Safeware Glasswall APAC Partner
Book a demo

Glasswall, delivered across Asia-Pacific

Neutralise file-based malware before it reaches your users

  • Stops known, unknown and AI-generated file threats, with AI-powered risk prediction built in
  • Every file rebuilt to its manufacturer's known-good specification, not scanned for known-bad
  • Deploys on-premises, in the cloud, or fully air-gapped
  • Contracted, deployed and supported in-region by Safeware

You're in good company

SingtelRepublic of Singapore Air ForceCompAsiaTUIST EngineeringJohn KeellsSingHealthCapitaLandSATSTicketmasterDBS BankOpodoORIXSoftwareOneNHSCRAPearsonNTUC LearningHubROHEIPenguin Random HouseAscendasHumanaExocapAge UKMullenLowePalgrave MacmillanReed Exhibitions

What is CDR

Content Disarm and Reconstruction, from the ground up

CDR removes file-borne threats without trying to detect them. Instead of scanning for known-bad, the file is taken apart and a safe copy is built. How much of the original survives is what separates vendors.

Glasswall CDR never passes the original file at all.

  • Every file is decomposed into the known-good components of its manufacturer's published specification
  • The parts are held in an intermediate representation; anything that does not conform is discarded
  • A brand-new file is manufactured from that intermediate form: the recipe, never the original bytes
  • No signatures, no detonation. Effective against known, unknown and AI-generated threats alike
A malicious PDF decomposed, repaired and rebuilt into a safe, functional file

About CDR

Zero-Trust and intelligent file protection

Glasswall CDR takes a Zero Trust, prevention-first approach

Glasswall CDR removes active content and rebuilds files into safe, usable versions. The result:

  • No reliance on signatures
  • Protection against known, unknown and AI-generated threats
  • Safe files delivered to users and systems
  • No need to predict attacker behaviour

Trust nothing, verify by rebuilding: every file, on every channel, before it reaches a user or a system.

42%

of ransomware incidents began with malicious files or links

(Source: Comparitech ransomware statistics 2025)

Zero-day and AI-generated threats are increasingly used to deliver malware through files

(Source: OpenText Cybersecurity Threat Report 2025)

Glasswall CDR is a part of Oracle Cloud Infrastructure's (OCI) approach to implementing a Zero Trust protection principle.

Oracle

Beazley's security is paramount, and this integration has significantly reinforced our cybersecurity framework.

Beazley

Close the detection gap

You can't detect every threat

Glasswall CDR eliminates file-borne risk without relying on threat identification. Objective testing across 8.27 million malicious files demonstrates why prevention is essential.

Sandboxing

Waits for execution

Threats must reveal themselves before action can be taken.

1in6 malicious files
evaded detection

Antivirus

Looks for known indicators

Detection depends on identifying malicious behaviour or signatures.

1in8 malicious files
evaded detection

Glasswall CDR

Removes the threat surface

Files are reconstructed into safe, usable versions before delivery.

100% of malicious files
neutralised

Glasswall Halo capabilities

Core capabilities

Rebuilding files is the foundation. Around it, these capabilities predict new threats, catch sensitive terms before they leave, spot prompt injection before text reaches an AI model, and pass a file only when every anti-virus engine agrees.

Content disarm and reconstruction

Stop file-borne threats by rebuilding files instead of trying to detect them. Glasswall Halo checks each file against its format's specification and builds a new, fully usable file, so nothing has to be recognised first.

AI-powered threat prediction

Get an early warning about risky files, even threats no signature has seen. Glasswall Halo scores each file's risk from its internal structure, with no signatures, sandbox or internet connection. It covers PDF, DOCX and XLSX.

Data loss prevention

Catch sensitive terms in documents before they leave, as they are rebuilt. Each match is reported, blocked or redacted. It covers Microsoft Office documents and plain text.

Prompt injection detection

Spot prompt injection in text before your application sends it to an AI model. Returns one of three verdicts. English only, up to 512 tokens per request, with a separate Pulsar licence.

Multi-AV scanning

Pass a file only when every anti-virus engine says it is clean. Choose a curated pack of engines from different vendors, or bring the scanners you already run.

Use cases

Find the control that fits your boundary

Boundary File Risk Removal

Every file is validated against its specification and rebuilt to a known-good standard in under a second, with active content and structural anomalies removed by construction. No signatures, no detonation, no waiting. The first control on upload portals, gateways, Microsoft 365, and transfer paths.

Glasswall HaloCDR

Explore the products

Incoming and Outgoing Email Protection

Email is a common way in for malware. The email relay sits in your mail flow beside Exchange or Microsoft 365 and rebuilds the whole message, incoming and outgoing: the message itself, attachments, calendar invites and the HTML body with its styling.

