The short answer: CDR products split into four buying routes - enterprise file-security platforms, cross-domain systems, sanitisation bundled into a gateway you already own and API-first services.
Which one fits is decided by where files enter, what you're allowed to run and how you're allowed to buy - long before capability comes into it. Filter the shortlist against your constraints.
The essentials:
- Almost nobody in this market publishes a price.
- File-type counts are not comparable between vendors.
- One vendor has a published independent efficacy test.
- Open-source CDR exists, and it is desktop software.
Written for security leads, technical founders and public-sector buyers who have decided they need file sanitisation and now have to choose a product.
Choosing a CDR product is harder than it should be, and not because the technology is complicated. It's because the market is small, prices are held back for a sales conversation and the most-read comparisons are written by participants in it.
The category leader's own "best vendors" guide ranks itself first. That's not unusual and it isn't disqualifying - it's a genuinely capable product - but it means the most-read comparison in this field is written by a participant, and so is this one.
What we sell, and how this was put together
Red Eagle Tech sells one of the products below. So that you can weigh what follows: every claim about another vendor comes from that vendor's own published material, its G-Cloud listing or its customer agreement, all checked in July 2026 and listed in the sources. Nothing here is sourced from a competitor's description of a competitor.
Capabilities are taken from each vendor's own documentation, so a product may well do more than we've credited it with - documentation isn't always current with the live product, and we'd rather understate than assume.
Treat this as a starting shortlist and confirm the detail with the vendor. The section on where each one could be the right choice includes ours.
Five different things are called CDR
Before anything else, a disambiguation that will save you an hour. "CDR" is one of the most overloaded acronyms in enterprise technology, and two of its meanings sit inside cybersecurity.
| CDR stands for | Field | What it is |
|---|---|---|
| Content disarm and reconstruction | Security | Rebuilding files to remove anything that shouldn't be there. This article. |
| Cloud detection and response | Security | Monitoring cloud workloads for attacks. A completely different product category that shares the acronym and much of the search traffic. |
| Call detail record | Telecoms | Metadata about a phone call, used for billing and analysis. |
| Critical design review | Defence and engineering | A programme milestone. |
| CorelDRAW file | Design | The .cdr vector graphics format. |
This matters commercially, not just editorially. Search for "CDR solutions" and you'll get cloud detection and response guides alongside file sanitisation ones. If you brief a colleague or an AI assistant with the acronym alone, expect to get answers about the wrong product. Use the full phrase in anything you circulate.
And the same technology goes by several other names
The acronym is overloaded in one direction and the technology is overloaded in the other: because "CDR" is ambiguous, most vendors have their own name for it. If you're searching, or comparing two datasheets that seem to describe different products, these all refer to the same underlying technique.
| Also called | Used by |
|---|---|
| File sanitisation, document sanitisation | The most common generic terms, used across the market and by us |
| Threat extraction | Check Point's name for it - its own material describes Threat Extraction as a content disarm and reconstruction capability |
| Threat removal | Deep Secure's term, carried into Everfox |
| Deep CDR | OPSWAT's trademarked name for its implementation |
| Zero Trust CDR | Everfox and Glasswall, framing it as a zero-trust data filter |
| Positive selection | Votiro's term, describing rebuilding from known-good elements only |
| Deweaponisation | Appears in OPSWAT's G-Cloud listing; also written as file disarming |
| File regeneration, file reconstruction | Descriptive terms used across several vendors' datasheets |
None of these is a different technology. They all describe taking a file apart, keeping what a valid file of that type is allowed to contain and rebuilding the rest. If a vendor uses one of these terms and never says "CDR", you're still looking at the same category.
How the CDR market actually splits
Vendor comparisons usually present this market as a league table. It isn't one. It's four groups of products that barely compete with each other, and knowing which group you're in eliminates most of the market immediately.
Enterprise file-security platforms
Broad products that sanitise files arriving through email, web traffic, removable media and storage, usually alongside multi-engine antivirus scanning and data loss prevention.
