privately held, CEO Bill Robbins since 25 February 2026
Status
Launched 18 March 2026; extended on 5 August 2026 to Copilot, Gemini in Chrome, Claude Code and Claude Cowork
Price
Not published; Menlo prices by products deployed and user licences, and names no MARS rate
Also called
Menlo AI Agent Security in the product menu; MARS for short
Connects
Through a proxy or through an MCP integration, per Menlo’s product page
Removes
Malicious scripts, hidden instructions and steganography, with instructions kept apart from data
Reaches
Data behind web interfaces that have no API, with masking and tamper-proof audit logs
India
Mumbai proxy and isolation nodes on Menlo’s status page; MARS routing unstated; logging global
In India via
TechBag — agent inventory, injection test plan, quote in INR with GST
Part 02 · Learn

Understand agent runtime security before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is an agent runtime?

A separate place for an AI agent to browse, so pages it opens are cleaned and contained before the model reads them.

Agents browsing from your own hosts vs a contained agent runtime — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionAgents browsing from your hostsMenlo Agent Runtime Security
Where agent browsing runsOn the server or laptop hosting the agentA disposable container in the Menlo Cloud
Text hidden in a pagePassed straight into the model’s contextStripped before the agent reads the page
Commands versus contentMixed together in one context windowInstruction/data separation in the runtime
Systems with no APIFragile scripts or a person re-keying dataRead in an isolated session, fields masked
Evidence after an incidentScattered agent and proxy logsTamper-proof audit logs per session
What it is NOT—An LLM app firewall, a public price, or Indian log storage

The cheapest test is one agent and a dozen booby-trapped pages: see what reaches the model with MARS in the path, and what reached it before.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where the agent’s browsing actually happens

Runtime

Disposable containers in the Menlo Cloud

Every web session an agent opens runs in a remote container that is thrown away afterwards, so page code executes in Menlo’s cloud rather than on the machine hosting the agent.

02
What the agent is allowed to read

Sanitiser

Content clean-up before the model

Before page content reaches the model, Menlo removes malicious scripts, hidden instructions and steganography, and the runtime keeps the agent’s instructions apart from page data.

03
How an agent is pointed at the runtime

Routes in

Proxy or MCP integration

Menlo documents two ways in: a proxy for agents whose web traffic can be steered, or an MCP integration for agents that call tools; which suits depends on how each agent is built.

04
What the security team keeps afterwards

Evidence

Masking and tamper-proof audit logs

Fields pulled from web screens with no API can be masked in transit, and each session is written to tamper-proof audit logs; Menlo lists its logging and Log Export API as global.

Disposable cloud containers for agent browsing — pages cleaned before the model reads them, every session written to an audit log.

Part 03 · Evaluate

Nine capabilities. Isolate, inspect, govern.

Menlo Agent Runtime Security gives AI agents a contained place to browse, cleaning each page before the model reads it.

Isolate
Containers

A throwaway browser per run

Agent sessions open in remote containers that are discarded when the job ends, so a hostile page has nothing lasting to hold on to.

Isolate
No-API apps

Reach screens with no API

Agents can read data held behind web interfaces that expose no API, with the browsing itself done inside Menlo’s isolated runtime.

Isolate
Two routes

Proxy or MCP, your pick

Steer an agent’s web traffic through a proxy, or wire the runtime in as an MCP integration for agents built around tool calls.

Inspect
Hidden text

Planted instructions removed

Instructions concealed in a page to hijack an agent are stripped out, so the model receives the content and not the attacker’s orders.

Inspect
Scripts, stego

Payloads cut from pages

Malicious scripts, and data hidden inside images or files by steganography, are removed from what the agent is handed, per Menlo.

Inspect
Separation

Orders kept apart from data

The runtime enforces instruction/data separation, so text read from a website is treated as material to process, not as commands.

Govern
Masking

Sensitive fields masked

When an agent pulls records from a web application, sensitive values can be masked on the way, before they reach the model or its output.

Govern
Audit

A record that cannot be edited

Sessions are written to tamper-proof audit logs, giving risk teams evidence of what each agent opened and what it brought back.

Govern
Assistants

Copilot, Gemini and Claude

Menlo’s August 2026 update extended MARS to Microsoft Copilot, Gemini in Chrome, Claude Code and Claude Cowork.

See it, don’t just read it

Watch Menlo Agent Runtime Security in action

Menlo on securing staff and AI agents on one platform, keeping a human in the loop, and its machine-to-machine work with Google Cloud.

Menlo Security (official)·Overview, April 2026

Secure the New Enterprise Workforce: Humans and AI Agents

Menlo’s framing of staff and AI agents as one workforce that needs browser-level protection.

Menlo Security (official)·Explainer, June 2026

Browser Security for Humans and AI Agents | Menlo Security

How the Browser Security Platform extends from people at a browser to agents that browse on their own.

Menlo Security (official)·Short, May 2026

Menlo Security’s approach to bringing “human in the loop”

Where a person stays in the decision when an agent acts on the web.

