Talk to us
by Menlo SecurityTechBag Intel Page

Menlo File Security

Invoices, CVs, claims and drawings arrive from strangers every day. None of them should be trusted as sent — Menlo File Security takes every incoming file apart and rebuilds it from known-safe content — across mail, upload portals, shared drives, S3 and SFTP — using the Positive Selection engine from Votiro.

220+ file types rebuiltMail, portals, S3 and SFTPVotiro engine, Menlo since 2025

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
No public figure for File Security; EchoQuote gives a budget number before a sales call
Quote
Formats
File types Menlo says it can disarm and rebuild, archives and protected files among them
220+
Analysts
No analyst ranking covers this product; Menlo’s GigaOm and Frost wins are for its browser and ZTNA
None named
India
Bengaluru office and distributor verified; where File Security processes files is not published
Ask

Quick answer

Menlo File Security is content disarm and reconstruction (CDR): it treats every incoming file as hostile, takes it apart and rebuilds it from known-good parts with Positive Selection, technology Menlo gained by buying Votiro in February 2025. It covers 220+ file types across email, web downloads, portal uploads, collaboration tools and AWS S3. Pricing is by quote, and it is sold as an add-on module. Read more ↓ Show less ↑
Part 01 · Orient

The Menlo Security platform family

This page covers Menlo File Security — the CDR add-on built on Votiro’s engine. The rest:

Quick facts

30-second orientation
Product
Content disarm and reconstruction that rebuilds each file before it reaches a user or a bucket
Maker
Menlo Security, Mountain View, California; private, CEO Bill Robbins since February 2026
Origin
Votiro’s Positive Selection engine, acquired by Menlo on 19 February 2025
Price
Quote only; Menlo’s EchoQuote tool gives a budgetary estimate, and no marketplace price applies
Licence
An add-on to the Menlo platform, priced on products deployed and user licences
Formats
220+ file types, including archives, password-protected files and files with macros
Channels
Email attachments, web downloads, portal uploads, collaboration sharing, AWS S3 and an open API
Deployment
Cloud by default and agentless; Menlo says on-premises installation is available on request
India
Menlo Security India LLP in Bengaluru; RAH Infotech distributes; logging is listed as Global
In India via
TechBag — channel mapping, a quote in INR with GST, and a side-by-side file test
Part 02 · Learn

Understand file sanitisation before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is content disarm and reconstruction?

CDR rebuilds every file from safe parts instead of guessing whether it is malicious.

Scan, sandbox and hope vs rebuilding every file — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionScan, sandbox and hopeMenlo File Security
A brand-new exploitMissed until a signature existsRemoved, because only known-safe content is kept
User waiting timeMinutes while a sandbox detonatesMilliseconds, by Menlo’s account
Password-protected ZIPPassed through or blocked outrightOpened, disarmed and rebuilt
Macro-heavy workbookFlattened to PDF or quarantinedRebuilt with macros still working
Upload portals and S3Usually no inspection at allSame rebuild step as email and web
What it is NOT—A phishing filter, link scanner or published price

The cheapest test is your own hardest files: run real macro workbooks and protected archives through it and open what comes back.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where files enter the service

Intake

Connectors and the open API

Files arrive from email gateways, Teams, OneDrive, Box, SharePoint or Google Drive, S3 buckets, FTP, SFTP or SMB shares, or your own application through the open API.

02
The quick first look

Pre-check

Antivirus and hash lookup

Before rebuilding, each file gets an antivirus pass and a hash check that Menlo calls near-instantaneous, so known-bad files are flagged and logged on the way in.

03
Where the file is remade

Rebuild

Positive Selection engine

The engine assumes the file is malicious, pulls out only the content it recognises as safe and builds a fresh file in the same format, keeping macros, templates and layout working.

04
What the security team sees

Analytics

Threat reporting

Reports show each file’s type and origin, what was removed, hashes, names and behavioural indicators, plus recurring campaigns and the users they keep targeting.

Connectors and an API feed one cloud engine — a fast antivirus check, then every file rebuilt from known-safe parts.