Glasswall HaloEmail relay

See the email relay

Encrypted Document Release

Encrypted files cannot be read, so they cannot be rebuilt and are held instead. The recipient signs in with Microsoft 365 or any OpenID Connect (OIDC) identity provider, types the password once, and receives a rebuilt copy. Each release link works only once.

Glasswall HaloPassword-protected files

See password-protected files

Digital Evidence and eDiscovery Intake

Seized media, disclosure bundles and third-party productions are rebuilt before they enter evidence stores and review platforms, so investigators open every exhibit safely and case systems stay clean.

Glasswall GenesisData loss prevention

Talk to us

Removable Media and Kiosk Ingest

Files arriving on USB drives, discs and unmanaged laptops are rebuilt at a kiosk or transfer station before they cross into the trusted network. Standard practice for plant floors, vessels, field sites and visitor media.

Glasswall HaloZero Trust KioskCDR

See the Zero Trust Kiosk

OT Removable Media Intake

Contractors and vendors bring USB sticks, SD cards and discs onto plant and critical-infrastructure sites. At the kiosk, every file goes through Glasswall Halo and your other checks, and the engineer collects what passed. One kiosk can work alone, with no network connection.

Glasswall HaloZero Trust Kiosk

See the Zero Trust Kiosk

Offline and DDIL Operations

Glasswall Genesis runs as a self-contained binary at the tactical edge: rebuild files in disconnected, degraded, intermittent or low-bandwidth environments, with no cloud dependency and nothing to install but one file.

Glasswall GenesisDDIL

DDIL briefing

OT and Industrial File Ingest

Vendor updates, configuration files and engineering documents are rebuilt before they reach OT and ICS environments, whether they arrive over a diode, through a transfer zone or on removable media.

Glasswall GenesisGlasswall Meteor

See integration paths

Vendor Patch and Installer Assurance

Vendor patches and installers for OT and critical systems are trusted because of who signed them, not rebuilt. The publisher's signature and your approved file lists are checked, any deny blocks the file, and a file on no list is unknown, never approved.

Glasswall HaloSigned software verification

See signed software verification

Large Archive and Disk Image Intake

Engineering bundles and disc images can be too large or too deeply nested to check in one go. Nested ZIP and ISO files are opened, every file inside is rebuilt, and the container is rebuilt with a tamper-evident manifest of what happened to each file.

Glasswall HaloLarge archive processing

See large archive processing

Supply Chain File Risk

Files from suppliers, contractors and managed providers arrive with implicit trust they have not earned. Rebuild every inbound document, archive and installer to a known-good standard before it enters your environment, whichever channel it arrives on.

CDRIntegration APIs

File threat landscape

Web Proxy Download Protection

Some web gateways and proxies cannot pass downloads to another service for checking. A bridge becomes their next stop and sends the files to Glasswall Halo's ICAP server to be rebuilt. If Halo cannot be reached, files are blocked, not passed.

Glasswall HaloWeb gateway bridge

See the web gateway bridge

Repository Remediation After Incidents or Migration

After a breach, a merger, a cloud migration, or an audit finding, you inherit years of files no scanner ever cleared. Run Glasswall CDR as a scheduled job across your storage: every document, spreadsheet, and archive is rebuilt under the same policy as live traffic, from a single share up to multi-terabyte repositories.

Glasswall HaloCDR

Migration cleansing guide

Post-Breach Recovery

After a compromise, nothing in the estate is trusted. Rebuild mailboxes, shares and repositories before they return to service, so recovery does not reinfect the environment: verified-clean files, with per-file evidence for the incident report.

Glasswall HaloCase study: research-centre breach

Post-breach remediation

File Threat Intelligence and Triage

AI-powered threat prediction scores file risk from structure, not signatures, and runs on your own infrastructure, so no files leave your network. Glasswall reports a 0.015% false-positive rate for PDFs, giving analysts a triage signal they can act on.

Glasswall HaloAI-powered threat prediction

See AI-powered threat prediction

Multi-Engine Malware Consensus

One anti-virus engine can miss what another catches. Send each file to engines from different vendors at once, alongside CDR, and release it only when every one reports it clean. Signed signature bundles keep air-gapped sites current.

Glasswall HaloMulti-AV scanning

See multi-AV scanning

AI-Generated Malware Defence

AI writes new malware variants faster than signatures can chase them. CDR does not chase: every file is rebuilt to its known-good specification, so polymorphic and machine-generated threats are removed by construction, and AI-powered threat prediction flags high-risk files before any detection exists.

CDRAI-powered threat prediction

File threat landscape

Controlled Macros in Business Workbooks

Some teams cannot simply strip macros from the workbooks and templates they depend on. Each macro your policy keeps is analysed without being run, and the file is blocked, flagged, allowed or cleaned, with the findings behind the verdict.

