Cybersecurity teams have spent years applying Zero Trust principles to identities, networks and applications. Glasswall is extending that model to one of the oldest and most persistent attack surfaces: the file itself. The company has launched Glasswall Genesis, a Content Disarm and Reconstruction (CDR) platform designed to treat every incoming or outgoing file as untrusted, validate its structure and rebuild a known-good version before it crosses a security boundary.
A file can look harmless while still containing something an organization does not want inside its environment.
That is the security problem Glasswall is attempting to address with Genesis, a new file-protection platform built around the principle that organizations should not have to decide whether a file is safe simply because a security scanner has not identified a known threat.
Traditional antivirus, malware detection and sandboxing systems generally ask whether a file contains malicious code or behavior. Glasswall’s approach asks a different question: What is the file actually supposed to contain, and can everything else be removed before the file reaches its destination?
Genesis uses Content Disarm and Reconstruction, or CDR. The system takes a file apart, analyzes its structure against the published specification for that format and reconstructs a new version containing only content that conforms to the organization’s policies.
The result is intended to be a usable file rather than a suspicious object waiting for a security verdict.
That distinction matters because detection is inherently dependent on what a security system knows or can recognize. Novel malware, evasive payloads and attacks exploiting legitimate file features can create a gap between “not detected” and “safe.”
CDR attempts to close that gap through reconstruction.
The approach is not entirely new. Content disarm and reconstruction has been used in high-assurance environments for years, particularly where organizations need to exchange files across security boundaries without relying exclusively on malware detection. Genesis represents Glasswall’s attempt to expand that model across a broader range of enterprise and specialist file types.
The company says Genesis supports more than 45 file formats and 140 extensions, including common Office documents, PDFs and images as well as specialized formats used in defense, intelligence, engineering and healthcare.
That breadth is one of the product’s more consequential claims.
Many secure-file-transfer systems simplify complex documents by converting them to a safer format, such as PDF. That can work for routine business documents, but it is less practical when the original file contains operational information that must remain editable or machine-readable.
An engineering organization, for example, may need a DWG, DXF or STEP AP242 file to retain its native structure. A healthcare organization may need to preserve DICOM medical imaging. Defense and intelligence organizations can rely on specialized imagery formats such as NITF and SIDD.
Glasswall says Genesis reconstructs those specialist files in their native formats rather than flattening them.
That positions the technology as a security layer designed to operate without fundamentally changing existing workflows.
The platform also provides policy controls for how suspicious or nonconforming content is handled. Security teams can configure findings to be reported, surfaced for review, replaced, removed or rejected depending on file format, content type or individual policy.
Every decision is logged, with rules mapped to sources including published file specifications, NSA Inspection and Sanitization Guidance, CVEs, security advisories and Glasswall research.
There is another security dimension: data leaving the organization.
Genesis can identify and redact personally identifiable information, secrets and cloud credentials across visible document content as well as metadata, comments and other less-visible structures. That extends the concept of Data Loss Prevention (DLP) into areas that conventional content inspection may overlook.
For enterprises, this convergence is significant. A file entering an organization can represent a malware risk; a file leaving it can represent a data-exfiltration risk. A single content-security architecture that addresses both directions could reduce the number of separate controls security teams need to manage.
Security architecture becomes part of the product
Glasswall is also emphasizing how Genesis itself is engineered.
The application is built using managed .NET and compiled as a self-contained Native AOT application. The architecture is intended to reduce exposure to common memory-corruption vulnerability classes, including buffer overflows and use-after-free conditions.
That is relevant for a file-processing product because the input itself may be deliberately malformed.
Security software that parses complex file structures has to assume that some files will attempt to exploit the parser. Genesis therefore includes resource limits, timeouts and post-reconstruction validation as additional controls, according to Glasswall.
The company says the architecture can process files at up to twice the speed of its previous engine.
Genesis runs on Windows, Linux and macOS across both x86-64 and Arm64 processors. It can be deployed in cloud environments, on premises, embedded within other products, at the tactical edge or in fully air-gapped environments. Glasswall says the platform can operate without signature updates, an important characteristic for isolated environments.
That flexibility makes the product particularly relevant to government, defense and regulated industries, where connectivity and data residency constraints can make cloud-first security architectures impractical.
Glasswall is also packaging Genesis through Glasswall Halo, which adds centralized policy management, dashboards and integrations with Microsoft 365 and cloud storage, and Glasswall Meteor, aimed at desktop file protection.
From Zero Trust networks to Zero Trust content
The broader industry direction is toward reducing implicit trust at every layer of the technology stack.
Zero Trust architecture has traditionally centered on identities, devices, applications and networks. The file remains an awkward exception: users and systems frequently have to accept files because business processes depend on them.
Genesis applies the same conceptual shift to content.
The important question for enterprise buyers will be whether reconstruction can consistently preserve functionality while removing content that creates unacceptable risk. That becomes harder as organizations move beyond standard Office and PDF files into highly specialized formats.
It also means CDR is not a replacement for endpoint security, email security, vulnerability management or other detection technologies. Rather, it represents a different security control: instead of attempting to identify every possible malicious payload, it attempts to constrain what a delivered file is allowed to contain.
That is a particularly relevant strategy for high-assurance environments.
As organizations exchange more files through cloud services, collaboration platforms, supply chains and automated workflows, file security is becoming less about the attachment in an email and more about every boundary through which content moves.
Glasswall’s Genesis launch is a bet that Zero Trust principles can be applied there too.
Market Landscape
The file-security market is evolving as organizations face increasingly sophisticated document-based attacks alongside growing regulatory and data-protection requirements.
Traditional antivirus and endpoint detection remain important, but they are fundamentally detection-oriented technologies. CDR offers a complementary approach by reconstructing content according to known structural rules before the file reaches its destination.
The model is particularly relevant to government, defense, healthcare, financial services and critical infrastructure, where a malicious or malformed file can cross multiple trust boundaries while remaining operationally necessary.
Major cybersecurity ecosystems including Microsoft, Palo Alto Networks, Fortinet and Trellix address file and content security through combinations of endpoint protection, email security, sandboxing, DLP and cloud security. Specialist CDR vendors compete by focusing more specifically on content sanitization and file reconstruction.
For enterprise security teams, the evaluation should focus on more than detection rates. Native-format fidelity, processing speed, policy granularity, auditability, deployment architecture and the ability to operate in disconnected environments can be equally important.
Top Insights
- Glasswall Genesis applies Zero Trust principles to files by reconstructing content instead of relying solely on malware detection or reputation-based security.
- The platform supports more than 45 file formats and 140 extensions, including specialized engineering, defense and medical formats requiring native-file fidelity.
- CDR can complement traditional endpoint and email defenses by removing nonconforming content before files cross organizational or network trust boundaries.
- Genesis extends data-loss prevention into metadata, comments, credentials and other hidden file structures that conventional content inspection may overlook.
- Air-gapped deployment, native-format reconstruction and policy-driven sanitization make the platform particularly relevant to high-assurance government and regulated environments.
Power Tomorrow’s Intelligence — Build It with TechEdgeAI











