Glasswall
Content You Can Trust. Access You Can Prove.
Glasswall protects government and commercial organizations against malicious files using Content Disarm and Reconstruction (CDR). Operating on Zero Trust principles, Glasswall treats every file as untrusted by default. Instead of relying on traditional signature-based scanning or threat detection—which can be evaded—it rebuilds files against known-good specifications to remove malware, zero-day exploits, and malformed code before files are ever opened. Glasswall's CDR is required as a content filter in Cross Domain Solutions (CDS) under the NSA's Raise the Bar guidance, and it is actively deployed within accredited CDS environments for demanding security organizations.
While this approach works smoothly for unencrypted boundary files, challenges arise as organizations increasingly adopt end-to-end file encryption to protect data in transit. Standard content filters cannot inspect encrypted data without decrypting it first, which breaks the chain of custody that encryption was implemented to protect.
Better Together: Glasswall + Virtru Data Security Platform
The combined solution extends data-centric security into CDR by maintaining continuous policy control directly attached to the data throughout the entire sanitization workflow. The Glasswall TDF Bridge operates as a federated gateway at the domain boundary, the Bridge authenticates as a governed service entity and requests decryption keys only when validated by attribute-based access policies. Content is reconstructed into a known-good format, re-encrypted, and embedded with signed provenance metadata before crossing the boundary. This process ensures the transferred file is sanitized while remaining fully bound to its original governance policy.
- Policy-Driven Access Control: The Glasswall Bridge grants access only when policy criteria are met—turning every sanitization event into an authorized access check.
- Tamper-Evident Auditing: Reconstructed files receive signed provenance and lineage assertions that persist with the encrypted object, providing oversight teams with continuous audit trails beyond the boundary.
- Streamlined Coalition Distribution: A single CDR pass enables secure cross-nation sharing without redundant manual re-encryption.
The Bridge deploys seamlessly alongside existing accredited guards and cross-domain solutions, delivering data-centric security without requiring guard re-accreditation.
- Policy-Enforced Sanitization: The solution grants access only when attribute-based policies are met, making every rebuild an authorized decision.
- Guard-Adjacent Deployment: The TDF Bridge operates alongside existing accredited guards, adding data-centric protection without requiring guard re-accreditation.
- In-Memory, Stateless Reconstruction: Files are decrypted, disarmed, and re-encrypted entirely in memory, maintaining security within the accreditation boundary.
- Signed Provenance and Lineage Assertions: Reconstruction history and classification levels are attached directly to the rebuilt object as tamper-evident, signed assertions.
- Federated Multi-KAS Key Wrapping: Sanitized objects are individually wrapped with the access policy embedded, enabling multinational sharing without manual re-encryption.
- Non-Person-Entity Identity for the Bridge: The Bridge authenticates to the identity provider using its own credentialed service entity, ensuring every key request is fully traceable.
- Decision-Level Audit at the Crossing: Every boundary key request and access decision generates granular audit evidence that persists as the file moves beyond the crossing.
Deploying Glasswall CDR with the Virtru Data Security Platform at a cross-domain boundary requires:
- Glasswall TDF Bridge deployed at the cross-domain boundary, operating adjacent to the customer's accredited guard or cross-domain solution.
- Virtru Data Security Platform running inside the accreditation boundary, providing the Key Access Service, key wrap/unwrap, and attribute-based policy enforcement.
- An OIDC/OAuth2 identity provider — Okta, Microsoft Entra ID, Ping Identity, or equivalent — to issue the Bridge's non-person-entity credential (client-credentials or x.509) and source attributes.
- Attribute-mapping configuration between source and destination policy spaces, established by authorized crossing administrators.
- Network connectivity within the accreditation boundary.
Security Architecture — The Glasswall Bridge manages workflow orchestration, in-memory file reconstruction, the CDR engine, non-person-entity identities, and audit logging. Meanwhile, the Virtru platform provides key management, encryption/decryption, and attribute-based access policy enforcement. Files are processed statelessly and are never written to disk in cleartext. By serving as the underlying identity, key, and policy layer, Virtru integrates smoothly with existing cross-domain guards to enforce protection everywhere a file moves.
Compliance & Standards — The Virtru Data Security Platform aligns with key Zero Trust and coalition standards, including ACP-240, NIST SP 800-162, and NIST SP 800-207. Built on the open, non-proprietary OpenTDF standard to avoid vendor lock-in, the platform is FedRAMP Moderate authorized and uses FIPS 140-3-validated key management. Granular, decision-level audit logs provide oversight beyond the traditional perimeter. Deploying adjacent to existing accredited guards preserves current authorizations while seamlessly adding data-centric protection.
Privacy & Data Sovereignty — Data owners retain complete decryption authority: Virtru's Key Access Service releases keys strictly according to defined policies, eliminating the need to give up control. For multi-national coalitions, Multi-KAS federation allows a single file to be shared across partner nations or enclaves while remaining secured under each partner's independent key authority.
Book a Demo
Become a Partner
Contact us to learn more about our partnership opportunities.
Become a Compliance Champion
Contact us to learn more about our partnership opportunities.