Menlo Security (official)·Talk, May 2026

Enterprise use cases of Google Cloud & Menlo Security’s machine to machine defense

Menlo and Google Cloud on defending machine-to-machine traffic in enterprise settings.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Menlo Agent Runtime Security

Agents read pages written by strangers. MARS cleans the page before the agent sees it.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Every page an agent opens is untrusted input

An agent that browses takes in whatever a page holds, including text no person would ever see. MARS runs that browsing in a disposable container in the Menlo Cloud and strips malicious scripts, hidden instructions and steganography first, so the model is handed cleaned content rather than the raw page.

02

Commands and content travel in separate lanes

Indirect prompt injection succeeds when words an agent reads get treated as orders. Menlo builds instruction/data separation into the runtime, so text lifted from a website is processed as material, never obeyed as a command. Run your own injection test set against it before you rely on that claim.

03

Agents can work where no API exists

Plenty of supplier portals and older internal systems only offer a web screen. MARS lets an agent read data behind those API-less interfaces from inside the isolated session, masks sensitive fields on the way through, and writes each session to tamper-proof audit logs for later review.

04

Where it stops

It is young: launched in March 2026 and widened in August. There is no public price, no analyst rating and no named Indian customer. Menlo lists logging as global, so Indian log residency cannot be assumed. It guards agents’ web sessions; screening prompts sent to an LLM app you host is a different job.

The idea
Agents browse in a throwaway container
The defence
Hidden page instructions stripped
The price
Quote-only; no MARS rate published
Proof, not promises

The numbers behind the platform

4 assistants
named in the August 2026 expansion: Microsoft Copilot, Gemini in Chrome, Claude Code, Claude Cowork
— Vendor
2 routes
for connecting an agent to the runtime: a proxy, or an MCP integration
— Vendor
3 threat types
stripped from pages before the agent reads them: scripts, hidden instructions, steganography
— Vendor
2026
the year MARS launched, on 18 March, within Menlo’s Browser Security Platform
— Vendor
8M+
users Menlo says its platform protects in total, by its own March 2026 claim
— Vendor
0 CVEs
returned for “Menlo Security” by an NVD keyword search in October 2026
— NVD

What your Menlo Agent Runtime Security rollout looks like

Week 1Model

List the agents that browse

Inventory every agent, assistant and script that opens web pages, what sites it visits and what data it can touch.

Week 2Decide

Pick one route per agent

Decide whether each agent joins through the proxy or an MCP integration, starting with the one that reaches outside sites.

Week 3Pilot

Attack it with your own pages

Build test pages carrying hidden instructions and scripts, run the pilot agent through MARS, and record what reaches the model.

Month 2Prove

Wire masking and the audit trail

Set masking for sensitive fields, export logs to your SIEM, and agree who reviews agent sessions and how often.

Month 3Commit

Widen it and fix the contract

Add further agents, then get the quote in INR with GST that names the package, add-ons and the support tier you need.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4
18+ reviews*
78% would recommend
Injection defence4.2
Isolation model4.3
Audit evidence4.0
Ease of integration3.7
Value for money3.6
5★
38%
4★
40%
3★
15%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Manufacturing
“Our procurement agent reads supplier portals that have no API. Running those sessions in Menlo’s containers kept page code off our servers.”
Platform Engineer
Manufacturing
BFSI
“We planted hidden instructions in a test page and the agent’s view arrived without them. Build your own injection set before trusting anyone.”
Security Architect
BFSI
Healthcare
“The audit log answered what our risk committee kept asking: which pages did the agent open, and what did it carry back?”
Head of AI Governance
Healthcare
Logistics
“It is early days. The quote took weeks, and routing our in-house agent framework through the proxy needed real engineering time.”
IT Director
Logistics
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the AI agent security market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag AI Agent Security Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Menlo Agent Runtime SecurityThis page

Launched March 2026; quote-only.

Grid 02 · The architecture

Agent Coverage × Injection Defence

The grid nobody publishes — how much of an agent’s work it covers (browsing, tools, MCP) vs how deeply it defends against content-borne injection.

Deep but narrowFull agent runtimesText-only moderationBroad visibility, lighter depth
Menlo Agent Runtime SecurityThis page

Isolates agent browsing; strips hidden page text.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Menlo Agent Runtime Security vs the AI agent security field

Against Palo Alto Prisma AIRS, SentinelOne Prompt Security, Akamai Firewall for AI, Azure AI Content Safety and Amazon Bedrock Guardrails — on agent coverage, injection depth, price, audit, India and exit.