Part 03 · Evaluate

Nine capabilities. Rebuild, reach, report.

Menlo File Security rebuilds every outside file from safe parts before anyone opens it, wherever it arrives.

Rebuild
Positive Selection

Rebuilt, not scanned

Every file is treated as hostile and remade from safe elements, so an unknown exploit is dropped without needing a signature.

Rebuild
Fidelity

Macros that still work

Menlo says rebuilt files keep their macros, templates and formatting, so a finance workbook stays usable after disarming.

Rebuild
Hard formats

Archives and passwords

ZIP and RAR archives, password-protected files, AutoCAD drawings, audio and video sit among the 220+ supported types.

Reach
Email

Attachments disarmed

Attachments are cleaned as mail passes through an email gateway, so a weaponised invoice arrives as a harmless copy.

Reach
Uploads

Portals that take files

Files customers or vendors upload through web portals are rebuilt before your staff or back-office systems open them.

Reach
Storage

S3 and shared drives

Objects landing in AWS S3, and files shared in Teams, OneDrive, Box, SharePoint or Google Drive, are sanitised as they arrive.

Reach
Transfers

FTP, SFTP and SMB

Connectors for FTP, FTPS, SFTP and SMB put the rebuild step in file-transfer paths that never touch a browser or mailbox.

Report
Threat view

What was stripped out

Reports list the malicious content removed, with hashes, file names and behavioural indicators for each sanitised file.

Report
Campaigns

Who keeps being targeted

Recurring campaigns and the users they aim at are surfaced, which turns silent file disarming into a list to act on.

See it, don’t just read it

Watch Menlo on file-borne threats

Two official Menlo explainers on file-borne ransomware, both recorded before the Votiro acquisition; Menlo hosts its CDR demo on Vimeo.

Menlo Security (official)·Explainer, February 2024

Protection from sophisticated ransomware threats with Menlo Security

Menlo on file-borne ransomware, recorded a year before the Votiro deal; not a demo of the current CDR engine.

Menlo Security (official)·Short, February 2023

Two minutes on: Ransomware prevention

A two-minute primer on how ransomware gets in, useful background for why a file is rebuilt rather than trusted.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Menlo File Security

Detection waits to recognise a threat. Menlo File Security rebuilds the file instead.

Here’s what genuinely sets it apart — and exactly where it stops.

01

No signature, no waiting for one

Scanners and sandboxes must recognise something bad before they act, and a new exploit is not yet recognised. Positive Selection works the other way: it keeps only the parts of a file it knows are safe and builds a new copy, so a zero-day hidden in a macro or PDF object never arrives.

02

One engine for every route a file takes

One rebuild step serves email attachments, downloads, portal uploads, Teams, OneDrive, Box, SharePoint, Google Drive, S3 and FTP, SFTP or SMB transfers, with an open API for the rest. It is sold beyond Menlo’s browser, so it can guard an upload portal with no Menlo proxy in the path.

03

Files that still open and still work

Flattening a document to PDF or an image makes it safe but breaks spreadsheets and forms. Menlo says its rebuilt files keep macros, templates and formatting, arrive in milliseconds, and include archives and password-protected files, so users get the file they asked for.

04

Where it stops

No public price and no analyst ranking. The File Security processing region is unpublished and logging is listed as Global, so Indian residency is a contract question. It disarms files only: no phishing-text filtering, no link scanning, no gateway replacement, and both videos predate Votiro.

The idea
Rebuild every file, trust none
The reach
Mail, portals, S3, drives and SFTP
The price
Quote-only add-on; EchoQuote estimate
Proof, not promises

The numbers behind the platform

220+ file types
that Menlo says Positive Selection can take apart and rebuild, archives included
— Vendor
10 billion
files sanitised to date, by Menlo’s own count on its File Security page
— Vendor
5 collab apps
named connectors: Teams, OneDrive, Box, SharePoint and Google Drive
— Vendor
4 protocols
file-transfer routes covered by connectors: FTP, FTPS, SFTP and SMB
— Vendor
2025
the year Menlo bought Votiro, the source of the Positive Selection engine
— Vendor
0 agents
on endpoints: Menlo describes the service as agentless and API-driven
— Vendor

What your Menlo File Security rollout looks like

Week 1Model

Map every way files get in

List mail, upload portals, S3 buckets, shared drives and SFTP feeds, with rough daily volumes and who opens the files.

