Invoices, CVs, claims and drawings arrive from strangers every day. None of them should be trusted as sent — Menlo File Security takes every incoming file apart and rebuilds it from known-safe content — across mail, upload portals, shared drives, S3 and SFTP — using the Positive Selection engine from Votiro.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Menlo File Security — the CDR add-on built on Votiro’s engine. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
CDR rebuilds every file from safe parts instead of guessing whether it is malicious.
What consolidation actually replaces, dimension by dimension.
| Dimension | Scan, sandbox and hope | Menlo File Security |
|---|---|---|
| A brand-new exploit | Missed until a signature exists | Removed, because only known-safe content is kept |
| User waiting time | Minutes while a sandbox detonates | Milliseconds, by Menlo’s account |
| Password-protected ZIP | Passed through or blocked outright | Opened, disarmed and rebuilt |
| Macro-heavy workbook | Flattened to PDF or quarantined | Rebuilt with macros still working |
| Upload portals and S3 | Usually no inspection at all | Same rebuild step as email and web |
| What it is NOT | — | A phishing filter, link scanner or published price |
The cheapest test is your own hardest files: run real macro workbooks and protected archives through it and open what comes back.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Files arrive from email gateways, Teams, OneDrive, Box, SharePoint or Google Drive, S3 buckets, FTP, SFTP or SMB shares, or your own application through the open API.
Before rebuilding, each file gets an antivirus pass and a hash check that Menlo calls near-instantaneous, so known-bad files are flagged and logged on the way in.
The engine assumes the file is malicious, pulls out only the content it recognises as safe and builds a fresh file in the same format, keeping macros, templates and layout working.
Reports show each file’s type and origin, what was removed, hashes, names and behavioural indicators, plus recurring campaigns and the users they keep targeting.
Connectors and an API feed one cloud engine — a fast antivirus check, then every file rebuilt from known-safe parts.
Menlo File Security rebuilds every outside file from safe parts before anyone opens it, wherever it arrives.
Every file is treated as hostile and remade from safe elements, so an unknown exploit is dropped without needing a signature.
Menlo says rebuilt files keep their macros, templates and formatting, so a finance workbook stays usable after disarming.
ZIP and RAR archives, password-protected files, AutoCAD drawings, audio and video sit among the 220+ supported types.
Attachments are cleaned as mail passes through an email gateway, so a weaponised invoice arrives as a harmless copy.
Files customers or vendors upload through web portals are rebuilt before your staff or back-office systems open them.
Objects landing in AWS S3, and files shared in Teams, OneDrive, Box, SharePoint or Google Drive, are sanitised as they arrive.
Connectors for FTP, FTPS, SFTP and SMB put the rebuild step in file-transfer paths that never touch a browser or mailbox.
Reports list the malicious content removed, with hashes, file names and behavioural indicators for each sanitised file.
Recurring campaigns and the users they aim at are surfaced, which turns silent file disarming into a list to act on.
Two official Menlo explainers on file-borne ransomware, both recorded before the Votiro acquisition; Menlo hosts its CDR demo on Vimeo.
Menlo on file-borne ransomware, recorded a year before the Votiro deal; not a demo of the current CDR engine.
A two-minute primer on how ransomware gets in, useful background for why a file is rebuilt rather than trusted.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Scanners and sandboxes must recognise something bad before they act, and a new exploit is not yet recognised. Positive Selection works the other way: it keeps only the parts of a file it knows are safe and builds a new copy, so a zero-day hidden in a macro or PDF object never arrives.
One rebuild step serves email attachments, downloads, portal uploads, Teams, OneDrive, Box, SharePoint, Google Drive, S3 and FTP, SFTP or SMB transfers, with an open API for the rest. It is sold beyond Menlo’s browser, so it can guard an upload portal with no Menlo proxy in the path.
Flattening a document to PDF or an image makes it safe but breaks spreadsheets and forms. Menlo says its rebuilt files keep macros, templates and formatting, arrive in milliseconds, and include archives and password-protected files, so users get the file they asked for.
No public price and no analyst ranking. The File Security processing region is unpublished and logging is listed as Global, so Indian residency is a contract question. It disarms files only: no phishing-text filtering, no link scanning, no gateway replacement, and both videos predate Votiro.
List mail, upload portals, S3 buckets, shared drives and SFTP feeds, with rough daily volumes and who opens the files.
Gather real macro workbooks, CAD drawings and password-protected archives your teams rely on, to test rebuild fidelity.
Connect a single route, such as a customer-upload portal or one S3 bucket, and compare rebuilt files against originals.
Extend to email attachments and Teams, OneDrive or SharePoint, and agree how users ask for an original when needed.
Route the stripped-content reports to your security team and review which users recurring campaigns keep reaching.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Loan applicants upload salary slips and bank statements to our portal. Every PDF is rebuilt first, and underwriters stopped asking whether a file is safe.”
