<img src="https://ad.doubleclick.net/ddm/activity/src=11631230;type=pagevw0;cat=pw_allpg;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=;tfua=;npa=;gdpr=${GDPR};gdpr_consent=${GDPR_CONSENT_755};ord=1;num=1?" width="1" height="1" alt="">

Glasswall

Content You Can Trust. Access You Can Prove.

Glasswall protects government and commercial organizations against malicious files using Content Disarm and Reconstruction (CDR). Operating on Zero Trust principles, Glasswall treats every file as untrusted by default. Instead of relying on traditional signature-based scanning or threat detection—which can be evaded—it rebuilds files against known-good specifications to remove malware, zero-day exploits, and malformed code before files are ever opened. Glasswall's CDR is required as a content filter in Cross Domain Solutions (CDS) under the NSA's Raise the Bar guidance, and it is actively deployed within accredited CDS environments for demanding security organizations.

While this approach works smoothly for unencrypted boundary files, challenges arise as organizations increasingly adopt end-to-end file encryption to protect data in transit. Standard content filters cannot inspect encrypted data without decrypting it first, which breaks the chain of custody that encryption was implemented to protect.

Better Together: Glasswall + Virtru Data Security Platform

The combined solution extends data-centric security into CDR by maintaining continuous policy control directly attached to the data throughout the entire sanitization workflow. The Glasswall TDF Bridge operates as a federated gateway at the domain boundary, the Bridge authenticates as a governed service entity and requests decryption keys only when validated by attribute-based access policies. Content is reconstructed into a known-good format, re-encrypted, and embedded with signed provenance metadata before crossing the boundary. This process ensures the transferred file is sanitized while remaining fully bound to its original governance policy.

  • Policy-Driven Access Control: The Glasswall Bridge grants access only when policy criteria are met—turning every sanitization event into an authorized access check.
  • Tamper-Evident Auditing: Reconstructed files receive signed provenance and lineage assertions that persist with the encrypted object, providing oversight teams with continuous audit trails beyond the boundary.
  • Streamlined Coalition Distribution: A single CDR pass enables secure cross-nation sharing without redundant manual re-encryption.

The Bridge deploys seamlessly alongside existing accredited guards and cross-domain solutions, delivering data-centric security without requiring guard re-accreditation.