Glasswall genesis blog main cover
Jake Bussell & Riyya Ahmed
August 17, 2026

Zero Trust file protection beyond everyday formats: meet Glasswall Genesis

Today, we're launching Glasswall Genesis, our new Zero Trust file protection solution, rebuilt from the ground up to protect a much broader range of the files that government, defense and enterprise organizations depend on every day.

Genesis succeeds Glasswall's existing Embedded Engine and represents a significant step forward in the breadth, performance and control we can offer customers and partners. It processes 45+ formats and 140+ file extensions, from everyday documents, email and images to specialist file types used in defense, intelligence, engineering and healthcare. It also introduces a more granular policy model, deeper auditability and more flexible deployment across Windows, Linux and macOS on both x86-64 and Arm64.

The new architecture delivers a substantial performance improvement too, with up to 2x faster file processing than Glasswall's previous solution. Genesis can run as a self-contained binary, in a container, within Glasswall’s Halo and Meteor products or added into other services.

Genesis is built around a simple Zero Trust principle: trust shouldn’t come from a verdict on the file; it should come from controlling what is allowed to exist inside it. 

Assume nothing. Rebuild everything.

The problem: a clean verdict isn't proof

Traditional security tools are designed to determine whether a file looks malicious. Antivirus products compare it against known signatures, sandboxes and EDR observe behaviors that suggest something may be wrong. These are valuable layers of security, but the answer they provide is still a verdict at a particular point in time.

A file passing those checks does not prove that everything inside it is safe. New, targeted or deliberately evasive threats may not yet have a signature or recognizable behavior, and disconnected or air-gapped environments cannot always rely on reputation services or continuously updated threat intelligence.

There is also a much broader file-format problem. Many security products concentrate on common Office documents, PDFs and email attachments, while government, defense and specialist business workflows rely on formats that conventional file-security tools have far less to say about. This leaves security teams carrying the uncertainty. 

Genesis takes a different approach.

Zero Trust, enforced inside the file

Rather than trying to determine whether a file looks malicious, Genesis treats the file itself as untrusted. It identifies what the file really is, validates its internal structure against the published specification for the format and reconstructs a new version containing only content that conforms and that policy permits. This approach is Content Disarm and Reconstruction, or CDR.  Because Genesis is enforcing what is permitted rather than trying to recognize every possible attack, protection doesn’t depend on having seen malware before.

"protection doesn’t depend on having seen malware before."

The result is a known-good, usable file that can continue to the user, application or next security domain, together with a transparent record of what Genesis found, what action it took and why. 

Policies can determine whether findings are reported, revealed, replaced, removed or cause the file to be rejected, giving teams control over the outcome rather than another black-box pass or fail.

Paul Farrington, Chief Product and Marketing Officer at Glasswall, explains:

"Zero Trust transformed how organizations think about identity and networks, yet content is still waved through on a hunch. Files remain the most direct route into an organization, and detection will always be one unseen sample behind. Genesis closes that gap, and it's the most significant engineering step we’ve taken in a decade."

Protecting the files organizations actually depend on

Genesis significantly expands the range of content that can be brought under that Zero Trust model. The engine covers 45+ file types and 140+ extensions, including documents, email and contact data, imagery, audio and video, geospatial and CAD formats, structured data and executable formats.

Alongside familiar formats such as Office documents, PDF and email, that includes NITF and SIDD imagery used in defense and intelligence workflows, DWG, DXF and STEP AP242 engineering files, DICOM medical imaging, and formats such as PE, ELF, Mach-O and Windows shortcuts.

Breadth alone is not enough. Complex files are often containers for other files, Genesis can clean embedded content through each layer rather than assuming that something is safe, or unsafe. An image inside a document, inside an email, still has to meet policy rules.

Importantly, Genesis works to preserve native formats rather than simply converting specialist information into a PDF or flattened representation. For mission, engineering and regulated workflows, security is only useful if the resulting file retains the fidelity and functionality required by the people and systems consuming it.

More control, with evidence behind every decision

Different workflows have different tolerances for change. A finding that can be safely removed from an everyday business document may need to be handled very differently in an evidentiary file, an engineering drawing or information moving across a classified boundary.

Genesis gives security teams granular policy control over those decisions. Rules use a common set of actions across the tool, while policies can establish a broad organizational posture and still make exceptions by format, content type or individual rule.

Every rule also carries structured provenance and a stable identifier. Decisions can be traced back to sources such as the published file-format specification, relevant CVEs and advisories, applicable security guidance or Glasswall research. Reporting then shows what was found, the action taken and the resulting state of the file.

That transparency matters in environments where teams need more than reassurance that a security product said "clean". They need to understand why a file was permitted to move and be able to demonstrate the controls that were applied to it.

Built for high-assurance environments

Genesis has also been re-engineered underneath. It is written in managed .NET and compiled as a self-contained Native AOT application, reducing exposure to common memory-corruption vulnerability classes associated with native parsing code while removing the need to install a separate .NET runtime.