“Our costing team lives in macro-heavy Excel from suppliers. The rebuilt workbooks still calculate, which was the test the last tool failed.”
“We put it on the S3 bucket our partners drop claims into. Nothing reaches the processing job until it has been remade.”
“Password-protected ZIPs used to sail past our gateway. Now they get opened, disarmed and repacked before anyone sees them.”
“The campaign report showed one vendor-payments clerk was hit by the same lure for weeks. That changed our training plan.”
“It works, but there is no price to budget against. We used EchoQuote for a rough figure and still waited on the real quote.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the file sanitisation market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Votiro engine under Menlo since 2025; quote only.
The grid nobody publishes — how many routes into the business it covers vs how thoroughly it rebuilds the files it touches.
220+ types rebuilt; mail, web, S3, collab and SFTP.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against OPSWAT MetaDefender, Glasswall Halo, Check Point Harmony Email & Collaboration, Microsoft Defender for Office 365 and Fortinet FortiMail — on method, file types, channels, price, India and exit.
| Dimension | Menlo File Security | OPSWAT MetaDefender | Glasswall Halo | Check Point Harmony Email & Collaboration | Microsoft Defender for Office 365 | Fortinet FortiMail |
|---|---|---|---|---|---|---|
| What it is | Standalone CDR service | Multi-engine platform | Dedicated CDR engine | Email suite with CDR | Sandbox, not CDR | Email gateway with CDR |
| Deployment | Cloud; on-prem on ask | Cloud, AWS AMI, on-prem | Kubernetes, OVA, AMI | SaaS via API | Inside Microsoft 365 | Appliance, VM or cloud |
| File coverage | 220+ file types | 200+ types to rebuild | 85+ formats | Office, PDF, images | Detonates, no rebuild | Office and PDF disarm |
| Channels covered | Mail, web, S3, shares | Web, mail, storage | API and desktop | Mail and collab apps | Microsoft 365 only | Email only |
| Pricing model | Per user, add-on | By request volume | Licence from vendor | Per user per month | Per user per month | Appliance or per user |
| Published entry price | Not published | $55,000 a year (AWS) | Not published | Quote only | $2 per user a month | Quote only |
| Included vs add-on | Bought on top | Engines count apart | CDR is the product | Beside sandboxing | In Business Premium | Sandbox sold apart |
| Speed and scale | Milliseconds (claim) | Milliseconds (claim) | Sized by you | Clean copy at once | Message first | Per appliance model |
| Method and depth | Rebuild every file | Rebuild plus AV | Rebuild to standard | Strip or convert | Detection only | Strip active content |
| Integrations | Collab, S3, transfers | ICAP and storage | REST API, Helm | M365 and Google | Microsoft only | Fortinet fabric |
| India data location | Not published | Your servers | Your servers | Ask for region | Tenant geography | Appliance on-site |
| Support | Basic + Care360 | Not published | Not published | Partner and vendor | With the subscription | FortiCare contracts |
| Lock-in and exit | Standard files out | Runs on your hosts | Containers you own | Tied to the tenant | Tied to Microsoft 365 | Gateway in mail path |
| Best fit | Many routes, one CDR | Air-gapped, multi-engine | Build it into apps | Harmony email buyers | Microsoft-only estates | Fortinet mail estates |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
TechBag has no file sanitisation (CDR) guide yet, so Menlo File Security sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →
Drag the sliders (staff who open files from outside; security-team hour cost). Estimates model security and IT time spent on suspicious-attachment triage, quarantine releases and clean-up after a malicious file is opened, at an assumed 1.5 hours per such employee a year, with 70% of it removed by rebuilding files before they arrive. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: Menlo prices by the products deployed and the number of user licences, and sells File Security as an add-on. Its EchoQuote tool gives a budgetary estimate; no marketplace price applies to this product. TechBag maps your file routes first, then gets the quote in INR with GST.
Best for an upload portal or S3 pilot
Best for a broader rollout
Best for regulated, file-heavy teams
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which routes carry outside files today — mail, portals, S3, shared drives, SFTP — and which will you connect first?
Do rebuilt copies of your own macro workbooks, CAD files and protected archives open and behave like the originals?
When a user needs the untouched original, who approves the release, and how is that request logged?
Where in the Menlo Cloud will files be processed, and will Menlo write that into the contract for India?
Logging is listed as Global; how will you export logs to a SIEM to hold CERT-In’s 180 days in India?
Do any channels need the on-premises option Menlo offers on request, and what does that change in the quote?
Which sandbox or gateway features in your current licences already touch these files, and what can retire?
Is File Security quoted as an add-on per user, and what users or volumes does it count? Ask for INR with GST.
List the routes outside files take into your business, or let a TechBag advisor scope a pilot on the one channel that worries you most.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.