42%
of ransomware incidents began with malicious files or links
(Source: Comparitech ransomware statistics 2025)
Glasswall HaloServer
Glasswall MeteorDesktop
Compliance by territory
You're in good company



























What is CDR
CDR removes file-borne threats without trying to detect them. Instead of scanning for known-bad, the file is taken apart and a safe copy is built. How much of the original survives is what separates vendors.
Glasswall CDR never passes the original file at all.
Zero-Trust and intelligent file protection
Glasswall CDR removes active content and rebuilds files into safe, usable versions. The result:
Trust nothing, verify by rebuilding: every file, on every channel, before it reaches a user or a system.
42%
of ransomware incidents began with malicious files or links
(Source: Comparitech ransomware statistics 2025)
Zero-day and AI-generated threats are increasingly used to deliver malware through files
(Source: OpenText Cybersecurity Threat Report 2025)
Glasswall CDR is a part of Oracle Cloud Infrastructure's (OCI) approach to implementing a Zero Trust protection principle.

Beazley's security is paramount, and this integration has significantly reinforced our cybersecurity framework.

Close the detection gap
Glasswall CDR eliminates file-borne risk without relying on threat identification. Objective testing across 8.27 million malicious files demonstrates why prevention is essential.
Waits for execution
Threats must reveal themselves before action can be taken.
Looks for known indicators
Detection depends on identifying malicious behaviour or signatures.
Removes the threat surface
Files are reconstructed into safe, usable versions before delivery.
Glasswall Halo capabilities
Rebuilding files is the foundation. Around it, these capabilities predict new threats, catch sensitive terms before they leave, spot prompt injection before text reaches an AI model, and pass a file only when every anti-virus engine agrees.
Stop file-borne threats by rebuilding files instead of trying to detect them. Glasswall Halo checks each file against its format's specification and builds a new, fully usable file, so nothing has to be recognised first.
Get an early warning about risky files, even threats no signature has seen. Glasswall Halo scores each file's risk from its internal structure, with no signatures, sandbox or internet connection. It covers PDF, DOCX and XLSX.

Catch sensitive terms in documents before they leave, as they are rebuilt. Each match is reported, blocked or redacted. It covers Microsoft Office documents and plain text.
Spot prompt injection in text before your application sends it to an AI model. Returns one of three verdicts. English only, up to 512 tokens per request, with a separate Pulsar licence.
Pass a file only when every anti-virus engine says it is clean. Choose a curated pack of engines from different vendors, or bring the scanners you already run.
Every capability
Checks before the rebuild, the channels files arrive by, and the records you need afterwards.