Resource limits, processing timeouts and post-reconstruction validation add further safeguards when Genesis encounters malformed or deliberately adversarial files. The same architectural work has also increased performance, with Genesis able to process files up to 2x faster than Glasswall's previous CDR.

"up to 2x faster than Glasswall's previous CDR."

Genesis supports Windows, Linux and macOS across x86-64 and Arm64, and is designed for deployment in the cloud, on premises, at the tactical edge or fully air-gapped. High-assurance deployment options include hardened non-root containers, FIPS-enabled environments and SELinux enforcement, while offline operation means file protection does not depend on connectivity to signature or reputation services.

What Genesis means for government and defense

For government and defense customers, Genesis brings Zero Trust file protection to the information formats and deployment environments the mission actually requires.

Cross Domain Solutions, data diodes, intelligence and imagery exchanges, secure import and export gateways and tactical systems all move information between different levels of trust. In those environments, simply allowing an uncertain file is unacceptable, but unnecessarily blocking mission information is not a workable security strategy either.

Genesis provides another option: validate and reconstruct the information according to an explicit policy before it crosses the boundary. Specialist formats such as NITF and SIDD imagery can be handled in their native form, while the tool can operate fully offline and in restricted environments where cloud-based security services are unavailable.

That gives mission teams stronger control over what crosses a trust boundary without giving up the usability of the information on the other side.

What Genesis means for BFSI and secure businesses

For banks, financial services organizations, insurers and other security-conscious enterprises, file risk is embedded in the workflows that keep the business moving. Customer uploads, insurance claims, underwriting exchanges, supplier documents, email attachments and files shared with third parties all need to reach their destination without creating another path for an attacker.

Genesis allows organizations to apply file protection within those existing workflows rather than relying solely on quarantine and investigation. A file can be reconstructed into a policy-compliant version and continue to the next user or system, while security teams receive a structured record of any findings and changes.

For supported formats, Genesis can also layer Find & Redact policies onto the file-protection process to identify and act on information that should not cross a boundary, including sensitive terms, secrets and PII. This extends the Zero Trust principle beyond controlling potentially dangerous content coming into an environment to also helping control sensitive information moving out.

What Genesis means for our partners

Genesis has been designed as a tool that partners can take into their own products, solutions and customer environments. OEMs, Cross Domain Solution providers, security vendors and systems integrators can use the same underlying tool and policy model across supported file formats rather than building separate integrations for different types of content.

The tool can be delivered as a self-contained binary, container or embedded package and deployed across the major operating systems and architectures. Partners can also narrow deployments to the file-processing capabilities required by a specific use case, helping tightly governed environments limit the parser surface they expose.

This means one integration can support a much broader range of customer requirements, from enterprise file-transfer workflows to air-gapped systems, tactical deployments and specialist cross-domain solutions.

Glasswall will provide end of life support to the existing ‘Embedded Engine’ CDR software package for at least 5 years, through to August 2031 – facilitating an orderly transition for technical partners.

One CDR. Three ways to deploy.

Genesis is the new CDR at the center of Glasswall's file protection portfolio, with different deployment options depending on where and how customers need to protect files.

  • Glasswall Genesis: One self-contained binary for adding directly into your own products and workflows. Built for OEMs, CI/CD, tactical edge, cross-domain and air-gapped deployments.
  • Glasswall Halo: Scalable deployment with policy management, dashboards, authentication, REST and ICAP interfaces, plus Microsoft 365 and cloud storage integrations.
  • Glasswall Meteor: Desktop file protection for Windows. Drag in a file, receive a safe version back. Ideal for post-breach remediation and tactical edge environments.

Together, they provide different ways to apply the same underlying principle wherever files move.

Assume nothing. Rebuild everything.

Genesis is a new CDR tool, but the security idea behind it is deliberately simple. A file should not be trusted because of where it came from, what its extension says or because a security product failed to recognize something malicious inside it.

Genesis establishes trust differently: by understanding the file, validating what is inside it and rebuilding it according to an explicit policy before it moves on.

Glasswall Genesis is available now. Visit the product page to learn more, or book a demo to see a file cleaned and rebuilt in real time.

See what Zero Trust file protection looks like. Live, in 25 minutes.

A tailored walkthrough of how Glasswall rebuilds files to a known-good state, removes hidden threats, and provides the intelligence you need to understand file risk.

What's in the demo

  • See malicious files rebuilt in real time
    Watch Glasswall remove hidden threats and return a safe, usable files.
  • Integrate security without disruption
    See how Glasswall fits into your existing workflows and infrastructure.
  • Gain complete visibility into file risk
    Uncover threats, anomalies and hidden file intelligence.

Beazley's security is paramount, and this integration has significantly reinforced our cybersecurity framework.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.