Q3-board-pack.pdf
Rebuilt
Two non-conforming structures found and repaired against the PDF specification.
Glasswall HaloServer
Glasswall MeteorDesktop
Compliance by territory
What is CDR?
Detection misses what it has never seen. Content Disarm and Reconstruction takes a Zero Trust, prevention-first approach: rather than trying to spot malware, it removes active content and rebuilds every file into a safe, usable version before it reaches a user, neutralising file-based malware and ransomware without needing to predict attacker behaviour. CDR is the deterministic core of Glasswall's file security engine, delivered and supported by Safeware across APAC.
The evidence
100%
of malicious files neutralised across 8.27M tested (Glasswall)
42%
of ransomware began with a malicious file or link (Glasswall)
1 in 6
malicious files evade sandboxing: 1 in 8 for antivirus (Glasswall)
The Problem
Glasswall reports that 42% of ransomware incidents began with a malicious file or link, and one in three data breaches begins with a malicious file. Regulated APAC organisations, banks under MAS oversight, government agencies, hospitals handling patient data, need a preventive control at the file boundary, not only detection after the fact.
Antivirus, sandboxing, and EDR all share one assumption: that a threat can be recognised. They detect known and observable threats, but they cannot vouch for an unknown file before it crosses a trust boundary. Glasswall CDR can. It validates the file against its format specification, removes anything non-conformant, macros, scripts, embedded objects, and rebuilds a clean copy that still opens and works.
How CDR Works
Parse the file against its format specification, mapping every element, embedded object, and piece of active content.
Remove macros, embedded scripts, OLE objects, and any structure that does not conform to the file specification.
Reconstruct the file from conformant elements to a known-good template. The rebuilt document keeps its content and formatting; active code is removed unless policy explicitly allows it.
Return the rebuilt file to the original workflow, email, portal, repository, with a Glasswall remediation report recording each item removed and the policy applied.
Glasswall's patented four-step CDR runs the same way every time: same input, same policy, same output. The file is never executed, so there is nothing to evade. Each file produces a per-file remediation record, what was removed and against which policy, that audit and SOC teams can retain as evidence.
Worked examples
Three files through the same policy, and the record each one leaves behind.
Rebuilt
Two non-conforming structures found and repaired against the PDF specification.
Macros removed by policy
The workbook arrives intact; the macro project does not survive the rebuild.
Two broken structures repaired
Malformed structures corrected, so the document opens cleanly downstream.
For technical specifications, the full supported-file-type list, and API references, visit Glasswall directly: product documentation.
Book a Demo
Safeware delivers and supports Glasswall CDR across APAC: architecture, deployment, integration and ongoing support. Book a demo to see CDR applied to your own email, upload and transfer workflows.