Safeware Glasswall APAC Partner
Book a demo

Glasswall Halo capabilities

Every capability, and who publishes it

Glasswall publishes the CDR engine and its core capabilities. ReversingLabs file reputation comes built into Glasswall Halo. Capabilities marked Safeware are ours, built for Glasswall Halo. Safeware delivers, integrates and supports Glasswall across Asia-Pacific.

Rebuild files, don't just scan them

The foundation: files are rebuilt to their format's specification, including files that are encrypted or packed inside large archives.

Glasswall

Content disarm and reconstruction

Stop file-borne threats by rebuilding files instead of trying to detect them.

Scanners only catch threats they recognise. Content disarm and reconstruction (CDR) works differently. Glasswall Halo checks each file against its format's specification and builds a new, fully usable file that matches it. Nothing has to be recognised first.

  • New threats handled like old onesKnown, unknown and AI-generated threats are treated the same way, because the rebuild never depends on a signature.
  • 140+ file extensionsDocuments, email and its attachments, images, CAD, audio, video and more.
  • You set the rulesFor each file type, choose whether macros, embedded files and links are kept, removed, or cause the file to be blocked.
  • A report on every fileEach rebuild can return a report of what was found and what was removed, for your audit trail.
  • Runs where you doOn-premises, in your own cloud, or fully air-gapped with no internet connection.
Connects via
Glasswall Halo

Glasswall

Data loss prevention

Catch sensitive terms in documents before they leave, as they are rebuilt.

Sensitive terms can leave your organisation inside an ordinary document. Glasswall Halo checks documents against the words and patterns in your policy as it rebuilds them. Each match is reported, blocked or redacted. It covers Microsoft Office documents and plain text.

  • Your words, your patternsList exact words, or describe patterns such as reference numbers with regular expressions.
  • Choose what happensReport the match only, block the file, redact the match, or release a plain-text file only if a required term is present.
  • Redaction in Office documentsRedaction replaces each match with a character you choose. It works in Microsoft Office documents.
  • One policyTerms and actions sit in the same Halo policy as your other rebuild settings.
Connects via
Glasswall Halo

Glasswall

Transform to XML

Make files simple enough for hardware at a secure boundary to check.

Some secure networks check incoming data in hardware, such as a data diode. Complex files are too hard to check that way. Glasswall rewrites each file as simple XML that can be checked against a schema, then returns it to its original format.

  • Simple enough to checkComplex formats such as PDF and Word become plain XML that describes the file's structure. Images become standard bitmaps.
  • Checked at the boundaryA data diode, a specialised chip (FPGA) or a software validator checks the XML against its schema. Only files that pass go on.
  • Usable on the other sideOn the secure side, the XML is turned back into the original format and checked again before delivery.
  • Built for cross-domain transferGlasswall states this lets cross-domain partners fully meet the Pattern for Safely Importing Data from the UK National Cyber Security Centre (NCSC).
Connects via
Glasswall Halo and Embedded Engine (SDK)

Safeware

Password-protected files

Rebuild password-protected files too, instead of blocking them or letting them through unchecked.

Encrypted files cannot be read, so Glasswall Halo cannot rebuild them. They are held until the recipient signs in and types the password once. Sign-in uses Microsoft 365 or any OpenID Connect (OIDC) identity provider. Covers encrypted PDF, DOCX, XLSX, PPTX, ZIP, 7z and RAR.

  • The password is never keptIt is used once to open the file, then discarded. It is never logged or written to disk.
  • Links that work onceEach release link works only once. A second click is refused.
  • Where these files arriveOutlook mailboxes, the email relay, web downloads, uploads to the Halo portal, and SharePoint and OneDrive.
  • A record of every releaseThe audit record shows which signed-in account released each file.
Connects via
Email, web downloads, the Halo portal and Microsoft 365

Safeware

Large archive processing

Large ZIP archives and ISO disc images, opened up and rebuilt file by file.

Big archives and disc images can be too large or too deeply nested to check in one go. This opens ZIP and ISO files, including archives inside them, and Glasswall Halo rebuilds each file. Anything it cannot rebuild is blocked and replaced with a placeholder.

