Stack of glowing XML documents on a platform, representing Glasswall Transform to XML
Capability Datasheet

Transform to XML

The structural rewriting capability that enables high-assurance, hardware-verifiable file transfer across trust boundaries.

Stack of glowing XML documents on a platform, representing Glasswall Transform to XML

CDR + XML

Higher-assurance capability vs. CDR alone

NCSC

Pattern for Safely Importing Data - aligned

Zero

Detection, signatures or detonation required

What is Transform to XML?

Glasswall Transform to XML is a structural rewriting capability built into the Glasswall Embedded Engine. It takes a complex file format, such as a PDF, Word document, or spreadsheet, and converts it into a simplified, Verifiable Intermediate Representation of the file’s internal Document Object Model (DOM). Unlike standard CDR, which rebuilds a file and returns it in its original format, Transform to XML exposes the file’s structure in a form that hardware devices, FPGAs, and software validators can independently inspect and verify. This makes it the critical enabling capability for government-grade Cross Domain Solutions where hardware verification of file content is a requirement.

Transform to XML is the capability that allows CDS partners to satisfy the NCSC’s Pattern for Safely Importing Data in full.

A PDF file breaking apart into data that flows into a verifiable XML fileA PDF file breaking apart into data that flows into a verifiable XML file

How Transform to XML takes CDR further

CDR rebuilds files to a known-good specification and removes malicious content. For the majority of enterprise file security use cases, this is the right solution. However, for certain sensitive cross domain deployments - particularly those involving data diodes, FPGAs, or hardware security devices - there is an additional challenge: these hardware components cannot inspect complex file formats directly. A DOCX or PDF is structurally opaque to a hardware diode. The NCSC’s Pattern for Safely Importing Data recommends a transformation step precisely to address this gap. Without it, the assurance chain is incomplete. CDR disarms the file; Transform to XML makes it hardware-verifiable.

The benefits of Transform to XML

  • Hardware-verifiable output - XML that diodes, FPGAs, and validators can inspect directly
  • Independent verification by third-party hardware or software
  • Full NCSC pattern compliance, completing the assurance chain
  • Available via the Glasswall Embedded Engine (SDK) and Glasswall Halo - integrates directly into partner product stacks
  • Complements CDR, does not replace it - both capabilities ship from the same engine
  • Proven in live environments for UK government and defence

Six steps from complex file to hardware-verifiable output

01

Semantic verification

Glasswall CDR validates the incoming file against its manufacturer file specification. Active content and structural anomalies are identified and removed.

02

Structural disassembly

The file’s complex internal structure is unravelled into its constituent components - text, metadata, images, embedded objects - and represented as a Document Object Model (DOM).

03

Transform to XML

The DOM is converted into a simple, verifiable intermediate representation (XML). Images are transcoded into standardised bitmaps. The result is a format that hardware can inspect.

04

Hardware or software verification

The XML is passed to partner technology - a syntactic verification diode, FPGA, or software validator - for XSD schema validation. Only conformant files proceed.

05

Recomposition

The verified XML is returned to the original complex file format, giving the end user a clean, usable document on the other side of the boundary.

06

Semantic verification

Glasswall CDR then re-applies the principles of step 1 to ensure a safe file is delivered on the secure side of the boundary.

Transform to XML flow across untrusted, processing and trusted zones: untrusted device, TLS offloader, processing, XML validator and trusted networkTransform to XML flow across untrusted, processing and trusted zones: untrusted device, TLS offloader, processing, XML validator and trusted network

CDR alone vs CDR with Transform to XML

CDR rebuilds files to a known-good specification and removes malicious content. For the majority of enterprise file security use cases, this is the right solution.

However, for certain sensitive cross domain deployments - particularly those involving data diodes, FPGAs, or hardware security devices - there is an additional challenge: these hardware components cannot inspect complex file formats directly. A DOCX or PDF is structurally opaque to a hardware diode.

The NCSC’s Pattern for Safely Importing Data recommends a transformation step precisely to address this gap. Without it, the assurance chain is incomplete. CDR disarms the file; Transform to XML makes it hardware-verifiable.

Capability
CDR alone
CDR + Transform to XML
Semantic verification
CDR alone
Malware removed; file rebuilt to known-good spec
CDR + Transform to XML
Malware removed; file rebuilt to known-good spec
Transformation to XML
CDR alone
N/A
CDR + Transform to XML
Complex file types can be transformed into verifiable intermediate representation (XML).
Syntactic verification
CDR alone
N/A
CDR + Transform to XML
Third-party hardware or software XSD schema validation
Recomposition from XML
CDR alone
N/A
CDR + Transform to XML
XML can be recomposed into original format after verification
NCSC pattern compliance
CDR alone
Partial - semantic verification satisfied
CDR + Transform to XML
Full - semantic verification, transformation, and syntactic verification satisfied

Mapped to NCSC guidance

NCSC Pattern for Safely Importing Data - Transform to XML directly satisfies the transformation step the pattern requires, completing the assurance chain that CDR alone cannot close. Deployments using both capabilities can claim full compliance.

Where Transform to XML is deployed

Data diode deployments

Transforms complex file types into simple XML that one-way hardware diodes can inspect and pass, resolving the fundamental limitation of hardware-only verification.

FPGA / hardsec integration

XML output from Glasswall CDR can be syntactically verified against an XSD by FPGA-based partner technology, enabling the full NCSC-recommended transformation control chain.

High-assurance intelligence environments

Provides the structural rewriting step required for intelligence community and defence networks where standard CDR alone may be insufficient.

Partner CDS solutions

Allows CDS vendors to embed Glasswall's Transform to XML capability within their own solution and defend a higher price point with clear, auditable assurance evidence.

See what Zero Trust file protection looks like. Live, in 25 minutes.

A tailored walkthrough of how Glasswall rebuilds files to a known-good state, removes hidden threats, and provides the intelligence you need to understand file risk.

What's in the demo

  • See malicious files rebuilt in real time
    Watch Glasswall remove hidden threats and return a safe, usable files.
  • Integrate security without disruption
    See how Glasswall fits into your existing workflows and infrastructure.
  • Gain complete visibility into file risk
    Uncover threats, anomalies and hidden file intelligence.

“

Beazley's security is paramount, and this integration has significantly reinforced our cybersecurity framework.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.