Talk to us
by Menlo SecurityTechBag Intel Page

Menlo Secure Application Access

Your contractors need three internal apps. They shouldn’t need a VDI desktop to open them — Menlo Secure Application Access opens private web, SaaS, SSH, RDP and legacy apps through a browser portal or extension, rendering each one in Menlo’s cloud browser so contractors and BYOD users never hold the data — with a client for the rest.

Clientless portal, optional clientData stays in the cloud browserQuote-only, per user licence

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Per user licences; EchoQuote gives a budget figure, and partners such as RAH Infotech quote in India
Quote
Reach
Web and SaaS clientless; SSH, RDP and thick-client apps too, the last through the optional client
Web + client
Analysts
Leader and Outperformer in GigaOm’s July 2025 ZTNA Radar, which assessed 28 vendors
GigaOm Leader
India
Menlo’s status page lists Mumbai proxy and isolation; it does not say SAA sessions are served there
Mumbai node

Quick answer

Menlo Secure Application Access (SAA) gives staff and contractors zero trust access to private web, SaaS, SSH, RDP and legacy apps. Web apps open from a browser portal or extension with nothing installed and are rendered in Menlo’s cloud browser, so the data stays off the device; the optional Menlo Security Client carries non-web apps. It is quote-only. Menlo’s status page lists a Mumbai node, but logging is global. Read more ↓ Show less ↑
Part 01 · Orient

The Menlo Security platform family

This page covers Menlo Secure Application Access — private-app access through the cloud browser, with the Menlo Security Client for legacy apps. The rest:

Quick facts

30-second orientation
Product
Zero trust access to private web, SaaS, SSH, RDP and thick-client apps, delivered through Menlo’s cloud browser
Maker
Menlo Security, Inc., Mountain View, California; privately held; CEO Bill Robbins since 25 February 2026
Recognition
Leader and Outperformer in the GigaOm Radar for ZTNA, July 2025, among 28 vendors assessed
Price
Quote-only, by products deployed and user licences; Menlo’s EchoQuote tool gives a budget estimate
Access
Browser portal or extension with no install; the Menlo Security Client is optional, for non-web apps
Identity
SAML 2.0 and OpenID Connect, naming Microsoft Entra ID, Okta and Google Workspace
Posture
Firewall, OS version and disk encryption checked before and during access; CrowdStrike ZTA score read
Data
Copy/paste limits, watermarking, redaction, read-only mode and upload or download rules inside the session
India
Mumbai proxy and isolation nodes on Menlo’s status page; logging is listed as Global
In India via
TechBag — apps mapped by protocol, posture and data rules designed, quote in INR with GST
Part 02 · Learn

Understand browser-delivered zero trust access before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is browser-delivered zero trust access?

Each user reaches only the apps assigned to them, and the app is rendered in a cloud browser instead of running on their device.

A VPN plus VDI desktops for partners vs Menlo SAA — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionA VPN plus VDI desktops for partnersMenlo Secure Application Access
What a contractor needsA VPN account or a VDI desktopA browser and an entry in the portal
What reaches the deviceFiles and app data, cached locallyA rendering; the data stays in Menlo’s cloud
Taking data awayCopy, download and print at willCopy/paste limits, watermarks, read-only views
What a login opensA subnet behind the concentratorOnly the apps assigned to that person
Work on your networkGateways to patch, desktop images to buildNo DNS edits or certificate imports, per Menlo
What it is NOT—A published price, a documented VoIP path, Indian logs

The cheapest test is one partner group: publish three web apps in the portal with read-only mode and watermarks on, and set it beside their VDI desktop.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where the application really runs

Cloud browser

Menlo Secure Cloud Browser

The app is opened in Menlo’s cloud browser and only a rendering reaches the screen, so Menlo says sensitive data is never downloaded into the laptop’s memory.

02
How a user gets in

Entry

Portal, extension or client

A web portal lists each person’s apps, a browser extension opens app links from mail or chat the same way, and the Menlo Security Client adds non-web apps.

03
Who may open which app

Policy

Identity, attributes and posture

SAML 2.0 or OIDC from Entra ID, Okta or Google Workspace names the user; rules weigh group, source IP and geography, and posture is checked throughout.

04
How private apps stay hidden

Path

Menlo Cloud to your apps

Private apps are kept off the public internet and reached through the Menlo Cloud; Menlo says no network rebuild, DNS record change or certificate import is needed.

