42%
of ransomware incidents began with malicious files or links
(Source: Comparitech ransomware statistics 2025)
Explore
What is CDRZero TrustThe detection gapCapabilitiesUse casesProducts
ProductsIntegrationFile supportCompliance
Control alignmentAPAC regulatory landscapeMore
Trust & certificationsAboutDocumentation Book a demoYou're in good company



























What is CDR
CDR removes file-borne threats without trying to detect them. Instead of scanning for known-bad, the file is taken apart and a safe copy is built. How much of the original survives is what separates vendors.
Glasswall CDR never passes the original file at all.
Zero-Trust and intelligent file protection
Glasswall CDR removes active content and rebuilds files into safe, usable versions. The result:
Trust nothing, verify by rebuilding: every file, on every channel, before it reaches a user or a system.
42%
of ransomware incidents began with malicious files or links
(Source: Comparitech ransomware statistics 2025)
Zero-day and AI-generated threats are increasingly used to deliver malware through files
(Source: OpenText Cybersecurity Threat Report 2025)
Glasswall CDR is a part of Oracle Cloud Infrastructure's (OCI) approach to implementing a Zero Trust protection principle.

Beazley's security is paramount, and this integration has significantly reinforced our cybersecurity framework.

Close the detection gap
Glasswall CDR eliminates file-borne risk without relying on threat identification. Objective testing across 8.27 million malicious files demonstrates why prevention is essential.
Waits for execution
Threats must reveal themselves before action can be taken.
Looks for known indicators
Detection depends on identifying malicious behaviour or signatures.
Removes the threat surface
Files are reconstructed into safe, usable versions before delivery.
What Glasswall does
Rebuilding files is the foundation, not the whole story. Glasswall pairs its CDR engine with AI-powered threat prediction and sensitive-data redaction, so the same platform that removes threats also anticipates them and keeps confidential content inside your boundary.
Neutralises file-borne threats in any file by rebuilding it to its manufacturer's known-good specification: office files, imagery, CAD, multimedia, archives and email, at line speed, fully usable.
Foresight scores file risk with machine learning trained on file structure, catching malicious content detection misses, including zero-day threats no signature has seen, on infrastructure you control.

Finds and redacts sensitive content in documents before they leave your boundary, and defeats steganography: rebuilt files cannot carry hidden payloads out.
Use cases
Every file is validated against its specification and rebuilt to a known-good standard in under a second, with active content and structural anomalies removed by construction. No signatures, no detonation, no waiting. The first control on upload portals, gateways, Microsoft 365, and transfer paths.
Glasswall HaloCDR
Files are sanitised on write to SharePoint, OneDrive, and Teams through the Glasswall API. Staff open and share documents in the same libraries, with no change to how they work.
Glasswall HaloStorage MonitorAPI
Citizens, customers, and third parties upload files straight into your case-management and claims systems. Every file is rebuilt before it lands, so case and records systems never touch file-borne malware.
Halo APICase study: EU bank KYC portal
Seized media, disclosure bundles and third-party productions are rebuilt before they enter evidence stores and review platforms, so investigators open every exhibit safely and case systems stay clean.
Glasswall GenesisFind & Redact
Move files across classification boundaries, mission enclaves, and disconnected networks. Each file is rebuilt to a known-good standard at the boundary, with the same outcome every time, so nothing untrusted crosses on the strength of a detection verdict.
Glasswall GenesisCase study: petabyte cross-domainCase study: RTB-compliant lab
Files arriving on USB drives, discs and unmanaged laptops are rebuilt at a kiosk or transfer station before they cross into the trusted network. Standard practice for plant floors, vessels, field sites and visitor media.
Glasswall MeteorCDR
Glasswall Genesis runs as a self-contained binary at the tactical edge: rebuild files in disconnected, degraded, intermittent or low-bandwidth environments, with no cloud dependency and nothing to install but one file.
Glasswall GenesisDDIL
Vendor updates, configuration files and engineering documents are rebuilt before they reach OT and ICS environments, whether they arrive over a diode, through a transfer zone or on removable media.
Glasswall GenesisGlasswall Meteor
Files from suppliers, contractors and managed providers arrive with implicit trust they have not earned. Rebuild every inbound document, archive and installer to a known-good standard before it enters your environment, whichever channel it arrives on.
CDRHalo API
After a breach, a merger, a cloud migration, or an audit finding, you inherit years of files no scanner ever cleared. Run Glasswall CDR as a scheduled job across your storage: every document, spreadsheet, and archive is rebuilt under the same policy as live traffic, from a single share up to multi-terabyte repositories.
Glasswall HaloCDR
After a compromise, nothing in the estate is trusted. Rebuild mailboxes, shares and repositories before they return to service, so recovery does not reinfect the environment: verified-clean files, with per-file evidence for the incident report.
Glasswall HaloCase study: research-centre breach
Glasswall Foresight scores file risk from structure, not signatures, and runs on your own infrastructure, so no files leave your network. Glasswall reports a 0.015% false-positive rate for PDFs, giving analysts a triage signal they can act on.
Glasswall Foresight
AI writes new malware variants faster than signatures can chase them. CDR does not chase: every file is rebuilt to its known-good specification, so polymorphic and machine-generated threats are removed by construction, and Foresight flags high-risk files before any detection exists.
CDRGlasswall Foresight
Documents feeding copilots, RAG indexes and model training are an attack path: hidden payloads, macros and embedded objects ride in on files. Rebuild every document to a clean, predictable form before your AI platform ingests it.
Halo APIGlasswall Genesis
Data hidden inside images and documents defeats inspection because there is nothing to detect. Rebuilding every image and file to a clean form destroys steganographic payloads in both directions: malware smuggled in, and sensitive data smuggled out.
CDRGlasswall Halo
Quishing campaigns hide malicious links inside QR codes in attachments, where link scanners cannot follow them. Glasswall detects QR codes in documents and removes or flags them under policy before the file is delivered.
CDRGlasswall Halo
Cloud and managed service providers embed Glasswall CDR into their own platforms, offering clean-file processing as a service to every tenant. Genesis ships as one self-contained binary, built for OEM integration into products, pipelines and customer offerings.
Glasswall GenesisOEM
Export processing volumes, policy outcomes, and rebuild rates as the reports your audit and assurance teams ask for: evidence that the control ran, and what it did, on every file.
Glasswall HaloCompliance evidence
Products
One CDR engine, one rebuild standard, one file-support matrix: from everyday documents to geospatial, CAD, executables and imagery. Wherever you deploy Glasswall, it is Genesis doing the rebuilding.
CDR Tool
One self-contained binary for adding directly into your own products and workflows. Built for OEMs, CI/CD, tactical edge, cross-domain and air-gapped deployments.
Server
Scalable deployment with policy management, dashboards, authentication, REST and ICAP interfaces, plus Microsoft 365 and cloud storage integrations.
Desktop
Desktop file protection for Windows. Drag in a file, receive a safe version back. Ideal for post-breach remediation and tactical edge environments.
Integration
One engine, reachable from every file path: no rip-and-replace, and the same policy and audit trail on each channel.

