Menlo Security expanded Menlo Agent Runtime Security (MARS) with new capabilities that extend the controls enterprises already use to govern their people to the AI agents now working alongside them. Introduced earlier this year, MARS is a cloud-based Browser Security Platform that protects AI assistants, coding agents, and autonomous agents by sanitizing the web pages and files they read, neutralizing prompt injection and blocking data exfiltration.
The release secures the AI assistants, coding agents, and autonomous agents enterprises are deploying: browser assistants like Microsoft Copilot and Google Gemini, coding agents like Claude Code, desktop assistants like Claude Cowork, and autonomous agents that require web access. MARS is the first Browser Security Platform to strip prompt injection and hidden instructions out of what agents read and to keep them from leaking sensitive data.
An AI agent will read and carry out an instruction hidden in white-on-white text, a file’s metadata, or a single human-invisible pixel, something no person would ever notice. Mandiant’s 2026 AI Risk and Resilience report names prompt injection a top threat to AI applications. Gartner projects that by the end of 2026, 40% of enterprise applications will include task-specific AI agents, up from less than 5% in 2025, faster than most enterprises can secure them.
Most enterprises face a bad choice: block agents and fall behind, or allow them and rely on built-in controls that were never designed for the agentic attack surface. MARS is built for the middle, giving security teams the guardrails to approve agentic AI and move fast without choosing between speed and safety.
“Every enterprise is racing to put AI agents to work, but agents operate at machine speed without human skepticism,” said Bill Robbins, Chief Executive Officer of Menlo Security. “They live in the browser and the everyday tools our teams rely on, which is exactly where attackers are aiming. MARS provides the essential runtime guardrails so security teams can confidently say yes to agentic AI instead of standing in its way.”
As enterprises connect AI agents to real tools and data, the security problem moves from the model to everything around it. Attackers are already going after the content and integrations agents depend on, and defenders need controls that work at that layer. That is where MARS operates.
Autonomous agents and coding agents run on the endpoint or in the cloud, and they reach the web and files through MARS. MARS runs that web activity in the Menlo Cloud and cleans the pages and files, including downloads and uploads, before the agent sees them, so an agent only ever acts on a sanitized version of what it requested. This prevents attacks rather than detecting them after the damage. Five capabilities set MARS apart:
- Isolation and threat removal. Strips prompt injection and hidden instructions, such as invisible or white-on-white text, from the web pages and files an agent reads.
- File sanitization. Files pulled from sources like SharePoint and OneDrive are sanitized before an agent ingests them, removing hidden instructions and malware, so a poisoned document cannot hijack an agent’s goal.
- Adaptive data governance and protection for agents. Through Menlo AI Adaptive DLP (Data Loss Prevention), data protections Menlo built for people now extend to agents, masking sensitive information, controlling which websites and applications each agent can access, and applying granular, per-agent policy, so agents do not become a new path for data to leak.
- Agent authentication and attribution. MARS provides token-based authentication for the agents driving secure browser sessions, enabling seamless authentication to the Menlo platform and per-agent attribution for policy and visibility.
- Human oversight and forensics. Security teams get per-agent activity logs, session recording, and the ability to take over live agent browser sessions, backed by a tamper-proof record of the content it saw and acted on.
Because MARS runs on the same Browser Security Platform Menlo already uses to govern human employees, security teams apply one policy framework across both people and agents, with granular, agent-specific controls. Its isolation-first design aligns with emerging standards, including the OWASP agentic guidelines, the NIST AI Risk Management Framework, and the EU AI Act.
Menlo’s decision to build MARS follows more than 70 conversations with customers over the past three months, which surfaced the same concerns: assistants with broad access to email and files, low-code agents inheriting employee credentials, coding agents exposing source code, and autonomous agents exposed on the open web.





