Holographic folder and document being rebuilt on a glowing platform, representing Zero Trust CDR
Content Disarm and Reconstruction

CDR for file uploads

Secure every inbound file submission with Zero Trust CDR before it reaches your network, storage, or systems.

Holographic folder and document being rebuilt on a glowing platform, representing Zero Trust CDR

70%

of successful cyber attacks start with a file

812ms

average file processing time

140+

file extensions supported

Detection alone cannot secure file uploads

From customer onboarding to regulatory submissions, file uploads keep business moving. They also bring untrusted files directly into trusted environments, exposing organisations to targeted attacks designed to bypass detection-based security.

NITF file rebuilt to a known-good standard

The fundamental problem with scanning files at upload

Antivirus and sandbox tools work by comparing files against known malware signatures or detonating them in a controlled environment. Neither approach catches zero-day threats embedded in structurally valid documents (malicious macros, weaponised metadata, exploitable object streams) where the file looks entirely normal to a scanner but executes a payload once opened. File upload portals are the exact scenario where adversaries craft these threats to bypass detection.

Prevention, not detection

Glasswall secures file uploads with Content Disarm and Reconstruction (CDR), integrating directly into upload workflows through API, SDK, and gateway-based deployment options. Rather than relying on detection to decide whether a file is safe, CDR rebuilds each file to a known-good standard before it reaches storage or internal systems.

Detection-based scanning

  • Compares against known threat signatures. Anything new will pass unchallenged
  • Sandbox detonation adds latency (seconds to minutes), unacceptable for real-time portals
  • Cannot inspect deeply nested content: macros inside embedded objects inside archives
  • Passes or blocks whole files. No granular remediation of specific risky elements
  • Legitimate files may be blocked; malicious ones dressed as legitimate files pass

Glasswall CDR

  • Rebuilds files to the published format specification, removing hidden threats and malformed content
  • Removes threats without relying on detection
  • Recursively processes archives and embedded objects to any nesting depth
  • Granular policy control: strip macros, metadata, external links while preserving content
  • Rebuilt files are visually and functionally identical. Zero disruption to the upload workflow

Deploy at the point files enter your organisation

Glasswall CDR can be deployed at multiple points within a file upload architecture, depending on where you need the enforcement boundary to sit.

Architecture diagram: files from untrusted internet users pass through the customer web app to Glasswall Halo, deployed in the customer environment, where they are analysed and rebuilt before clean files and analysis reports are delivered and blocked files are heldArchitecture diagram: files from untrusted internet users pass through the customer web app to Glasswall Halo, deployed in the customer environment, where they are analysed and rebuilt before clean files and analysis reports are delivered and blocked files are held
01

File submission & interception

A user uploads a file through your portal, application, or secure file exchange service. Before the file is written to storage or routed to internal systems, Glasswall intercepts it at the integration point for processing. Processing occurs transparently in the background with no impact on the user experience.

02

Deep file analysis & policy enforcement

Glasswall deconstructs the file and validates every element against the manufacturer’s published file format specification rather than relying on threat signatures. Macros, embedded objects, scripts, external links, metadata, and active content can be removed, sanitised, or allowed based on your organisation’s requirements.

03

File reconstruction

Glasswall rebuilds the file from validated content, creating a brand-new version that conforms to the published file format specification, preserving the original document’s appearance, formatting, images, and business content.

04

Delivery, reporting & audit

The rebuilt file is delivered to its destination — cloud storage, a document management system, workflow platform, or business application — with a detailed analysis report for compliance, investigations, and security monitoring.

Integration options

Web application layer

Embed Glasswall directly in your web application using the REST API or Embedded Engine SDK. Files are processed at the point of submission, before storage is written, with clean files returned synchronously or via webhook.

Cloud storage trigger

For architectures where files land in object storage first (S3, Azure Blob, Dropbox), Glasswall can be triggered via AWS Lambda or Azure Function to process files automatically on upload. Clean files are written to an output bucket; non-conforming files are quarantined. This pattern is used in insurance, financial services, and government claims workflows.

Gateway / ICAP layer

Deploy Glasswall Halo as an ICAP-compatible gateway service to intercept file transfers at the network layer, independent of the application.

Granular control over every content element

Not all risky content requires the same response. Glasswall’s policy settings lets you define exactly how each category of potentially dangerous content is handled per file type, per use case, or per user group, giving you precision rather than a binary allow/block decision.

Content Type
Risk
Typical portal policy
Outcome
Macros & active content
High: primary malware vector in Office docs
Strip from all inbound files
Sanitised
Embedded objects / OLE
High: can contain hidden executable payloads
Remove embedded objects
Sanitised
External URL references
Medium: used for beaconing, credential harvesting
Remove hyperlinks; preserve display text
Sanitised
JavaScript in PDFs
High: executes on open in vulnerable readers
Strip all PDF JavaScript
Sanitised
Document metadata
Low to Medium: data leakage; some exploits via metadata
Strip metadata; preserve document content
Sanitised
Embedded images
Low: potential steganographic payload carrier
Regenerate via CDR; remove hidden content
Sanitised
Malformed file structure
High: malformation itself is an exploit technique
Quarantine; flag for manual review
Quarantined
Executables (.exe, .dll)
Critical: never acceptable in a document portal
Block at policy level; reject upload
Blocked

How Glasswall protects a leading European bank from file-based threats

  • Automatically remove zero-day malware from files
  • Secure ‘Know Your Customer’ KYC file uploads
  • Enable compliance with Anti-Money Laundering (AML) regulations
Click to read our case study

See what Zero Trust file protection looks like. Live, in 25 minutes.

A tailored walkthrough of how Glasswall rebuilds files to a known-good state, removes hidden threats, and provides the intelligence you need to understand file risk.

What's in the demo

  • See malicious files rebuilt in real time
    Watch Glasswall remove hidden threats and return a safe, usable files.
  • Integrate security without disruption
    See how Glasswall fits into your existing workflows and infrastructure.
  • Gain complete visibility into file risk
    Uncover threats, anomalies and hidden file intelligence.

“

Beazley's security is paramount, and this integration has significantly reinforced our cybersecurity framework.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.