Week 2Decide

Collect the awkward files

Gather real macro workbooks, CAD drawings and password-protected archives your teams rely on, to test rebuild fidelity.

Week 3Pilot

Pilot one channel

Connect a single route, such as a customer-upload portal or one S3 bucket, and compare rebuilt files against originals.

Month 2Prove

Add mail and shared drives

Extend to email attachments and Teams, OneDrive or SharePoint, and agree how users ask for an original when needed.

Month 3Commit

Wire reports to the SOC

Route the stripped-content reports to your security team and review which users recurring campaigns keep reaching.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.2
38+ reviews*
83% would recommend
Zero-day protection4.5
File fidelity4.2
Channel coverage4.3
Reporting3.9
Value for money3.7
5★
45%
4★
37%
3★
12%
2★
4%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“Loan applicants upload salary slips and bank statements to our portal. Every PDF is rebuilt first, and underwriters stopped asking whether a file is safe.”
Information Security Manager
BFSI
Manufacturing
“Our costing team lives in macro-heavy Excel from suppliers. The rebuilt workbooks still calculate, which was the test the last tool failed.”
IT Manager
Manufacturing
Insurance
“We put it on the S3 bucket our partners drop claims into. Nothing reaches the processing job until it has been remade.”
Cloud Security Engineer
Insurance
Healthcare
“Password-protected ZIPs used to sail past our gateway. Now they get opened, disarmed and repacked before anyone sees them.”
SOC Lead
Healthcare
Logistics
“The campaign report showed one vendor-payments clerk was hit by the same lure for weeks. That changed our training plan.”
CISO
Logistics
Education
“It works, but there is no price to budget against. We used EchoQuote for a rough figure and still waited on the real quote.”
Head of IT
Education
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the file sanitisation market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag File Sanitisation Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Menlo File SecurityThis page

Votiro engine under Menlo since 2025; quote only.

Grid 02 · The architecture

Channel Reach × Rebuild Depth

The grid nobody publishes — how many routes into the business it covers vs how thoroughly it rebuilds the files it touches.

Deep single-route enginesRebuild everywhereGateway add-onsBroad but scan-based
Menlo File SecurityThis page

220+ types rebuilt; mail, web, S3, collab and SFTP.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Menlo File Security vs the file sanitisation field

Against OPSWAT MetaDefender, Glasswall Halo, Check Point Harmony Email & Collaboration, Microsoft Defender for Office 365 and Fortinet FortiMail — on method, file types, channels, price, India and exit.

DimensionMenlo File SecurityOPSWAT MetaDefenderGlasswall HaloCheck Point Harmony Email & CollaborationMicrosoft Defender for Office 365Fortinet FortiMail
What it isStandalone CDR serviceMulti-engine platformDedicated CDR engineEmail suite with CDRSandbox, not CDREmail gateway with CDR
DeploymentCloud; on-prem on askCloud, AWS AMI, on-premKubernetes, OVA, AMISaaS via APIInside Microsoft 365Appliance, VM or cloud
File coverage220+ file types200+ types to rebuild85+ formatsOffice, PDF, imagesDetonates, no rebuildOffice and PDF disarm
Channels coveredMail, web, S3, sharesWeb, mail, storageAPI and desktopMail and collab appsMicrosoft 365 onlyEmail only
Pricing modelPer user, add-onBy request volumeLicence from vendorPer user per monthPer user per monthAppliance or per user
Published entry priceNot published$55,000 a year (AWS)Not publishedQuote only$2 per user a monthQuote only
Included vs add-onBought on topEngines count apartCDR is the productBeside sandboxingIn Business PremiumSandbox sold apart
Speed and scaleMilliseconds (claim)Milliseconds (claim)Sized by youClean copy at onceMessage firstPer appliance model
Method and depthRebuild every fileRebuild plus AVRebuild to standardStrip or convertDetection onlyStrip active content
IntegrationsCollab, S3, transfersICAP and storageREST API, HelmM365 and GoogleMicrosoft onlyFortinet fabric
India data locationNot publishedYour serversYour serversAsk for regionTenant geographyAppliance on-site
SupportBasic + Care360Not publishedNot publishedPartner and vendorWith the subscriptionFortiCare contracts
Lock-in and exitStandard files outRuns on your hostsContainers you ownTied to the tenantTied to Microsoft 365Gateway in mail path
Best fitMany routes, one CDRAir-gapped, multi-engineBuild it into appsHarmony email buyersMicrosoft-only estatesFortinet mail estates
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Menlo File Security if…