Embed CDR into your own applications and pipelines via Halo APIs or the Genesis engine.

Sanitise downloads and uploads through the secure web proxy you already operate.
Mailbox at-rest protection for Microsoft 365 through Storage Monitor for Outlook.

Continuous at-rest protection for SharePoint, OneDrive, mailboxes and file shares.

Kiosk check-in for USB, SD and optical media at the gate of OT and air-gapped sites.

The Email CDR Relay cleans inbound attachments in transit, entirely inside your own network.
Powered by Safeware

Sanitise legacy repositories as they move, so nothing dormant travels into the new environment.
Denied, disrupted, intermittent and limited-bandwidth settings: the engine runs where there is no connectivity at all.

Citizen, KYC and partner file intake sanitised at ingress, including cross-domain transfer paths.
File support
The Genesis engine's coverage, shared by every deployment.
PDF · OOXML · Legacy Office · ODF · RTF
PE · ELF · Mach-O · LNK
EML · MSG · Nested attachment processing
NITF, including MIL-STD-2500C and TRE analysis · SIDD · GPX · KML · GeoJSON · SHP · DWG · DXF · STEP AP242
H.264 · H.265 · MPEG-2 · MP4 · MP3 · WAV
JSON · CSV · SVG · HTML · CSS
JPEG · PNG · TIFF · GIF · BMP · HEIF · JPEG 2000 · WebP · WSQ · DICOM
ZIP · 7Z · RAR · TAR · GZ · BZ2 · XZ · ISO
CMYK-accurate images. Embedded fonts intact. Coordinates untouched. A rebuilt file nobody has to ask about.
Trusted where it matters
Glasswall technology protects government, defence and intelligence communities worldwide. Across Asia-Pacific, Safeware delivers it to government, defence, financial services and critical-infrastructure organisations.
Who we are
We contract, deploy and support Glasswall technology across APAC for government, defence, financial services and critical infrastructure: on your infrastructure, in your jurisdiction, including air-gapped environments. Engine-level issues escalate directly into Glasswall engineering; everything else is handled in-region.
Contract in-region with a Singapore-based partner rather than a remote vendor.
Architecture, installation, policy tuning and production support, with vendor-level escalation into Glasswall.
On-premises and air-gapped delivery for environments where data cannot leave.
Contact
A tailored walkthrough of Glasswall CDR against your own files takes 25 minutes. Our full site is being finalised; in the meantime, reach us directly.