CONTENT DISARM AND RECONSTRUCTION

CDR for Cross-Domain Solutions

The real-time Zero Trust enforcement point at the diode — every file rebuilt to a known-good standard before it crosses between classification levels.

NCDSMO

Top-rated content filter for CDS

RTB

Satisfies NSA Raise the Bar requirement

10+ years

Deployment across the US IC

5

US Intelligence Community agencies

Detection cannot enforce a trust boundary

At the most critical point in the network — the trust boundary between classification levels — the file itself becomes the attack surface. Traditional malware detection attempts to identify known threats. 
If a malicious file avoids detection, it crosses the boundary intact.Cross Domain Solutions require a different approach. Glasswall Content Disarm and Reconstruction (CDR) assumes every file is untrusted, validates its structure against specification, and rebuilds it into a known-good version before transfer.


The result is deterministic enforcement of Zero Trust at the domain boundary.

Detection-based scanning

  • Relies on known threat signatures. Unknown and 
zero-day threats pass unchecked.
  • File content is trusted implicitly once 
it clears a scan.
  • Embedded malware in complex file formats 
(Office, PDF) remains structurally intact.
  • Binary transfer allows malicious payloads to 
traverse the diode undisturbed.

Glasswall CDR

  • Every file is assumed malicious and rebuilt from scratch to a known-good standard.
  • Threats are removed structurally, not just flagged. No signatures required.
  • Complex file formats are deconstructed, validated, 
and reconstituted to specification.
  • Files are decomposed to a schema-checkable intermediate representation, hardware-verifiable 
as it crosses the diode.

Purpose-Built for Cross Domain Security

Glasswall integrates directly into existing Cross Domain Solutions, data diodes, secure gateways, and transfer workflows without requiring replacement of existing infrastructure.

IL5 to IL6 Data Flows

Glasswall CDR operates as the mandatory content filter at the IL5/IL6 boundary, with every file sanitised in time before reaching the destination classified environment. CDR enables secure synchronous/API-based transfer of mission-critical data between IL5/IL6 environments, reducing risk of file-borne attack, data loss, or CDS compromise.

Deterministic CDR Architecture

The Embedded Engine SDK provides deterministic content reconstruction as a mandatory control at the trust boundary. Files are deconstructed, validated, and reconstructed before transfer. Rather than moving opaque binary contentacross the boundary, Glasswall transforms content into a schema-verifiable intermediate representation that canbe independently validated as it traverses the diode.

Tactical and Edge Deployments

Supports disconnected, tactical, and DDIL environments where human reviewand release workflows remain operational requirements.

Key deployment capabilities

Air-gapped and DDIL environments. No external connectivity required.
Rapid, flexible deployment across on-prem, cloud, and hybrid architectures.
No ML model or signature database. Deterministic, auditable processing.
Modular open API standards for interoperability and plug-and-play deployment.

Built for accreditation from day one

Glasswall is the NCDSMO top-rated content filter for Cross Domain Solutions, satisfying the NSA Raise the Bar content-filter requirement.

National Security Agency logo USA

NSA Raise the Bar (RTB) mandate

Glasswall CDR satisfies the NSA RTB mandatory content filter requirement for Cross Domain Solutions, providing a real-time sanitisation layer that every file must pass before entering the secure domain.

Find out more

NIST Risk Management Framework (RMF)

Glasswall's Zero Trust CDR approach supports NIST SP 800-171 controls and the broader RMF risk reduction requirements for handling CUI and classified material in cross-domain scenarios.

Find out more

NCSC Pattern for Safely Importing Data

Architecture aligned with the NCSC's published pattern, ensuring that data brought into a high-trust network has been validated, transformed, and verified through a recognised, approved process.

Find out more

How CDS programs benefit

01

Accelerate Accreditation

Deploy a recognised content-filter capability that supports RTB-aligned security architectures and simplifies evidence mapping for accreditation teams.

02

Enforce Zero Trust at the Boundary

Every file is reconstructed before entering the destination environment, eliminating reliance on detection outcomes alone.

03

Reduce Operational Risk

Prevent malicious, malformed, or non-compliant content from crossing classification boundaries.

04

Preserve Existing Investments

Integrate into deployed guards, gateways, and diodes without replacing approved infrastructure.

05

Support Enterprise and Tactical Missions

Apply consistent security policies across cloud, on-premises, air-gapped, and edge environments.

See what Zero Trust file protection looks like. Live, in 25 minutes.

A tailored walkthrough of how Glasswall rebuilds files to a known-good state, removes hidden threats, and provides the intelligence you need to understand file risk.

What's in the demo

  • See malicious files rebuilt in real time
    Watch Glasswall remove hidden threats and return a safe, usable files.
  • Integrate security without disruption
    See how Glasswall fits into your existing workflows and infrastructure.
  • Gain complete visibility into file risk
    Uncover threats, anomalies and hidden file intelligence.

Trusted by government agencies and secure businesses

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Trusted by government agencies and secure businesses