A cloud browser between user and app — web apps rendered remotely, legacy traffic tunnelled through the optional client.

Part 03 · Evaluate

Nine capabilities. Connect, contain, govern.

Menlo SAA opens each private app inside a cloud browser, so a contractor’s laptop sees the app but never holds its data.

Connect
Portal

Apps listed in a browser portal

Users sign in to a Menlo portal and see only the applications provisioned for them, from managed, unmanaged or mobile devices.

Connect
Extension

Links that open through Menlo

A lightweight browser extension mirrors the portal, so an internal app link pasted into an email or a chat opens through Menlo too.

Connect
Client

Legacy apps through the client

The Menlo Security Client, available with SAA, tunnels non-web and thick-client traffic through the Menlo Cloud for remote users.

Contain
Isolation

Rendered, not delivered

Apps render in the Secure Cloud Browser, which Menlo says keeps cross-site scripting, cookie theft and session hijacking off the app.

Contain
Data rules

Last-mile data rules

Copy/paste limits, watermarks on pages and downloads, data redaction and read-only mode are set per application and per group.

Contain
File checks

Transfers scanned both ways

Uploads and downloads can be allowed, blocked or passed through DLP, while sandboxing and anti-virus scans look for infected files.

Govern
Least privilege

Rules by user, group, IP, place

Access is granted app by app on users, groups, source IP addresses and geographic location, never to a whole network or segment.

Govern
Posture

Device checks, client or not

Firewall status, OS version and disk encryption are checked before and during access; Managed Chrome allows clientless posture checks.

Govern
Visibility

Logs your SOC can use

Each app access is logged with user, source location and activity, for export to SIEM and EDR/XDR tools; Browsing Forensics is an add-on.

See it, don’t just read it

Watch Menlo SAA in action

Menlo’s case for SAA over VDI from November 2025, access paired with Browsing Forensics from December 2024, and an early 2024 VDI comparison. All from Menlo’s official channel.

Menlo Security (official)·Explainer, November 2025

How Menlo Secure Application Access Reduces VDI Complexity

Menlo’s case for serving browser-based work through SAA instead of a pool of virtual desktops.

Menlo Security (official)·Short, December 2024

Menlo Secure Application Access & Browsing Forensics - security & visibility

Private-app access paired with Browsing Forensics, the add-on that records what users did in a session.

Menlo Security (official)·Short, February 2024

Overcome the disadvantages of VDI with Menlo Security Secure Application Access

An early 2024 look at where VDI slows users down and how a cloud-rendered portal changes that.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Menlo Secure Application Access

A VPN hands over the network; VDI hands over a whole desktop. SAA hands over one rendered app.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Partners without VPN accounts or VDI desktops

A contractor or auditor opens the apps on their list from a browser portal on their own laptop, with nothing to install and, Menlo says, no certificate import or DNS change on your side. By Menlo’s own estimate, swapping VDI for this trims its running cost by as much as 80%; test that on your estate.

02

The device never holds the data

Because the app runs in Menlo’s cloud browser and only a rendering reaches the screen, Menlo says sensitive data is never downloaded to the endpoint. Read-only mode, watermarks, redaction and copy/paste limits decide what anyone carries away, even from an unmanaged machine.

03

One service for web, admin and legacy apps

Web and SaaS apps need no client, SSH and RDP targets are reachable, and the optional Menlo Security Client tunnels thick-client traffic through the Menlo Cloud. Posture is checked before and during a session, can read a CrowdStrike ZTA score, or comes clientless from Managed Chrome.

04

Where it stops

Menlo prints no price and quotes per user. Server-initiated protocols such as softphone traffic, and SCIM provisioning, are not described in the material reviewed. Mumbai nodes appear on Menlo’s status page, yet logging is listed as Global, so Indian log residency is not on offer.

The idea
Apps rendered in a cloud browser
The reach
Web, SaaS, SSH, RDP and thick clients
The price
Quote-only, per user licence
Proof, not promises

The numbers behind the platform

28 vendors
assessed in GigaOm’s July 2025 ZTNA Radar, which named Menlo a Leader and Outperformer
— Analyst
Up to 80%
lower VDI total cost of ownership, as Menlo claims for SAA; your own figure needs a pilot
— Vendor
3 ways in
for users: a browser portal, a browser extension, or the optional Menlo Security Client
— Vendor
4 policy inputs
beyond the app itself: user, group, source IP address and geographic location
— Vendor
6 data controls
copy/paste, watermarks, redaction, read-only, transfer limits and DLP on allowed transfers
— Vendor
2 GigaOm years
as a ZTNA Leader: Fast Mover in the July 2024 Radar, Outperformer in July 2025
— Analyst

What your Menlo SAA rollout looks like

Week 1Model

Sort users and apps

List who needs remote access — staff, contractors, auditors — and tag every app as web, SaaS, SSH, RDP or thick client.