They deploy in your infrastructure or as a managed service, and they integrate through ICAP (the protocol a gateway uses to hand a file to an external scanner) as well as APIs. All are bought through a sales process. OPSWAT, Glasswall, Votiro and Sasa Software sit here.
Cross-domain and high-assurance systems
Products designed to move data between networks at different classification levels, where the sanitiser is one component inside a guard. These are cross-domain solutions: they carry formal accreditation, they run offline and air-gapped and the procurement is a programme rather than a purchase. Everfox and Nexor are the names a UK buyer meets, and Glasswall competes here too.
There's a structural point worth absorbing if you're evaluating this end of the market: independent analysis of the cross-domain market argues that CDR is increasingly a component of guard solutions rather than a standalone product. If you're buying cross-domain, you're buying a guard, and the CDR inside it is a feature.
Sanitisation bundled into a gateway you already own
Check Point's Threat Extraction and Fortinet's CDR are capabilities inside network and email security products. Coverage is narrower - Check Point publishes support for around 40 file types against OPSWAT's claimed 200-plus.
If you already run the platform, though, this is a licence change rather than a project. It is comfortably the cheapest route to "something is sanitising our email attachments" for anyone already inside those ecosystems.
A worked example, because it's our own. Red Eagle Tech's managed IT support includes advanced email and Microsoft 365 security on every tier, and the CDR in it is Check Point's Threat Extraction.
Attachments arriving by email, and files moving through OneDrive, SharePoint and Teams, get stripped and rebuilt before anyone opens them - typically in under two seconds, with the original held back for sandboxing in parallel.
It's a good illustration of how this route actually works in practice, because the CDR is one layer rather than the whole product. Alongside it sit a CPU-level sandbox for files it hasn't seen before, antivirus scanning, anti-phishing and impersonation detection, malicious-domain blocking and warning, URL rewriting and file-type controls that can block anything outside an approved list. The CDR file-type coverage is comparatively narrow - Office documents and PDFs, plus image handling on email attachments - but it doesn't need to be broad, because the other layers cover what it doesn't.
That's worth understanding even if you never buy it, because it reframes the question. Plenty of organisations looking for CDR don't want an API or a platform at all - they want the capability to arrive as part of a managed service somebody else runs. If that describes you, the buying decision isn't which CDR product to license; it's which managed service already includes it.
API-first services
Sanitisation as an HTTP call, for teams putting it inside an application rather than at a network boundary. This is where we operate, and we're not alone: Sasa Software sells GateScanner through an API and ICAP as a service, Glasswall Halo is a REST and ICAP product on Kubernetes and Everfox's Application eXchange is an API service.
One distinction gets lost constantly here, and it's worth separating properly. "Has an API" and "can be bought without a sales call" are different questions. Sasa's API service and Glasswall Halo are both genuinely API-delivered, and both are quote-only with a "request a demo" button. Being a developer-shaped product doesn't make it a self-serve one.
The shortlist, and a filter for it
What this list covers. These are CDR products - vendors for whom sanitisation is a named product with its own support, SLA and roadmap. It is not exhaustive, and the omissions are deliberate:
- General-purpose API platforms that expose a CDR endpoint alongside dozens of unrelated APIs. Several exist and some are cheap. They're a reasonable answer if sanitisation is a small part of what you need from a supplier, and they're a different kind of purchase from the ones below.
- Suites where CDR isn't separable, and vendors with no meaningful UK route to market.
- Browser isolation products, which solve an adjacent problem.
Capabilities below are what each vendor publishes, checked in July 2026. Filter the table against your own constraints and you'll see what removed each product.