  • ✓Files reach you through several routes — mail, upload portals, S3, shared drives, SFTP — and you want one rebuild engine on all of them
  • ✓Users depend on macro-heavy spreadsheets or password-protected archives that flattening or blocking would break
  • ✓You already run Menlo’s cloud browser and want downloads and uploads rebuilt by the same vendor

Compare alternatives if…

  • ✓You need CDR on servers in an air-gapped network — OPSWAT MetaDefender Core and Glasswall Halo both install on-premises by design
  • ✓Your only file route is Microsoft 365 mail — Defender for Office 365 may already be in the licence you hold
  • ✓You want a published price before talking to sales — Defender lists per-user rates, and OPSWAT has an AWS listing

Do not expect…

  • ✓A public price, a marketplace listing or a free trial for File Security
  • ✓A phishing filter, link rewriting or a replacement for your email gateway
  • ✓A published Indian processing region; Menlo lists its logging as Global

TechBag has no file sanitisation (CDR) guide yet, so Menlo File Security sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →

Do the math

What do risky outside files cost you?

Drag the sliders (staff who open files from outside; security-team hour cost). Estimates model security and IT time spent on suspicious-attachment triage, quarantine releases and clean-up after a malicious file is opened, at an assumed 1.5 hours per such employee a year, with 70% of it removed by rebuilding files before they arrive. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual file-threat handling cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: Menlo prices by the products deployed and the number of user licences, and sells File Security as an add-on. Its EchoQuote tool gives a budgetary estimate; no marketplace price applies to this product. TechBag maps your file routes first, then gets the quote in INR with GST.

One channel first

Best for an upload portal or S3 pilot

  • One route connected through the API
  • Rebuilt files checked against originals
  • Quote on request; no public price

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Every file route

Best for regulated, file-heavy teams

  • Mail, collaboration, storage and SFTP
  • Threat reports routed to the SOC
  • On-premises option on request

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Entry points

Which routes carry outside files today — mail, portals, S3, shared drives, SFTP — and which will you connect first?

2
File fidelity

Do rebuilt copies of your own macro workbooks, CAD files and protected archives open and behave like the originals?

3
Originals

When a user needs the untouched original, who approves the release, and how is that request logged?

4
Processing region

Where in the Menlo Cloud will files be processed, and will Menlo write that into the contract for India?

5
Logs

Logging is listed as Global; how will you export logs to a SIEM to hold CERT-In’s 180 days in India?

6
On-premises

Do any channels need the on-premises option Menlo offers on request, and what does that change in the quote?

7
Overlap

Which sandbox or gateway features in your current licences already touch these files, and what can retire?

8
Licence

Is File Security quoted as an add-on per user, and what users or volumes does it count? Ask for INR with GST.

FAQ

Questions buyers ask

It is Menlo’s content disarm and reconstruction (CDR) product. Instead of looking for malware, it treats every file as dangerous, keeps only the content it recognises as safe and builds a fresh copy in the same format, so hidden exploits in documents, archives or images are dropped before anyone opens the file.

Ready to evaluate Menlo File Security?

List the routes outside files take into your business, or let a TechBag advisor scope a pilot on the one channel that worries you most.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.