Explore
What is CDRZero TrustThe detection gapCapabilitiesUse casesProducts
ProductsIntegrationFile supportCompliance
Compliance hubMore
Trust & certificationsAboutDocumentation Book a demoFramework alignment
Maps to SI-3 (malicious code protection), SC-7 (boundary protection), AC-4 (information flow enforcement) and AU-2/AU-12 (audit events and logging). Glasswall CDR rebuilds every file crossing the boundary; the per-file verdict record is the audit evidence the AU family asks for. Under the NIST CSF, this supports the PR.DS and PR.PT categories.
CDR strips and rebuilds active content before files reach the desktop or a classified domain. That reinforces two Essential Eight strategies, user application hardening and configuring Microsoft Office macro settings, and supports the ISM content-validation and content-conversion controls. Macro analysis (Powered by Safeware) inspects embedded macros and active content; Glasswall CDR enforces the rebuild. We document where this sits relative to PROTECTED-aligned environments, without claiming an IRAP assessment we have not completed.
For Singapore financial institutions, CDR aligns with the MAS TRM guidance on system security and network perimeter defence: untrusted files are rebuilt at the boundary rather than admitted on a detection verdict. Find & Redact removes named data patterns before files are stored or shared, supporting the PDPA Protection Obligation. Every verdict is logged for audit.
For operators in Singapore's Critical Information Infrastructure regime, CDR supports the malware-protection and secure-configuration domains of the CSA marks and the file-handling expectations of the sectoral Codes of Practice (CCoP): inbound files are rebuilt to a known-good standard before they reach an operational network. Safeware maps the relevant clauses to the deployment in scope.
Safeware prepares the deployment evidence an assessor expects: architecture diagrams, trust-boundary mapping, operational procedures, the support model, exportable telemetry, and a documented control-responsibility matrix, what Glasswall enforces, what Safeware operates, and what the customer retains. IRAP is an assessment process, not a certification; the architecture is built to be assessable.
Cross-domain transfer
Cross-domain and Raise-the-Bar (RTB) transfers carry the strictest file-handling requirements: content must be transformed to a known-good state, not merely scanned, before it crosses from a lower to a higher classification. Glasswall CDR rebuilds each file to the published specification at the transfer point, producing a deterministic, repeatable transformation an assessor can reason about. Glasswall reports 100% of malicious files neutralised across 8.27 million tested, no signature, sandbox detonation or verdict delay in the path. Safeware documents how the rebuild sits within a cross-domain or RTB pattern for the deployment in scope; it does not assert RTB accreditation that Glasswall or Safeware does not hold.
Technical controls by Glasswall; regional deployment and operations by Safeware.
Transfer point
Per-file verdict record retained as assessment evidence.
Assurance pack
Safeware delivers the assurance pack your security review and procurement teams will request, boundary map, policy map, telemetry specification and cutover runbooks, at architecture review, not after go-live.
By territory
How each APAC territory regulates file security and audit, and where Glasswall CDR evidences the control.
Trusted where it matters
Glasswall technology protects government, defence and intelligence communities worldwide. Across Asia-Pacific, Safeware delivers it to government, defence, financial services and critical-infrastructure organisations.