Glasswall HaloMacro analysis

See macro analysis

Safe File Ingestion for AI Platforms

Documents feeding copilots, RAG indexes and model training are an attack path: hidden payloads, macros and embedded objects ride in on files. Rebuild every document to a clean, predictable form before your AI platform ingests it.

Integration APIsGlasswall Genesis

Discuss AI pipelines

AI Assistant and LLM Input Protection

Text from people you do not control can carry planted instructions. Check each prompt before your application sends it to a copilot or chatbot model, and get one of three verdicts. English only, up to 512 tokens per request, with a separate Pulsar licence.

Glasswall HaloPrompt injection detection

See prompt injection detection

Steganography and Hidden Data

Data hidden inside images and documents defeats inspection because there is nothing to detect. Rebuilding every image and file to a clean form destroys steganographic payloads in both directions: malware smuggled in, and sensitive data smuggled out.

CDRGlasswall Halo

Steganography brief

QR Code Threats (Quishing)

Quishing campaigns hide malicious links inside QR codes in attachments, where link scanners cannot follow them. Glasswall detects QR codes in documents and removes or flags them under policy before the file is delivered.

CDRGlasswall Halo

QR threat brief

Service Provider and OEM Platforms

Cloud and managed service providers embed Glasswall CDR into their own platforms, offering clean-file processing as a service to every tenant. Genesis ships as one self-contained binary, built for OEM integration into products, pipelines and customer offerings.

Glasswall GenesisOEM

CSP case study

File Policy Telemetry and Audit Evidence

Export processing volumes, policy outcomes, and rebuild rates as the reports your audit and assurance teams ask for: evidence that the control ran, and what it did, on every file.

Glasswall HaloCompliance evidence

See monitoring and SIEM integration

SOC Visibility into File Processing

Halo's logs, traces and metrics reach the SIEM and dashboards your SOC already uses, in one format, with passwords and other secrets removed first. Grafana, Splunk, Microsoft Sentinel, Datadog and IBM QRadar are supported, or any tool that accepts OpenTelemetry (OTLP).

Glasswall HaloMonitoring and SIEM integration

See monitoring and SIEM integration

Products

One engine. Three products.

Glasswall Genesis is the engine inside every product

One CDR engine, one rebuild standard, one file-support matrix: from everyday documents to geospatial, CAD, executables and imagery. Wherever you deploy Glasswall, it is Genesis doing the rebuilding.

Explore Genesis

Glasswall Genesis

CDR Tool

One self-contained binary for adding directly into your own products and workflows. Built for OEMs, CI/CD, tactical edge, cross-domain and air-gapped deployments.

Explore Genesis

Glasswall Halo

Server

Scalable deployment with policy management, dashboards, authentication, REST and ICAP interfaces, plus Microsoft 365 and cloud storage integrations.

Explore Halo

Glasswall Meteor

Desktop

Desktop file protection for Windows. Drag in a file, receive a safe version back. Ideal for post-breach remediation and tactical edge environments.

Explore Meteor

Compare Genesis, Halo and Meteor

Integration

Fits the estate you already run

One engine, reachable from every file path: no rip-and-replace, and the same policy and audit trail on each channel.

Integration APIs

Embed CDR into your own applications and pipelines through Halo's Integration APIs, the Genesis engine as a process, or the Embedded Engine SDK in-process.

See this capability

Web gateway integration

Rebuild downloads and uploads through the secure web gateway or proxy you already run. Halo includes its own ICAP server.

See this capability

Web gateway bridge

For gateways that cannot send downloads over ICAP. A bridge in front of Halo's ICAP server that blocks files if Halo cannot be reached.

See this capability

Microsoft 365 storage protection

Files are rebuilt as they are uploaded to SharePoint, OneDrive and Teams, and the rebuilt version replaces the original in place.

See this capability

Zero Trust Kiosk

Check USB sticks, SD cards and discs at the gate of OT and air-gapped sites, before files reach your network.

See this capability

Email relay

Rebuilds incoming and outgoing email, including the message itself, attachments, calendar invites and the HTML body, entirely inside your own network.

See this capability

Cloud migration

Sanitise legacy repositories as they move, so nothing dormant travels into the new environment.

Cloud migration guide

Offline and DDIL environments

Denied, disrupted, intermittent and limited-bandwidth settings: the engine runs where there is no connectivity at all.

DDIL insights

Upload portals & transfer

Citizen, KYC and partner file intake sanitised at ingress, including cross-domain transfer paths.

File upload portals

File support

140+ file extensions. Rebuilt with fidelity.

The Genesis engine's coverage, shared by every deployment.