One deliberate exception: how you're able to buy doesn't eliminate anything. Your procurement route doesn't change what a product can do, so anything capable of the job still appears - just separated into what you can buy the way you asked and what's sold a different way.
| Product | Where it fits | How you buy it | What stands out |
|---|---|---|---|
| Glasswall | Enterprise platform, cross-domain, API | Sales process. Price on request. | London-registered. Published customers include NATO, Five Eyes and AUKUS members. Halo runs on Kubernetes with REST and ICAP; the engine works offline and disconnected. |
| OPSWAT | Enterprise platform, email, web, ICAP, kiosk | Sales process, or G-Cloud 14 | The category leader and the only vendor with a published independent test. MetaDefender Core is listed on G-Cloud at £2,562.00 a unit a year. |
| Everfox | Cross-domain, high-assurance, API | Sales process, or G-Cloud 14 | Formerly Forcepoint Federal; absorbed Deep Secure. Zero Trust CDR is listed on G-Cloud at £165.75 a unit. Its API service is contractually capped at 20 requests per second. |
| Votiro (Menlo) | Browser, email, SaaS, collaboration, API | Sales process | The category's pioneer, acquired by Menlo Security in February 2025 and now part of a wider workspace-security platform rather than a standalone purchase. |
| Sasa Software | Email, web, managed file transfer, media, API/ICAP | Sales process. Demo request only. | GateScanner handles archives, PST and OST mailboxes and DICOM medical imaging. It also offers an optical data diode for cross-domain transfer. |
| ReSec | Email, web, removable media, file servers, API | Sales process | Keeps originals quarantined outside your network and delivers rebuilt replicas. Note the gap between formats detected and formats sanitised. |
| odix | Microsoft 365 mail, API | Sales process | FileWall is pitched squarely at smaller organisations inside Microsoft 365, which almost nothing else in this market is. |
| Check Point | Network gateways, endpoints, email | Sales process, usually an existing contract | Threat Extraction is bundled into Check Point's threat-prevention products. Around 40 file types, with optional conversion to PDF. |
| Fortinet | FortiMail, FortiGate, ICAP, sandbox | Sales process, usually an existing contract | Strips active content and delivers a flattened copy, with the original retained or sent to FortiSandbox by policy. Office, PDF and ZIP. |
| Nexor | Cross-domain transfer, defence and government | Sales process | UK company focused on secure data transmission between domains, with CDR integrated into the transfer path. |
| Red Eagle Tech | Applications and APIs only | Self-serve with a card, or invoice | Processing in Azure UK South, OAuth2, billed per accepted document with published pricing. Capped at 30 requests a minute, cloud only, no accreditation. |
Filter the shortlist
Answer all seven and the shortlist will filter itself.
Still standing
Could do the job, but sold a different way
Nothing in this list can do all of that. That's a real answer rather than a failure of the filter - some combinations of constraint aren't served by an off-the-shelf CDR product, particularly specialist formats combined with air-gapped operation.
Relax whichever constraint is softest and try again, and treat the result as the start of a procurement conversation rather than a shopping list.
A shortlist of one is worth a second look. If you narrowed it by asking to buy self-serve, the short list reflects how this market sells rather than how many products could do the job - CDR is overwhelmingly sold through sales teams. If the buying route matters more to you than having a dedicated CDR product, general-purpose API platforms expose sanitisation endpoints too.
Ruled out, and why
Each product is matched on the first constraint that separates it. Capabilities come from each vendor's own documentation, so a product may do more than it's credited with here - worth confirming with the vendor before you rule it out.
Ours is one of the ones left. You can see what the CDR API does and what it costs, and be up and running in a few minutes entirely self-service. The guide to CDR covers the technique itself.
The six questions that separate vendors
The NCSC publishes a design pattern for safely importing data, and it's the most useful thing a UK buyer can read before taking a vendor call - because it's written by people with no product to sell. It requires that nested content is unpacked, transformed and verified, that limits are placed on recursion depth and that content format is verified robustly and consistently at each step of the architecture.
Those requirements imply questions. Here are the six that actually produce different answers from different vendors.
1. Where does it sit in your architecture?
An ICAP server, an email gateway, a kiosk and an HTTP API are four different products even when the sanitisation engine underneath is identical. This is the constraint that eliminates most of the market, so establish it first.
2. What does it do to the file?
There's a real spectrum here. Some products flatten everything to a PDF, which is completely effective and destroys editability. Some rebuild the file in its original format, keeping it usable. Some let you choose per policy. Ask specifically about nested content - archives inside archives, an embedded spreadsheet inside a document - because that's where the difference between products shows up, and it's exactly what the NCSC pattern calls out. Ask how deep the recursion goes and what happens at the limit.
