What Is Menlo Security? Browser Isolation, Explained, and Where It Stops
.jpeg)
Menlo Security is the company most people think of when they hear "browser isolation." It built its name on a simple, compelling idea: never let web content run on the laptop at all. In 2026 Menlo has broadened that pitch into a full Browser Security Platform aimed at humans and AI agents alike. If you are already comparing vendors, our head-to-head on Menlo Security vs Zscaler is the quickest way in. This post answers the earlier question: what Menlo actually is, how it works, and where its model stops.
The short answer
Menlo Security is a cloud security company, headquartered in Mountain View, California, whose platform centers on remote browser isolation. Menlo loads web pages in a remote browser in its cloud, executes the active content there, and sends a sanitized version down to the user's device. It sells that isolation alongside secure web gateway, browser DLP, and secure application access capabilities. Isolation is Menlo's hook and its ceiling: it is excellent at keeping browser-borne threats off the endpoint, but its controls are built around the browser session, so AI desktop apps, IDEs, command-line tools, and API traffic sit largely outside the frame. dope.security takes the opposite approach, inspecting all web traffic on the device itself and sending it direct.
That is a testable claim. Open ChatGPT Desktop or an AI coding assistant in your terminal and ask where your browser security platform sees that traffic. The answer defines the gap.
What is Menlo Security?
Menlo Security came out of stealth in 2015 and has raised about $250 million, with backers including Vista Equity Partners, General Catalyst, JPMorgan Chase, American Express Ventures, and HSBC. Its product family has grown well beyond the original isolation service.
- Remote browser isolation. The core. Web content runs in a Menlo cloud container, not on the laptop.
- Secure web gateway. Cloud proxy inspection and URL policy around the isolation service.
- Browser DLP. Data controls applied to what users upload, paste, and type in isolated sessions.
- Secure application access. Browser-based access to private and SaaS applications.
- Secure enterprise browser. Menlo Secure Enterprise Browser is reviewed as its own product on Gartner Peer Insights.
In March 2026 Menlo announced a Browser Security Platform built to secure what it calls the agentic enterprise. Menlo argues the browser has become the operating system for both people and AI agents, and the platform adds AI agent security (a "Guardian Runtime" that enforces instruction-data separation), deterministic session visibility, and least-privileged agent access through Menlo Secure Application Access.
How Menlo Security works
The mechanics matter, because they explain both the strengths and the trade-offs. When a user browses to a site, the request goes to Menlo's cloud. A remote browser there fetches and renders the page and runs its scripts. Menlo then transmits a safe representation of the page to the user's local browser. Menlo's patented approach, Adaptive Clientless Rendering, uses DOM mirroring to send lightweight, clean content rather than a video stream of pixels.
That design keeps malicious code away from the endpoint. It also means every isolated page is served through a cloud round trip, and interactive web apps have to behave correctly when rendered by one browser and displayed by another.
Isolation vs pixel streaming
Menlo is candid that not all isolation is equal. Its own marketing criticizes pixel-streaming isolation products for lag, latency, and mushy scrolling, and positions DOM mirroring as the fix. That is a fair distinction, and it is also a useful admission: the category's defining risk is user experience, and the vendor that knows it best says so. We cover when the trade is worth it in when remote browser isolation actually helps.
Does Menlo Security slow browsing down?
Any cloud-delivered inspection adds a detour: device to the vendor's point of presence, out to the destination, and back. Isolation adds rendering work on top of that. Measured cloud-proxy latency typically runs 40 to 80 milliseconds near a point of presence and 150 to 400 milliseconds when users are far from one, and a modern SaaS page chains dozens of requests. The math is in the latency math behind cloud proxy SWGs.
Rendering compatibility is the other half. On November 9, 2023, Menlo's isolation broke Cloudflare CAPTCHA challenges for users, a reminder that remote rendering can collide with the sites people need to reach. Reviewers also report that isolation can break interactive applications, which leads to exceptions lists that send some traffic around the isolation layer.