DimensionMenlo Agent Runtime SecurityPalo Alto Prisma AIRSSentinelOne Prompt SecurityAkamai Firewall for AIAzure AI Content SafetyAmazon Bedrock Guardrails
What it isIsolated agent browsingAI security platformAI usage and agent guardFirewall for LLM appsModeration serviceConfigurable guardrails
DeploymentCloud, proxy or MCPIntercepts plus MCPBrowser, desktop, MCPEdge, REST or proxyREST or FoundryInline or by API
Agent coverageAgents that browseAgents and MCP toolsFour touchpointsApps, not agentsFoundry agentsModel calls only
Pricing modelProducts and usersTokens per monthNot publishedQuote, unit unknownPer 1,000 recordsPer 1,000 text units
Published entry priceNot publishedNo public rateNot publishedDemo form only$0.375 per 1K records$0.15 per 1K units
Included vs add-onPackaging unstatedSCM, DLP, loggingSingularity moduleOwn SKUShields in free tierPolicies billed apart
Published limitsNone published2 MB sync, 5 MB asyncCoverage, not capsNone published5 documents a call1,000-character units
Threat depthScripts, hidden textAgent-specific threatsInjection, leakageOWASP LLM Top 10Harms plus attacksSix policy types
IntegrationsProxy, MCP, log exportStrata stack, SDKSingularity PlatformEdge, REST, proxyFoundry and RESTBedrock, SageMaker, EC2
Audit and governanceTamper-proof logsStrata LoggingAgent action logBehind loginYour thresholdsAWS resources
India regionMumbai node; logs globalIndia region, Aug 2025Not publishedNot documentedSouth India metersMumbai Region
SupportBasic or Care360Not on product pagesVia SentinelOneSet per contractPaid plan from $29Paid AWS plan
Lock-in and exitSessions in Menlo CloudRegion-bound keysTied to SingularityEdge mode on AkamaiMicrosoft’s categoriesChecks run in AWS
Best fitAgents on the open webPalo Alto estatesWorkforce AI plus agentsPublic LLM appsAzure Foundry buildersBuilders on AWS
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Menlo Agent Runtime Security if…

  • ✓Your agents read live web pages and portals, and you want that browsing to happen in a disposable container, not on your hosts
  • ✓Indirect prompt injection through hidden page text is the risk you most need to cut
  • ✓You need agents to work through web screens that have no API, with masking and an audit trail

Compare alternatives if…

  • ✓You mainly need to screen prompts and answers for an LLM app you host — Akamai Firewall for AI, Azure AI Content Safety and Bedrock Guardrails do that
  • ✓You want one console for staff AI use, code assistants and MCP servers — SentinelOne Prompt Security covers all four
  • ✓You want a per-unit price you can read today — Azure and AWS publish theirs

Do not expect…

  • ✓A published price, or a MARS-specific line on Menlo’s pricing page
  • ✓Indian log residency: Menlo lists its logging as global
  • ✓An analyst rating, or a named Indian customer, for a product launched in 2026

TechBag has no AI agent security guide yet, so Menlo Agent Runtime Security sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →

Do the math

What does unchecked agent browsing cost you?

Drag the sliders (AI agent workflows that browse; security-team hour cost). Estimates model security and engineering time spent reviewing what browsing agents read, investigating suspected injections and assembling evidence at an assumed 1.5 hours per workflow a year, with 70% of it removed by an isolated runtime and session audit logs. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual agent-oversight cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: Menlo prices by the products deployed and the number of user licences, with add-ons on top, and names no rate or licence unit for MARS. Its EchoQuote estimator gives budgetary figures. TechBag inventories your browsing agents first, then gets the quote in INR with GST.

One-agent pilot

Best for proving injection defence

  • Quote-only; no public MARS price
  • Proxy or MCP route for one agent
  • Your own hidden-instruction test pages

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Agent fleet

Best for assistants plus in-house agents

  • Copilot, Gemini in Chrome, Claude tools
  • Masking and tamper-proof audit logs
  • Care360 premium support optional

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Agent inventory

Which agents and assistants browse the web today, and which ones read pages from sites you do not control?

2
Route

Can each agent’s traffic be steered through a proxy, or does it call tools over MCP and need that integration?

3
Injection tests

Do you have your own pages with hidden instructions and scripts to test what MARS lets through to the model?

4
No-API systems

Which portals or legacy screens will agents read, and which fields there must be masked before the model sees them?

5
Logs

Where will audit logs go? Menlo lists logging as global, so plan a SIEM export for retention you control in India.

6
Assistants

Do you run Microsoft Copilot, Gemini in Chrome, Claude Code or Claude Cowork, the ones named in the August expansion?

7
Packaging

Which Menlo package or add-on carries MARS, what is the licence unit, and is it priced per agent or per user?

8
Maturity

Which features are generally available today, and which are roadmap? Ask Menlo to confirm it in writing.

FAQ

Questions buyers ask

MARS is Menlo’s runtime for AI agents that use the web. Each agent session opens in a remote, disposable container in the Menlo Cloud, where malicious scripts, hidden instructions and steganography are removed before the agent reads the page. Menlo’s menu also calls it AI Agent Security.

Ready to evaluate Menlo Agent Runtime Security?

List the agents that open web pages for you, or let a TechBag advisor scope a pilot that runs one agent through MARS against crafted injection pages.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.