3. What throughput will it sustain?
Vendors advertise latency - "milliseconds per file" is the standard phrasing - and latency is not the number that decides whether a product fits. Concurrency is. A service that processes one file in 200 milliseconds but accepts ten requests a second cannot sit inline in front of a busy upload path, however fast each individual file is.
Hardly anyone publishes a rate limit. Everfox does, in its customer agreement rather than its marketing: its CDR cloud service may not exceed 20 requests per second, and exceeding your purchased throughput in a month allows termination on 30 days' notice unless you buy more capacity. Ours is capped at 30 requests a minute. Both of those are useful numbers precisely because they're specific. Ask every vendor for theirs in writing, and treat "it scales" as a non-answer.
4. What is the billable unit?
Per file, per gigabyte, per user, per appliance, per credit, per CPU. This is the question that decides whether two quotes can be compared at all, and credit-based pricing is where it gets genuinely difficult - a single document can consume many credits depending on its size, type and what was done to it, which makes "25,000 API calls" an unknowable quantity of actual work.
Ask what one document costs, in writing, with an example. Then ask what happens on a failed submission: some providers charge for it.
5. Where does processing physically happen?
If you're handling client documents, this is a contract question and a data-protection one. Ask where files are processed, how long the submitted file and the rebuilt copy are retained and whether your content is used for anything other than fulfilling your request. Some file-scanning services share submitted samples with the wider security industry - genuinely valuable for threat intelligence, and a serious problem if the file contains someone else's personal data.
6. What happens when it fails?
The most-skipped question in the evaluation, and the one you'll care about most in production. Does an unprocessable file fail open or fail closed? Is the original quarantined, returned or destroyed? Do you get told which elements were removed, or just handed a clean file? Is there a report you can show an auditor?
No answer here is automatically wrong. Not knowing which one you bought is.
Which of these will tell you the price?
Almost none of them, on their own website. We checked all nine third-party products in July 2026. Not one publishes a commercial price - Glasswall prints "price on request" directly in its own product comparison table, which is at least unambiguous.
There is one genuine exception, and it's a UK one that surprisingly few buyers know about. Two of these vendors publish a price on the G-Cloud framework, through the government's Digital Marketplace:
| Product | Published price | Where |
|---|---|---|
| OPSWAT MetaDefender Core | £2,562.00 a unit a year | G-Cloud 14, free trial available |
| Everfox Zero Trust CDR | £165.75 a unit | G-Cloud 14 via Softcat, free trial available |
Those figures are the published list prices on the Digital Marketplace, checked in July 2026. Deliberately, we're not putting them side by side as a comparison: a "unit" means different things in the two listings and the terms differ, so treating one as cheaper than the other would be meaningless. What they show is that a published number exists, which is more than the vendors' own websites will tell you.
If you're a public-sector buyer, check the framework before starting a procurement from scratch. If you're not, you're in a market where the price is a conversation, and you should budget time for it.
While we're on numbers you'll be quoted
Two figures get waved at buyers in this market and neither survives contact with the source.
File-type counts aren't comparable. The category leader's own comparison table lists ReSec as supporting 250-plus formats for detection while sanitising 50-plus - a fivefold gap inside a single row. OPSWAT publishes "200+ file types" in that same blog and "180+ FileTypes" on its G-Cloud listing. Glasswall's own documentation lists supported formats by category and gives no total at all, which means the "85+" figure attributed to it comes from a competitor rather than from Glasswall. The number is marketing, not a specification. Ask which of your formats are supported, and whether each is sanitised or merely recognised.
Market-growth forecasts are guesses. Five published analyst estimates of this market's compound annual growth rate range from 8.73% to 19.1%, with base-year sizings that disagree by around 10 per cent. When a vendor cites market growth at you, the published estimates differ by more than a factor of two, so the figure is a mood rather than a measurement.
Is there a credible open-source CDR?