Documents

PDF · OOXML · Legacy Office · ODF · RTF

Executables & shortcuts

PE · ELF · Mach-O · LNK

Email

EML · MSG · Nested attachment processing

Geospatial & CAD

NITF, including MIL-STD-2500C and TRE analysis · SIDD · GPX · KML · GeoJSON · SHP · DWG · DXF · STEP AP242

Audio & video

H.264 · H.265 · MPEG-2 · MP4 · MP3 · WAV

Structured data & web

JSON · CSV · SVG · HTML · CSS

Imagery

JPEG · PNG · TIFF · GIF · BMP · HEIF · JPEG 2000 · WebP · WSQ · DICOM

Archive formats

ZIP · 7Z · RAR · TAR · GZ · BZ2 · XZ · ISO

And the fidelity to match

CMYK-accurate images. Embedded fonts intact. Coordinates untouched. A rebuilt file nobody has to ask about.

Trusted where it matters

Deployed by the world's most security-conscious organisations

Glasswall technology protects government, defence and intelligence communities worldwide. Across Asia-Pacific, Safeware delivers it to government, defence, financial services and critical-infrastructure organisations.

NATO NSA HM Government AUKUS Microsoft Oracle BAE Systems Beazley

Who we are

Safeware is the independent Glasswall representative for Asia-Pacific

We contract, deploy and support Glasswall technology across APAC for government, defence, financial services and critical infrastructure: on your infrastructure, in your jurisdiction, including air-gapped environments. Engine-level issues escalate directly into Glasswall engineering; everything else is handled in-region.

Local contracting

Contract in-region with a Singapore-based partner rather than a remote vendor.

Deployment and support

Architecture, installation, policy tuning and production support, with vendor-level escalation into Glasswall.

Sovereign-ready

On-premises and air-gapped delivery for environments where data cannot leave.

FAQ

Frequently asked questions

The questions APAC buyers ask most, about the technology, deployment, pricing and support. Ask us anything else through the form below.

What is CDR (Content Disarm and Reconstruction)?

CDR is a zero trust file security technique. Rather than trying to detect malware, Glasswall CDR validates each file against its format specification, removes active content such as macros, scripts and embedded objects by policy, and rebuilds a clean copy that still opens and works. In Glasswall's published testing, 100% of malicious files were neutralised across 8.27 million files tested.

How does Glasswall CDR differ from antivirus or sandboxing?

Antivirus, sandboxing and EDR all share one assumption: that a threat can be recognised. Glasswall reports that 1 in 6 malicious files evade sandboxing and 1 in 8 evade antivirus. CDR makes no such assumption. It treats every file as untrusted and rebuilds allowed content to a known-good standard before the file crosses an email, web, upload or transfer boundary, so detection and CDR work together rather than in place of each other.

What file types does Glasswall CDR support?

Glasswall publishes support for a broad range of formats, including PDF, Microsoft Word, Excel and PowerPoint, ZIP and other archives, and common image and media formats such as JPEG, PNG, GIF, TIFF, SVG, MP4 and WAV. More than 140 file extensions are covered; the file support section above has the current list.

What deployment models are available?

Three. Halo is the cloud-native API, with a Glasswall-published benchmark of 186,000 files per hour at 815ms median latency. Meteor runs on-premises, air-gapped, and against local or cloud storage. Genesis is the CDR engine itself, a self-contained command-line binary embedded in applications and pipelines as a process. All three deliver the same deterministic CDR standard.

Do you support air-gapped and sovereign deployments?

Yes. Glasswall CDR runs fully offline with no callback to Glasswall or Safeware infrastructure. Diagnostics are exchanged as exportable log bundles over your approved transfer process, which suits classified, sovereign and critical-infrastructure environments.

How is Glasswall CDR priced?

By quotation rather than a published list. The figure follows your seat count, monthly file volume, deployment model and the capabilities in scope, which are all listed on the Capabilities page. Tell us your scope through the contact form below and we return a quote.

Can Glasswall CDR be purchased through cloud marketplaces?

Yes. It can be procured through AWS Marketplace and Azure Marketplace where that suits your purchasing rules, or bought direct. Safeware handles the listing and contracting across APAC.

Who delivers and supports Glasswall CDR in APAC?

Safeware, the independent Glasswall representative for Asia-Pacific, based in Singapore. We cover architecture, deployment, integration and ongoing support across the region, including joint case ownership with your systems integrator or MSSP and vendor-level escalation into Glasswall.

Still have questions? Talk to us

Contact

Talk to us about Zero Trust file security

A tailored walkthrough of Glasswall CDR against your own files takes 25 minutes. Our full site is being finalised; in the meantime, reach us directly.

sales@safeware.ai

Your details go directly to our own mailbox and nowhere else: no marketing lists, no third-party form services. We use them only to respond to your enquiry.