Use cases
Every file is validated against its specification and rebuilt to a known-good standard in under a second, with active content and structural anomalies removed by construction. No signatures, no detonation, no waiting. The first control on upload portals, gateways, Microsoft 365, and transfer paths.
Glasswall HaloCDR
Files are rebuilt as they are uploaded to SharePoint, OneDrive, and Teams by Microsoft 365 storage protection. Staff open and share documents in the same libraries, with no change to how they work.
Glasswall HaloMicrosoft 365 storage protectionIntegration APIs
Email is a common way in for malware. The email relay sits in your mail flow beside Exchange or Microsoft 365 and rebuilds the whole message, incoming and outgoing: the message itself, attachments, calendar invites and the HTML body with its styling.
Glasswall HaloEmail relay
Citizens, customers, and third parties upload files straight into your case-management and claims systems. Every file is rebuilt before it lands, so case and records systems never touch file-borne malware.
Encrypted files cannot be read, so they cannot be rebuilt and are held instead. The recipient signs in with Microsoft 365 or any OpenID Connect (OIDC) identity provider, types the password once, and receives a rebuilt copy. Each release link works only once.
Glasswall HaloPassword-protected files
Seized media, disclosure bundles and third-party productions are rebuilt before they enter evidence stores and review platforms, so investigators open every exhibit safely and case systems stay clean.
Glasswall GenesisData loss prevention
Move files across classification boundaries, mission enclaves, and disconnected networks. Each file is rebuilt to a known-good standard at the boundary, with the same outcome every time, so nothing untrusted crosses on the strength of a detection verdict.
Glasswall GenesisCase study: petabyte cross-domainCase study: RTB-compliant lab
Files arriving on USB drives, discs and unmanaged laptops are rebuilt at a kiosk or transfer station before they cross into the trusted network. Standard practice for plant floors, vessels, field sites and visitor media.
Glasswall HaloZero Trust KioskCDR
Contractors and vendors bring USB sticks, SD cards and discs onto plant and critical-infrastructure sites. At the kiosk, every file goes through Glasswall Halo and your other checks, and the engineer collects what passed. One kiosk can work alone, with no network connection.
Glasswall HaloZero Trust Kiosk
Glasswall Genesis runs as a self-contained binary at the tactical edge: rebuild files in disconnected, degraded, intermittent or low-bandwidth environments, with no cloud dependency and nothing to install but one file.
Glasswall GenesisDDIL
Vendor updates, configuration files and engineering documents are rebuilt before they reach OT and ICS environments, whether they arrive over a diode, through a transfer zone or on removable media.
Glasswall GenesisGlasswall Meteor
Vendor patches and installers for OT and critical systems are trusted because of who signed them, not rebuilt. The publisher's signature and your approved file lists are checked, any deny blocks the file, and a file on no list is unknown, never approved.
Glasswall HaloSigned software verification
Engineering bundles and disc images can be too large or too deeply nested to check in one go. Nested ZIP and ISO files are opened, every file inside is rebuilt, and the container is rebuilt with a tamper-evident manifest of what happened to each file.
Glasswall HaloLarge archive processing
Files from suppliers, contractors and managed providers arrive with implicit trust they have not earned. Rebuild every inbound document, archive and installer to a known-good standard before it enters your environment, whichever channel it arrives on.
Some web gateways and proxies cannot pass downloads to another service for checking. A bridge becomes their next stop and sends the files to Glasswall Halo's ICAP server to be rebuilt. If Halo cannot be reached, files are blocked, not passed.
Glasswall HaloWeb gateway bridge
After a breach, a merger, a cloud migration, or an audit finding, you inherit years of files no scanner ever cleared. Run Glasswall CDR as a scheduled job across your storage: every document, spreadsheet, and archive is rebuilt under the same policy as live traffic, from a single share up to multi-terabyte repositories.
Glasswall HaloCDR
After a compromise, nothing in the estate is trusted. Rebuild mailboxes, shares and repositories before they return to service, so recovery does not reinfect the environment: verified-clean files, with per-file evidence for the incident report.
Glasswall HaloCase study: research-centre breach
AI-powered threat prediction scores file risk from structure, not signatures, and runs on your own infrastructure, so no files leave your network. Glasswall reports a 0.015% false-positive rate for PDFs, giving analysts a triage signal they can act on.
Glasswall HaloAI-powered threat prediction
One anti-virus engine can miss what another catches. Send each file to engines from different vendors at once, alongside CDR, and release it only when every one reports it clean. Signed signature bundles keep air-gapped sites current.
Glasswall HaloMulti-AV scanning
AI writes new malware variants faster than signatures can chase them. CDR does not chase: every file is rebuilt to its known-good specification, so polymorphic and machine-generated threats are removed by construction, and AI-powered threat prediction flags high-risk files before any detection exists.
Some teams cannot simply strip macros from the workbooks and templates they depend on. Each macro your policy keeps is analysed without being run, and the file is blocked, flagged, allowed or cleaned, with the findings behind the verdict.
Glasswall HaloMacro analysis
Documents feeding copilots, RAG indexes and model training are an attack path: hidden payloads, macros and embedded objects ride in on files. Rebuild every document to a clean, predictable form before your AI platform ingests it.
Integration APIsGlasswall Genesis
Text from people you do not control can carry planted instructions. Check each prompt before your application sends it to a copilot or chatbot model, and get one of three verdicts. English only, up to 512 tokens per request, with a separate Pulsar licence.
Glasswall HaloPrompt injection detection
Data hidden inside images and documents defeats inspection because there is nothing to detect. Rebuilding every image and file to a clean form destroys steganographic payloads in both directions: malware smuggled in, and sensitive data smuggled out.
CDRGlasswall Halo
Quishing campaigns hide malicious links inside QR codes in attachments, where link scanners cannot follow them. Glasswall detects QR codes in documents and removes or flags them under policy before the file is delivered.
CDRGlasswall Halo
Cloud and managed service providers embed Glasswall CDR into their own platforms, offering clean-file processing as a service to every tenant. Genesis ships as one self-contained binary, built for OEM integration into products, pipelines and customer offerings.
Glasswall GenesisOEM
Export processing volumes, policy outcomes, and rebuild rates as the reports your audit and assurance teams ask for: evidence that the control ran, and what it did, on every file.
Glasswall HaloCompliance evidence
Halo's logs, traces and metrics reach the SIEM and dashboards your SOC already uses, in one format, with passwords and other secrets removed first. Grafana, Splunk, Microsoft Sentinel, Datadog and IBM QRadar are supported, or any tool that accepts OpenTelemetry (OTLP).
Glasswall HaloMonitoring and SIEM integration
Products
CDR Tool
One self-contained binary for adding directly into your own products and workflows. Built for OEMs, CI/CD, tactical edge, cross-domain and air-gapped deployments.
Server
Scalable deployment with policy management, dashboards, authentication, REST and ICAP interfaces, plus Microsoft 365 and cloud storage integrations.
Desktop
Desktop file protection for Windows. Drag in a file, receive a safe version back. Ideal for post-breach remediation and tactical edge environments.
Integration
One engine, reachable from every file path: no rip-and-replace, and the same policy and audit trail on each channel.