Yes - one, and the precise shape of the answer is more useful than either "no" or a list of repositories.
Dangerzone, maintained by the Freedom of the Press Foundation, is real. It's AGPL-licensed, has roughly 5,600 GitHub stars and 2,000+ commits, and it was audited by Include Security in December 2023 - the audit found no high-risk issues, with three low-risk and seven informational findings. It takes PDFs, Office documents, OpenDocument files, EPUBs and common image formats, renders them to pixels inside a sandbox with no network access and rebuilds a PDF from the pixel data.
That's genuine content disarm and reconstruction, done by a credible team, for free.
It is also desktop software that always outputs a PDF. If you're a journalist opening documents from sources, or anyone reviewing untrusted files by hand, it's an excellent answer and you should use it. If you need sanitisation inside a request path, it isn't a candidate - not because of quality, but because of shape. You lose editability on every file, and there's no throughput story because it was never trying to have one.
The rest of the open-source CDR field is dormant. DocBleach, which describes itself as content disarm and reconstruction software and handles Office and PDF files, has been archived and read-only since November 2020. ExeFilter, the original public implementation of the idea, was presented at CanSecWest in 2008 and hasn't moved meaningfully since.
So: one maintained, audited, free tool, shaped for people rather than for pipelines. That's the whole category.
Where each one could be the right choice
Every product here is the best answer for somebody. Which one is yours depends far more on your constraints than on any ranking, so here is the case for each - and the situation where you'd be better served by one of the others.
| Product | It could be the right choice when |
|---|---|
| Glasswall, OPSWAT, Sasa | You need coverage across every channel - email, web, removable media, storage - with deep policy control, and you have a procurement process that can accommodate a platform. Consider a lighter option if you want to be live this week or only sanitise the occasional file. |
| Everfox, Nexor | You're moving data between security domains and need formal accreditation behind it. That capability is theirs and few others have it. If no formal boundary exists in your architecture, the accreditation and cost buy you little. |
| Check Point, Fortinet | You already run their gateways - then it's a licence change rather than a project, and comfortably the cheapest route in. Bought standalone purely for CDR they're the wrong shape, and Fortinet's flattened output rules it out if files must stay editable. |
| Votiro (Menlo) | You're buying browser and workspace security anyway - the CDR comes as part of a broader platform with real pedigree behind it. If you want file sanitisation on its own, that's a larger commitment than you need. |
| odix | Your files arrive through Microsoft 365 and you're a smaller organisation - FileWall is the one product in this list aimed squarely at that, which almost nothing else is. |
| Dangerzone | A person is reviewing untrusted documents by hand and a PDF is a fine output. It's free, audited and genuinely good at that. It isn't a candidate inside an application, or where files must stay editable. |
| Red Eagle Tech | Files arrive through an application you run, you want them rebuilt rather than judged, and you'd like published pricing and a self-service start. For on-premises or air-gapped deployment, ICAP integration with a gateway, cross-domain transfer, defence accreditation or specialist formats, one of the products above will serve you better. |
One more, applying to everyone including us: only one vendor here has a published independent efficacy test. SE Labs tested OPSWAT's Deep CDR in October 2023 and awarded 100% for protection and accuracy, and SecureIQLab published a separate validation in 2024. Nobody else in this comparison has submitted to a public test, and neither have we.
Two caveats that matter. These tests are vendor-submitted and vendor-funded - standard practice across security testing, and SE Labs discloses it. And the test is nearly three years old. The practical consequence for a buyer is that efficacy claims across this market are almost entirely self-asserted, so weigh what a vendor will commit to in a contract more heavily than what appears on a datasheet.
Where Red Eagle Tech fits
We offer an API-first route with published, per-document pricing, and you can be up and running within minutes. If your files arrive through an application you run, you want them rebuilt rather than judged and you'd like to onboard yourself through a secure, self-service platform, we're built for that.
What's specific about it:
- Processing happens in the UK, in Azure UK South, and submitted content is deleted once processing completes. Rebuilt files are held for 24 hours and you can delete them sooner through the API. Your files are never used for anything except sanitising them.