How much is the detour costing you? Run the Fly-Direct Speed Test to measure your real round-trip latency and compare a cloud-proxy or isolation detour with inspection on the device. See how dope.security's Fly-Direct Secure Web Gateway removes the stopover, or book a 20-minute demo to see it live.
The takeaway: isolation moves the risk off the laptop by moving the browsing into the cloud, and every page pays for the trip.
What Menlo Security does well
Credit where it is due. Menlo is a strong fit in specific situations.
- Zero-day web threats. If active content never runs on the device, a browser exploit has nothing to land on. For high-risk browsing, that is a genuinely strong control.
- Unmanaged and contractor devices. Browser-based delivery reaches users where you cannot install an agent.
- A thoughtful rendering approach. DOM mirroring is a real improvement over pixel streaming.
- An early bet on agents. Menlo is taking AI agents seriously as a security population, which many incumbents are not.
Where Menlo Security falls short in 2026
The limits follow directly from the architecture.
AI governance is bound to the browser
Menlo's AI controls apply to browser sessions. That covers ChatGPT or Claude in a tab. It does not cover ChatGPT Desktop, Claude Desktop, AI features inside IDEs, command-line coding assistants, scripts calling AI APIs, or MCP server traffic from developer tools, because none of that runs through the browser. That is a growing share of real AI usage, and we map it in how to detect shadow AI in desktop apps, IDEs, and CLIs and MCP server security and governance. Menlo's new Browser Security Platform extends its reach to agents that use headless browsers or web protocols, but its own framing still puts the control point inside the browser session.
Dictionary DLP, not semantic DLP
Menlo's browser DLP is built on regex and dictionaries, with more than 380 predefined dictionaries. That catches structured data like card numbers well. It struggles with unstructured content, such as a pasted paragraph of product strategy or a block of source code, which is exactly what people paste into AI prompts.
Configuration effort
Reviewers consistently name configuration complexity as their top complaint, and isolation exceptions add another list to maintain. Neither is a deal breaker. Both are real operating cost.
Menlo Security vs dope.security: the head-to-head
Both products want web traffic to be safe without slowing people down. They put the control point in different places. Here is the comparison, line by line.
- Where the control point lives. Menlo runs the browsing session in its cloud and sends a sanitized page to the device. dope.security inspects traffic on the device with an on-device SSL inspection proxy and sends it direct to the destination.
- Network path. Menlo routes isolated and proxied traffic through its cloud. dope.security has no points of presence in the data path and delivers up to 4x performance over legacy proxy SWGs.
- AI surfaces covered. Menlo's AI controls are bound to the browser. dope.security inspects web egress from the endpoint, so AI traffic from desktop apps and tools is in scope, not just browser tabs.
- Personal vs corporate AI accounts. Blocking personal ChatGPT while allowing the corporate workspace requires tenant-aware inspection of decrypted traffic. dope.security Cloud Application Control restricts ChatGPT, Claude, Google, and Microsoft 365 to corporate tenants on the device.
- DLP approach. Menlo browser DLP uses regex and dictionaries. Dopamine DLP intercepts file uploads and AI prompts and classifies them with large language models through zero-retention OpenAI APIs, covering ChatGPT, Claude, Perplexity, Abacus, and Copilot.
- Compatibility. Remote rendering can break interactive apps and challenges like CAPTCHAs. dope.security leaves page rendering to the local browser and surfaces SSL errors from certificate pinning so admins can create targeted bypasses in a few clicks.
- Footprint and console. The dope.security agent is Mac native and Windows, uses less than 100 MB of RAM, and runs SWG, CASB Neural, and Dopamine DLP under one console.
For a broader field, our Menlo Security alternatives guide ranks the options, and do you need a secure enterprise browser covers the browser-first category as a whole.
Questions to ask in a Menlo Security proof of concept
A proof of concept is where architecture stops being abstract. These questions surface the trade-offs quickly, and they apply to any browser-first platform, not just Menlo.