Embed CDR into your own applications and pipelines through Halo's Integration APIs, the Genesis engine as a process, or the Embedded Engine SDK in-process.

Rebuild downloads and uploads through the secure web gateway or proxy you already run. Halo includes its own ICAP server.

For gateways that cannot send downloads over ICAP. A bridge in front of Halo's ICAP server that blocks files if Halo cannot be reached.

Files are rebuilt as they are uploaded to SharePoint, OneDrive and Teams, and the rebuilt version replaces the original in place.

Check USB sticks, SD cards and discs at the gate of OT and air-gapped sites, before files reach your network.

Rebuilds incoming and outgoing email, including the message itself, attachments, calendar invites and the HTML body, entirely inside your own network.

Sanitise legacy repositories as they move, so nothing dormant travels into the new environment.
Denied, disrupted, intermittent and limited-bandwidth settings: the engine runs where there is no connectivity at all.

Citizen, KYC and partner file intake sanitised at ingress, including cross-domain transfer paths.
File support
The Genesis engine's coverage, shared by every deployment.
PDF · OOXML · Legacy Office · ODF · RTF
PE · ELF · Mach-O · LNK
EML · MSG · Nested attachment processing
NITF, including MIL-STD-2500C and TRE analysis · SIDD · GPX · KML · GeoJSON · SHP · DWG · DXF · STEP AP242
H.264 · H.265 · MPEG-2 · MP4 · MP3 · WAV
JSON · CSV · SVG · HTML · CSS
JPEG · PNG · TIFF · GIF · BMP · HEIF · JPEG 2000 · WebP · WSQ · DICOM
ZIP · 7Z · RAR · TAR · GZ · BZ2 · XZ · ISO
CMYK-accurate images. Embedded fonts intact. Coordinates untouched. A rebuilt file nobody has to ask about.
Trusted where it matters
Glasswall technology protects government, defence and intelligence communities worldwide. Across Asia-Pacific, Safeware delivers it to government, defence, financial services and critical-infrastructure organisations.
Who we are
We contract, deploy and support Glasswall technology across APAC for government, defence, financial services and critical infrastructure: on your infrastructure, in your jurisdiction, including air-gapped environments. Engine-level issues escalate directly into Glasswall engineering; everything else is handled in-region.
Contract in-region with a Singapore-based partner rather than a remote vendor.
Architecture, installation, policy tuning and production support, with vendor-level escalation into Glasswall.
On-premises and air-gapped delivery for environments where data cannot leave.
FAQ
The questions APAC buyers ask most, about the technology, deployment, pricing and support. Ask us anything else through the form below.
CDR is a zero trust file security technique. Rather than trying to detect malware, Glasswall CDR validates each file against its format specification, removes active content such as macros, scripts and embedded objects by policy, and rebuilds a clean copy that still opens and works. In Glasswall's published testing, 100% of malicious files were neutralised across 8.27 million files tested.
Antivirus, sandboxing and EDR all share one assumption: that a threat can be recognised. Glasswall reports that 1 in 6 malicious files evade sandboxing and 1 in 8 evade antivirus. CDR makes no such assumption. It treats every file as untrusted and rebuilds allowed content to a known-good standard before the file crosses an email, web, upload or transfer boundary, so detection and CDR work together rather than in place of each other.
Glasswall publishes support for a broad range of formats, including PDF, Microsoft Word, Excel and PowerPoint, ZIP and other archives, and common image and media formats such as JPEG, PNG, GIF, TIFF, SVG, MP4 and WAV. More than 140 file extensions are covered; the file support section above has the current list.
Three. Halo is the cloud-native API, with a Glasswall-published benchmark of 186,000 files per hour at 815ms median latency. Meteor runs on-premises, air-gapped, and against local or cloud storage. Genesis is the CDR engine itself, a self-contained command-line binary embedded in applications and pipelines as a process. All three deliver the same deterministic CDR standard.
Yes. Glasswall CDR runs fully offline with no callback to Glasswall or Safeware infrastructure. Diagnostics are exchanged as exportable log bundles over your approved transfer process, which suits classified, sovereign and critical-infrastructure environments.
By quotation rather than a published list. The figure follows your seat count, monthly file volume, deployment model and the capabilities in scope, which are all listed on the Capabilities page. Tell us your scope through the contact form below and we return a quote.
Yes. It can be procured through AWS Marketplace and Azure Marketplace where that suits your purchasing rules, or bought direct. Safeware handles the listing and contracting across APAC.
Safeware, the independent Glasswall representative for Asia-Pacific, based in Singapore. We cover architecture, deployment, integration and ongoing support across the region, including joint case ownership with your systems integrator or MSSP and vendor-level escalation into Glasswall.
Contact
A tailored walkthrough of Glasswall CDR against your own files takes 25 minutes. Our full site is being finalised; in the meantime, reach us directly.