- The billable unit is one accepted document - no credit multipliers, no per-megabyte surcharge. If a document fails to process because of a fault on our side, it's credited back automatically.
- You can buy it today via self-service. Sign up, add credit and make your first call entirely self-service if that suits you - and we're glad to talk it through instead if you'd prefer. We hold the documentation to a standard that makes that realistic: good enough to hand to an AI coding assistant that has never seen the API and be up and running within a few minutes.
- OAuth2 client credentials, short-lived tokens, no long-lived API keys sitting in request headers.
Where another product would serve you better. Everything in our row of the table above is real, and worth being straight about. We're cloud-only, so on-premises and air-gapped requirements point you elsewhere. We have no ICAP server, so a network gateway isn't where we sit. We hold no defence accreditation, and we don't claim to.
On throughput, the 30 requests a minute is what you get on the self-service tiers - comfortable for an application upload path, and probably not enough for high-volume inline gateway traffic. It isn't a hard limit on what we can do: Enterprise customers can have a higher ceiling, it just needs a conversation first. Contractual SLAs likewise start at our Enterprise tier, and support runs UK business hours.
If any of those describe your requirement, one of the enterprise platforms or cross-domain products above is the better answer and we'd rather point you at it.
Sanitising documents inside an application? See what the CDR API does and what it costs - published pricing, and you can be up and running in minutes entirely self-service. If you'd rather talk it through first, we're glad to. If you're earlier than that, our guide to content disarm and reconstruction covers the technique, and file upload security covers the rest of the upload path.
Frequently asked questions
There isn't one, and any page that gives you a single answer is selling something. The products in this market are built for genuinely different jobs: cross-domain transfer between classified networks, inline sanitisation on an email or web gateway and sanitisation as an API call inside an application. A product that is excellent at one of those is usually unavailable for the others. The useful question is which constraints you have - where files enter, whether processing can happen off your own infrastructure, how you are allowed to buy - because those eliminate most of the market before capability ever comes up.
Yes, one: Dangerzone, maintained by the Freedom of the Press Foundation. It is AGPL-licensed, has around 5,600 GitHub stars and was audited by Include Security in December 2023 with no high-risk findings. It renders a document to pixels inside a network-isolated sandbox and rebuilds it as a PDF. That makes it a real option for a person checking documents by hand, and not an option for an API in a request path, because the output is always a PDF and there is no throughput story. The other open-source CDR projects are dormant: DocBleach has been archived and read-only since November 2020, and ExeFilter dates from 2008.
Because this market sells through sales conversations rather than price lists. Of the nine CDR products we checked in July 2026, none published a commercial price on its own website - Glasswall prints "price on request" in its own product table. Two publish through the UK government's G-Cloud framework, which is a genuine route to a number if you are a public-sector buyer: OPSWAT lists MetaDefender Core at £2,562.00 a unit a year, and Everfox lists Zero Trust CDR at £165.75 a unit. Everyone else expects a sales conversation.
The question can't be answered, and it's worth understanding why before you use it to choose. Vendors count different things. OPSWAT's own comparison shows ReSec supporting 250-plus formats for detection but sanitising 50-plus - a fivefold gap inside one row. OPSWAT itself publishes "200+ file types" in its blog and "180+ FileTypes" on its G-Cloud listing. Ask instead which of the formats you actually handle are supported, and whether each one is sanitised or merely recognised.
Antivirus compares a file against things known to be malicious and returns a verdict. CDR takes the file apart, keeps the content a valid file of that type is allowed to contain, discards the rest and builds a fresh file - so it never needs to recognise the threat. Our guide to content disarm and reconstruction covers the technique in full, including how it compares with sandboxing and data loss prevention.
Yes. Two of the products in this comparison are listed on G-Cloud 14 on the Digital Marketplace, both with published prices and free trials: OPSWAT MetaDefender Core, and Everfox Zero Trust CDR, which is supplied through Softcat. For a public-sector buyer that is often the fastest route to both a price and a contract, and it is worth checking before starting a procurement from scratch.