- Which AI tools does the policy actually see? Test ChatGPT in a tab, then ChatGPT Desktop, then an AI assistant inside an IDE or terminal. Note which ones show up in the logs.
- How many isolation exceptions do we need in week one? Track every internal app, SaaS workflow, and challenge page that has to be excluded, because each exception is traffic outside the isolation layer.
- What does a pasted paragraph of source code trigger? Dictionary DLP is easy to test with card numbers. Test it with unstructured content instead.
- Can we allow corporate ChatGPT and block personal ChatGPT? Run the same-domain tenant test live and confirm it is enforced, not just reported.
- What do remote users feel? Measure page load times for heavy SaaS apps from home networks and from abroad, not just from headquarters.
Do you still need browser isolation?
Sometimes, for a slice of traffic. Isolation earns its keep for high-risk categories, uncategorized sites, and users on unmanaged devices. For the managed laptops that make up most of a 250 to 5,000 person workforce, the bigger risks in 2026 are data leaving through AI prompts and uploads, personal SaaS accounts, and shadow AI tools that never open a browser tab. Those are endpoint problems, and they are cheaper to solve where the data starts.
A practical pattern is to keep isolation narrow, for the risky categories, and move general web security, AI tenant control, and DLP onto the device. Deployment speed is rarely the obstacle. Greylock Partners replaced Cisco Umbrella with dope.security and went from first proposal to signed contract in 27 days, deploying through Intune in phases. Read how Greylock Partners made the switch.
The bottom line on Menlo Security
In one line: Menlo Security secures the browser tab very well, but the browser is only one of the places data and AI traffic leave a company in 2026, so a browser-first platform is a partial control by design. If you want web security, AI governance, and DLP that cover every app on the laptop and send traffic direct, that is what dope.security was built to do. Explore the Fly-Direct Secure Web Gateway, see how teams block personal ChatGPT while keeping the corporate account, or book a 20-minute demo.
Frequently Asked Questions
What does Menlo Security do?
Menlo Security provides cloud-delivered browser security centered on remote browser isolation. Web pages load and execute in a remote browser in Menlo's cloud, and a sanitized version is sent to the user's device. Menlo also sells secure web gateway, browser DLP, and secure application access capabilities around that core.
Is Menlo Security a secure web gateway?
Menlo offers secure web gateway capabilities, but its identity is isolation. Traffic is proxied and, for isolated sessions, rendered in Menlo's cloud before reaching the user. dope.security is a Fly-Direct secure web gateway that performs SSL inspection on the device, so there is no cloud detour in the data path.
What is Menlo Security's Browser Security Platform?
Announced in March 2026, the Browser Security Platform extends Menlo's controls to AI agents as well as people. It adds AI agent security that enforces instruction-data separation, session-level forensic visibility, and least-privileged agent access through Menlo Secure Application Access. Its control point remains the browser session.
Can Menlo Security control ChatGPT Desktop or AI coding tools?
Menlo's AI controls are bound to browser sessions, so AI desktop apps, IDE assistants, command-line tools, and direct API calls fall largely outside them. dope.security inspects web egress on the endpoint, which brings that traffic into scope, and pairs it with Cloud Application Control and Dopamine DLP.
Does remote browser isolation add latency?
It adds a cloud round trip plus remote rendering work. Menlo's own marketing criticizes pixel-streaming isolation for lag and latency and positions its DOM-mirroring approach as lighter. Cloud-proxy latency typically runs 40 to 80 milliseconds near a point of presence and 150 to 400 milliseconds far from one. dope.security adds no network detour because inspection runs on the device.
What is the best Menlo Security alternative?
For teams whose priority is AI governance and DLP across every app on the laptop, not just the browser, dope.security is a strong alternative. It combines an on-device SSL inspection proxy, Cloud Application Control for corporate-only AI tenants, and Dopamine DLP for prompts and uploads under one console, with an agent that uses less than 100 MB of RAM.