  • Archives within archivesOpens nested archives to a depth you set, so nothing hides in the innermost layer.
  • Put back togetherThe archive or disc image is rebuilt in its original format, with the rebuilt files inside.
  • Protection against archive bombsLimits on size, file count and compression stop archives built to overwhelm the system.
  • A tamper-evident recordA manifest records what happened to every file, in a form that shows if it has been altered.
  • Upload or hand overUpload through the Halo portal, or hand archives over from a kiosk or another system.
Connects via
Halo portal and API

Check before and alongside the rebuild

Second opinions where the rebuild needs help: new threats, programs, macros you keep, signed installers, and text bound for AI models.

Glasswall

AI-powered threat prediction

Get an early warning about risky files, even threats no signature has seen.

Some threats are too new for any scanner to know. Glasswall Halo uses machine learning to score each file's risk from its internal structure. It needs no signatures, sandbox or internet connection. It covers PDF, DOCX and XLSX files.

  • Reads structure, not signaturesThe score comes from how the file is built, so a threat nobody has seen before can still score high.
  • Leaves the file aloneIt adds a risk score without changing the file.
  • Works offlineNeeds no internet connection, so it suits air-gapped and disconnected sites.
  • PDF, Word and ExcelCoverage today is PDF documents, Word documents (DOCX) and Excel workbooks (XLSX).
Connects via
Glasswall Halo

Glasswall

Prompt injection detection

Spot prompt injection in text before your application sends it to an AI model.

Text sent to a large language model (LLM) can carry planted instructions that change what it does. Glasswall Halo checks the text first and returns one of three verdicts. English only, up to 512 tokens per request, with a separate Pulsar licence.

  • Three clear verdictsNo Threat Detected, Suspicious or Malicious, so your application can decide whether to send the text on.
  • Text, not filesIt checks the text your application is about to send to the model. It does not check files.
  • Know the limitsEnglish only in this first release. Up to 512 tokens per request, the units AI models count text in. Longer text is rejected.
  • Runs in your own HaloRuns inside your Glasswall Halo deployment and is called through one web API request. It needs a separate Pulsar licence.
Connects via
Glasswall Halo REST API

ReversingLabs

File reputation

Check each file against ReversingLabs threat intelligence, including files Halo cannot rebuild.

Some files, such as programs, are outside what Glasswall Halo can rebuild. File reputation, built into Halo, looks up each file's fingerprint with ReversingLabs in real time and returns a verdict. It needs your ReversingLabs account and a live internet connection.

  • A clear verdictEach file comes back UNKNOWN, KNOWN, SUSPICIOUS or MALICIOUS, with a threat name and a threat level.
  • Covers what the rebuild cannotYour policy can act on programs and other file types that Glasswall Halo does not rebuild.
  • Results where you already lookVerdicts appear in Halo's response and its analysis report, so existing integrations can read them.
  • Needs a connectionEvery lookup goes to ReversingLabs over the internet. Fully air-gapped sites run without it, and the rebuild never depends on it.
Connects via
Glasswall Halo, with a live ReversingLabs connection

Safeware

Multi-AV scanning

Pass a file only when every anti-virus engine says it is clean.

One anti-virus engine can miss what another catches. Choose a curated pack of engines from different vendors, or bring the scanners you already run. Each file goes to every engine at once and passes only when all report it clean.

  • Every engine must agreeEngines scan in parallel. A file passes only when each one reports it clean, and each verdict is recorded separately.
  • Engines from across the marketCurated packs combine engines from different vendors, so one engine's blind spot is covered by another.
  • Or bring your ownConnect any scanner you already run that supports ICAP (Internet Content Adaptation Protocol).
  • Out-of-date engines are not trustedAn engine with old or unknown signature updates is refused by default: a warning at 7 days, a refusal at 30.
  • Updates for air-gapped sitesSignature updates arrive as signed bundles, checked in full before anything in them is trusted.
Connects via
Curated AV engine packs, or bring your own

Safeware

Macro analysis

Know what a macro would do before anyone enables it, without running it.

Some organisations must keep trusted macros in their documents, so they cannot simply remove them. Macro analysis examines the macros your Glasswall Halo policy keeps and gives a verdict with its reasons. Documents are never opened in Office, and the macros are never actually run.