Week 2Decide

Connect identity and rules

Federate SAA with Entra ID, Okta or Google Workspace over SAML or OIDC, then write rules by group, source IP and geography.

Week 3Pilot

Portal pilot for one partner

Publish three web apps in the portal for one contractor group with read-only mode and watermarks on, and log every session.

Month 2Prove

Admins and legacy apps

Push the Menlo Security Client to admins who need thick-client apps, add SSH and RDP targets, and switch on posture checks.

Month 3Commit

Cut VDI seats

Compare session logs and tickets with the old VDI or VPN, remove seats app by app, and keep a dated list of exceptions.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.1
41+ reviews*
80% would recommend
Clientless app access4.4
In-session data controls4.3
Contractor onboarding4.2
Protocol reach3.7
Value for money3.6
5★
42%
4★
37%
3★
14%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“Our statutory auditors now open the ledger app from their own laptops, watermarked and read-only. We dropped their VDI pool.”
Finance IT Lead
BFSI
IT Services
“Publishing the first web apps in the portal took an afternoon. Agreeing posture rules with the risk team took three weeks.”
End-User Computing Manager
IT Services
Insurance
“Partner agents cannot copy text out of the claims screen, and redaction hides policy numbers. That settled our privacy review.”
Information Security Manager
Insurance
Manufacturing
“Admins reach Linux hosts over SSH in the browser, but the plant historian needed the client. Plan for two user groups.”
OT Security Engineer
Manufacturing
Healthcare
“We feed the CrowdStrike ZTA score into posture, so a laptop with a stopped sensor loses the HR app mid-session.”
Security Architect
Healthcare
Retail
“No figure until the quote, and we had to ask in writing whether our Pune staff would be served from Mumbai.”
Head of IT
Retail
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the zero trust access market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Zero Trust Access Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Menlo Secure Application AccessThis page

Quote-only, priced on products deployed and user count.

Grid 02 · The architecture

Session Control × Protocol Reach

The grid nobody publishes — how much a product limits what an unmanaged device can take from a session vs how many kinds of app traffic it can carry.

Wide reach, light controlReach and controlWeb-first, light controlControl-first, narrower reach
Menlo Secure Application AccessThis page

Cloud rendering, redaction, watermarks; thick clients via the client.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Menlo SAA vs the zero trust access field

Against Zscaler Private Access, Netskope One Private Access, Cloudflare Access, Akamai Enterprise Application Access and InstaSafe ZTNA — on access modes, protocol reach, price, session security, identity, support and India.

DimensionMenlo Secure Application AccessZscaler Private Access (ZPA)Netskope One Private AccessCloudflare AccessAkamai Enterprise Application AccessInstaSafe ZTNA
What it isBrowser-rendered ZTNAZscaler’s VPN successorA Netskope One moduleInside Cloudflare OneAkamai’s ZTNA serviceIndian IP-layer ZTNA
Deployment and accessPortal, extension, appApp + Client ConnectorsUniversal ZTNATunnel, WARP or browser8 connector platformsAgent and agentless
Apps and protocolsWeb, SSH, RDP, thickServer-started via NCBroadest documentedWeb, SSH and RDPWeb, RDP, SSH, TCP/UDPThick clients via IP
Pricing modelPer user, by packagePer user, by editionPer user, in platformFree to 50, then $7Quote; unit unstatedPer user, managed
Published entry priceNot published~$6–11 reportedNot published$0 to 50, then $7Not published~$8/user/month
Included vs add-onForensics extraDLP is its own lineShared DLP policyGateway, DLP by planMFA, SIA sold apartAccess only
Scale evidenceCompany claims onlyMost widely deployedPast 5,000 usersBeyond 5,000 usersOne named customerMid-market evidence
Session securityIsolation + data rulesRechecked mid-sessionEvery request judgedPer-app posture rulesChecks plus EDR verdictsDark until verified
IntegrationsSIEM, EDR, Google WANZero Trust ExchangeNetskope One stackIdPs and the suiteAkamai MFA, SIA, SIEMInstaSafe’s own stack
Identity and SSOSAML and OIDCSAML, OIDC, SCIMSAML, OIDC, SCIMSAML, OIDC, SCIMFive IdPs plus SCIMSAML and OIDC
India presenceMumbai node listedNo city confirmed8 Indian data centres6 Indian citiesNo EAA PoP namedIndia-built and hosted
SupportBasic + Care360Set in the quoteNot recordedSelf-serve to quotedTrial, then quoteManaged service in
Lock-in and exitLittle on devicesConnectors + clientTied to Netskope OneTunnels and WARPConnectors, client outAgent fleet to replace
Best fitVDI for contractorsRetiring the VPNAwkward protocolsFast, priced startAkamai estatesRupee and GeM buyers
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Menlo SAA if…

