Menlo Security Extends MARS to Secure AI Assistants and Coding Agents Against Threats
MENLO SECURITY, a leader in browser security for human and agentic workforces, has expanded its Menlo Agent Runtime Security (MARS) platform with new capabilities that extend the controls enterprises use to govern their people to the AI agents working alongside them. The updated MARS platform now secures AI assistants, coding agents, and autonomous agents by sanitizing web pages and files they read, neutralizing prompt injection, and blocking data exfiltration.
The release addresses a pressing concern for businesses: securing the rapidly growing number of AI-powered tools that are being deployed in the workplace. These include browser assistants like Microsoft Copilot and Google Gemini, coding agents like Claude Code, desktop assistants like Claude Cowork, and autonomous agents that require web access. MARS is the first Browser Security Platform to strip prompt injection and hidden instructions out of what agents read and to keep them from leaking sensitive data.
Prompt injection refers to a type of attack where an AI agent reads and carries out an instruction hidden in white-on-white text, a file’s metadata, or a single human-invisible pixel. This threat is particularly concerning because it can be executed without the knowledge of even the most vigilant security teams. Mandiant’s 2026 AI Risk and Resilience report highlights prompt injection as one of the top threats to AI applications.
The growing adoption of AI agents in enterprises has created a new challenge for security teams: they must either block these agents or allow them, relying on built-in controls that were never designed for the agentic attack surface. MARS is designed to bridge this gap by providing essential runtime guardrails so security teams can confidently say yes to agentic AI instead of standing in its way.
According to Bill Robbins, Chief Executive Officer of Menlo Security, ‘Every enterprise is racing to put AI agents to work, but agents operate at machine speed without human skepticism. They live in the browser and the everyday tools our teams rely on, which is exactly where attackers are aiming.’ MARS provides a comprehensive solution for securing these AI-powered tools by running web activity in the Menlo Cloud and cleaning pages and files before they reach the agent.
The platform’s isolation-first design aligns with emerging standards, including the OWASP agentic guidelines, the NIST AI Risk Management Framework, and the EU AI Act. MARS operates at a layer that is critical for securing AI agents: everything around them, not just their models. This includes content and integrations they depend on.
Autonomous agents and coding agents run on endpoints or in the cloud, reaching the web and files through MARS. The platform cleans pages and files before an agent sees them, preventing attacks rather than detecting them after the damage is done. Five key capabilities set MARS apart: isolation and threat removal, file sanitization, adaptive data governance and protection for agents, agent authentication and attribution, and human oversight and forensics.
Isolation and threat removal involve stripping prompt injection and hidden instructions from web pages and files an agent reads. File sanitization ensures that files pulled from sources like SharePoint and OneDrive are cleaned before an agent ingests them, removing malware and hidden instructions. Adaptive data governance and protection for agents apply granular policy controls to mask sensitive information and control which websites and applications each agent can access.
Agent authentication and attribution provide token-based authentication for the agents driving secure browser sessions, enabling seamless authentication to the Menlo platform and per-agent attribution for policy and visibility. Human oversight and forensics offer security teams per-agent activity logs, session recording, and the ability to take over live agent browser sessions, backed by a tamper-proof record of content it saw and acted on.
Because MARS runs on the same Browser Security Platform Menlo already uses to govern human employees, security teams apply one policy framework across both people and agents. This streamlines their work and reduces complexity. The platform’s isolation-first design also aligns with emerging standards for securing AI-powered tools in enterprises.
The decision to build MARS follows more than 70 conversations with customers over the past three months, which surfaced concerns about assistants with broad access to email and files, low-code agents inheriting employee credentials, coding agents exposing source code, and autonomous agents exposed on the open web. Menlo’s solution addresses these pressing issues head-on by providing a comprehensive platform for securing AI-powered tools in enterprises.
AI assistants are increasingly being used in businesses as data analysis tools to streamline operations and improve efficiency. However, their growing adoption has also created new security challenges that must be addressed. MARS is designed to provide the essential runtime guardrails so security teams can confidently say yes to agentic AI instead of standing in its way.
The platform’s capabilities are crucial for securing AI-powered tools in enterprises because they address a critical gap in current security solutions: protecting everything around AI agents, not just their models. This includes content and integrations they depend on. By providing a comprehensive solution for securing these tools, MARS helps businesses to confidently deploy AI assistants and coding agents without compromising their security posture.