  • Four verdictsBlock, Flag, Allow or Clean, each with the findings that led to it.
  • The formats that carry codeWord and Excel macros, including older Excel 4.0 macros, older Office files, PDF scripts and HTML scripts.
  • Behaviour, safely simulatedA simulator traces what the macro would do and draws it as a diagram. No real program, network or file is touched.
  • Findings your SOC can useFindings are tagged with MITRE ATT&CK, the common catalogue of attacker techniques.
  • Indicators to investigateWeb addresses, IP addresses, file paths and decoded hidden text are pulled out for your threat-intelligence team.
Connects via
Glasswall Halo, alongside the rebuild

Safeware

Signed software verification

Let genuine signed installers through unchanged, and block anything that fails the checks.

Signed installers are trusted because of who signed them, not rebuilt. This checks the publisher's digital signature and approved lists of file fingerprints. Any deny blocks the file. A fingerprint on no list counts as unknown, never as approved. Every decision is recorded.

  • Checks the publisher's signatureVerifies Microsoft Authenticode signatures on Windows programs and packages (EXE, DLL, MSI, CAB, MSU, APPX, MSIX). It can also require the one publisher you expect.
  • Approved fingerprint listsLists of approved file fingerprints load only if their own signature, certificate and cryptography pass the checks.
  • Any deny winsA deny on any list blocks the file. A file on no list is unknown, never approved.
  • Exceptions with a name attachedYour own additions to the approved list need a recorded approval naming the approver, kept in a tamper-evident log.
Connects via
Part of the Halo file checks

Bring your channels to the same engine

Email, web gateways, Microsoft 365, removable media and your own applications all send files to the same Glasswall Halo, under one policy.

Glasswall

Integration APIs

Add file rebuilding to your own applications, portals and gateways.

Your own systems can send files to Glasswall Halo directly. Halo offers web APIs that return a result at once or later, and an ICAP service for web gateways. A rebuild request can return the rebuilt file, a report on it, or both.

  • Now or laterWait for the rebuilt file, or submit the work and collect the result later.
  • Web gatewaysSecure web gateways can send downloads and uploads to Halo over ICAP (Internet Content Adaptation Protocol).
  • Policy you can scriptChange rebuild policies through the API, or name the policy to use on each request.
  • XML checked against your schemaCheck XML files against your XML schema before they move on.
Connects via
Web APIs and ICAP

Glasswall

Web gateway integration

Rebuild web downloads and uploads through the gateway or proxy you already run.

Many secure web gateways and proxies can hand files to another service using ICAP (Internet Content Adaptation Protocol). Glasswall Halo includes an ICAP server, so those files are rebuilt before users get them. You start, stop and configure it from the Halo portal.

  • Downloads and uploadsGateways can send the files users download and the files they upload. ICAP profiles let each use its own policy.
  • Run from the portalStart, stop and configure the server in the Halo portal. Stopping it keeps your settings. It needs ICAP on your Halo licence.
  • Mutual TLS availableTurn on mutual TLS so that only gateways with a trusted certificate can connect.
  • What passes unchangedFile types your Halo policy does not rebuild are passed back unchanged, not blocked.
Connects via
ICAP, from your gateway or proxy

Glasswall

Microsoft 365 storage protection

Rebuild files as they are uploaded to SharePoint, OneDrive and Teams.

A malicious file shared in Microsoft 365 can reach everyone who opens it. Glasswall Halo watches SharePoint and OneDrive, which also hold Teams files. Each new upload is rebuilt, and the rebuilt version replaces it in place. The original stays in version history.

  • Works in the backgroundPeople keep working in SharePoint and OneDrive as normal. Files are rebuilt after each upload.
  • Teams includedFiles shared in Teams are stored in SharePoint and OneDrive, so they are covered too.
  • Connects through Microsoft GraphUses the Microsoft Graph API, registered as an application in Microsoft Entra, your Microsoft 365 directory.
  • The original is keptSharePoint and OneDrive keep the original upload in version history, beside the rebuilt file.
Connects via
Microsoft Graph (SharePoint, OneDrive, Teams)

Safeware

Email relay

Rebuild incoming and outgoing email, not just its attachments.

Email is a common way in for malware. The email relay sits in your mail flow, beside Exchange or Microsoft 365. Glasswall Halo rebuilds the whole message, incoming and outgoing. Your policy decides what happens to anything that cannot be rebuilt.