  • ✓Contractors, auditors or BYOD staff need internal apps and the data should stay in a cloud browser, not on their laptops
  • ✓You run VDI or a VPN mainly so third parties can reach a few web apps, and read-only views with watermarks would do
  • ✓You already use Menlo’s Secure Enterprise Browser and want private-app access logged in the same place

Compare alternatives if…

  • ✓What is left on the VPN includes VoIP or SCCM — Netskope documents both, and Zscaler reaches them with its Network Connector
  • ✓You need a number before a sales call — Cloudflare is free to 50 users and $7 after, and InstaSafe lists about $8
  • ✓SCIM provisioning is mandatory — Zscaler, Netskope, Cloudflare and Akamai all document it

Do not expect…

  • ✓A published SAA price; it is quote-only, with EchoQuote for a budget figure
  • ✓Indian log storage — Menlo lists logging as Global
  • ✓Documented support for server-initiated protocols such as softphones

Menlo Secure Application Access is one of 23 zero trust access products TechBag carries. The Zero Trust Access guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does VPN and VDI access cost you to run?

Drag the sliders (remote and third-party users; IT staff-hour cost). Estimates model the staff time spent issuing VPN accounts, maintaining VDI desktops and handling access tickets, at an assumed 1.5 hours per user a year, with 70% of it removed by clientless, policy-based app access. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual remote-access admin cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. Menlo prints no figure for Secure Application Access. Its pricing FAQ ties the cost to which of its packages you run and how many users you license, and Browsing Forensics is one of the extras sold on top; volume discounts are offered. For a rough number before talking to sales, the EchoQuote estimator returns budgetary pricing. Every licence carries basic support, while Menlo Care360 is the paid upgrade. In India it is sold through partners, with RAH Infotech as distributor. TechBag counts your users and apps first, then quotes in INR with GST.

Clientless access

Best for contractors and BYOD users

  • Browser portal or extension, nothing installed
  • Read-only, watermark, redaction, copy/paste rules
  • Quoted per user; EchoQuote for a budget

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Client and add-ons

Best for admins and legacy apps

  • Menlo Security Client for thick-client apps
  • Posture checked before and during sessions
  • Browsing Forensics sold as an add-on

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
User groups

Which people are contractors or BYOD users who can stay clientless, and which managed staff will need the client?

2
App protocols

Which apps are web or SaaS, which need SSH or RDP, which are thick-client, and are any server-initiated?

3
Identity

Is your IdP Entra ID, Okta or Google Workspace, and how will group changes reach Menlo with no SCIM documented?

4
Data rules

For each app, should partners get read-only views, watermarks, redaction or upload limits, and who signs that off?

5
Posture

Will posture come from the client, from a CrowdStrike ZTA score, or clientless from Managed Chrome?

6
India latency

Will the pilot time page rendering from each Indian office, and does the quote state which node serves them?

7
Logs

Logging is listed as Global — will you export to a SIEM you hold in India to keep CERT-In’s 180 days of records?

8
Licence

Does the quote state users, packages and add-ons such as Browsing Forensics, in INR with GST and a fixed term?

FAQ

Questions buyers ask

SAA is Menlo Security’s zero trust access service. Users reach only the private web, SaaS, SSH, RDP or legacy apps their policy allows, and web apps are opened in Menlo’s Secure Cloud Browser, so the device shows a rendering rather than holding the data. GigaOm named it a ZTNA Leader in 2025.

Ready to evaluate Menlo Secure Application Access?

Count the contractors and BYOD users who only need web apps first, or let a TechBag advisor map every app by protocol, design the data rules and get the quote itemised in INR.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.