  • The whole messageThe message itself, its attachments, calendar invites (iCal) and the HTML body with its styling (CSS) are all rebuilt.
  • You decide the outcomeReplace with the rebuilt file, swap in a notice, warn, quarantine or block. A warning passes the original through unchanged.
  • Password-protected attachmentsHeld in quarantine, with a one-time link for the recipient to release a rebuilt copy.
  • Encrypted in transitConnections in and out must be encrypted, using TLS 1.2 or 1.3.
  • Mail stays on your networkAll processing, including the rebuild, happens inside your network.
Connects via
Your mail flow (SMTP), in and out

Safeware

Web gateway bridge

For web gateways that cannot send downloads over ICAP: a bridge to Halo.

Some web gateways and proxies cannot pass downloads to another service for checking. This bridge becomes the next stop for their web traffic. It sends the files to Glasswall Halo's ICAP server to be rebuilt. If Halo cannot be reached, files are blocked.

  • Blocks when Halo is downIf Halo is unreachable, downloads and uploads are blocked. Production settings refuse to switch this off without a recorded exception.
  • Uploads too, if you chooseTurn on upload checks to rebuild files users send out, under the same policy or a stricter one.
  • What passes unchangedOrdinary web pages, and file types Halo is not set to rebuild, pass through unchanged.
  • Different rules for different teamsSend different parts of your network to different Halo policies.
  • Fits how you deployRun it as its own appliance, on the Halo server, or in your own Kubernetes cluster.
Connects via
Behind your existing web gateway

Safeware

Zero Trust Kiosk

Check USB sticks and other media at the door, before files reach your network.

Contractors and vendors bring USB sticks, SD cards and discs into industrial and critical-infrastructure sites. At the kiosk, files go through Glasswall Halo and your other checks. The engineer then collects the files that passed, rebuilt or verified.

  • The media people bringUSB sticks, SD cards, CDs and DVDs. Encrypted drives (Linux LUKS and Windows BitLocker To Go) are unlocked at the kiosk.
  • One set of rules everywhereFiles go through the same checks as your other channels, so one policy and one record cover them all.
  • Installers still installSigned installation media is verified and passed unchanged, or blocked.
  • Four simple stepsLog in, insert the media, wait while files are checked, collect the results. One decision per screen.
  • Works alone or as a fleetOne kiosk can run Halo by itself with no network connection, or many kiosks can share a central Halo on your network.
Connects via
USB sticks, SD cards and discs

Manage and monitor

Settings and reports for each capability in the Halo portal, and monitoring in the tools you already use.

Safeware

Portal reporting and settings

Manage and report on every Safeware capability inside the Glasswall Halo portal.

Operators should not need a separate console for each add-on. These panels put settings, reports and service status for each installed Safeware capability into the Glasswall Halo portal, without changing Halo's code. They can be re-applied safely after every Halo upgrade.

  • Settings in one placeEach installed capability's settings and reports sit beside Halo's own, in the same style.
  • Reports where you lookReports for encrypted files, large archives, anti-virus and web traffic, plus macro verdicts in Halo's own file view.
  • Service healthSee at a glance whether each Safeware capability is running.
  • Docs for your developersInteractive API documentation for each installed capability, ready for your developers to build against.
Connects via
Glasswall Halo portal

Safeware

Monitoring and SIEM integration

See Glasswall Halo's activity in the dashboards and SIEM you already use.

Each service in a Halo deployment writes logs in its own shape. Managed telemetry gathers them in one place and gives them one format. It removes passwords and other secrets, then sends them to Grafana or your SIEM.

  • One collector, many toolsEach tool connects to the same collector, so nothing has to be set up twice.
  • One format everywhereEvery record carries the same labels, so dashboards and alert rules keep working if you change tools.
  • Secrets removed firstPasswords, tokens, keys and connection strings are stripped before anything leaves your environment.
  • Supported toolsGrafana, Splunk, Microsoft Sentinel, Datadog, IBM QRadar, or any tool that accepts OpenTelemetry (OTLP).
  • Fits your setupRuns on the Halo cluster, on a separate cluster, or on its own server.
Connects via
OpenTelemetry (OTLP)