Use the NCSC's own design pattern for safely importing data as the frame, because it is vendor-neutral and it implies the questions. It requires that nested content is unpacked, transformed and verified, that limits are placed on recursion depth and that content format is verified robustly at every step of the architecture. From there the questions that actually separate products are practical: where it sits in your architecture, what it does to the file, what throughput it will sustain, what the billable unit is, where processing happens and what happens when sanitisation fails.
This is the question most buyers forget to ask, and the answers differ in ways that matter. Some products fail closed and block the file. Some fail open and pass it through. Some quarantine the original outside your network and deliver only a rebuilt copy. Some return an error and charge you for the attempt. None of those is automatically wrong, but you need to know which one you are buying, and it is rarely on the datasheet. Ask for it in writing.
Some products can and most cloud services can't. Because CDR rebuilds files against a format specification rather than matching them against threat signatures, it doesn't need a live connection for updates the way antivirus does - which is exactly why it suits offline and disconnected environments. Glasswall, OPSWAT, Sasa Software and Nexor all offer deployments that run on your own infrastructure. Anything sold only as a cloud service, ours included, is out of scope for an air-gapped requirement.
Vendors advertise latency, usually "milliseconds per file", and that is not the number that decides whether a product fits. Concurrency is. Everfox's own customer agreement caps its CDR cloud service at 20 requests per second and allows termination on 30 days' notice if you exceed the throughput you bought. Our own API is capped at 30 requests a minute at launch. Almost nobody else publishes a rate limit at all, so ask for one before you design an inline path around a product.
Not really. Defender for Office 365 Safe Attachments detonates attachments in a sandbox and makes a verdict, and Purview handles data governance. Both are useful and neither rebuilds the file, which is the thing CDR does. If your files arrive by email and you already pay for Defender, it is worth understanding what it does before buying anything else - but it answers "is this known to be bad" rather than "is what's left safe to keep".
One has. SE Labs, an independently owned and AMTSO-certified testing house, tested OPSWAT's Deep CDR in October 2023 and awarded a 100% protection and accuracy score. SecureIQLab published a separate validation of the same product in 2024. No other vendor in this comparison has a published independent CDR test, and neither do we. These tests are also vendor-submitted and vendor-funded, which is normal for the industry but worth knowing. The practical consequence is that efficacy claims in this market are almost entirely self-asserted, so weigh what a vendor will put in a contract more heavily than what it puts on a datasheet.
Menlo Security acquired Votiro on 19th February 2025, and Votiro's CDR now sits inside Menlo's secure browser and workspace platform. Deep Secure, the UK CDR specialist, was absorbed into Everfox - Everfox's cloud CDR service is still described in its own contracts as "previously Deep Secure ZT CDR API Service". Everfox itself was Forcepoint Federal until 2024, and it went on to acquire the London hardware-security firm Garrison Technology in August 2024. If you are signing a multi-year contract, ask where the product sits on the acquirer's roadmap.
It depends entirely on what the provider does with the file, and that is a contract question rather than a technical one. Ask three things in writing: where processing physically happens, how long the submitted file and the rebuilt copy are retained and whether your content is ever used for anything other than processing your request. Some file-scanning services share submitted samples with the wider security industry, which is a real problem if the documents contain client data. If a provider won't answer those three questions in writing, that is your answer.
Sources
- National Cyber Security Centre - Pattern: Safely Importing Data (accessed July 2026). ncsc.gov.uk/guidance/pattern-safely-importing-data
- National Cyber Security Centre - Design Pattern: Safely Exporting Data (accessed July 2026). ncsc.gov.uk/guidance/design-pattern-safely-exporting-data
- Department for Science, Innovation and Technology and Home Office - Cyber Security Breaches Survey 2025/2026 (2026). gov.uk/government/statistics/cyber-security-breaches-survey-20252026
- Crown Commercial Service - OPSWAT MetaDefender Core, G-Cloud 14, Digital Marketplace (accessed July 2026). applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/266961883480396
- Crown Commercial Service - EverFox Zero Trust Content Disarm and Reconstruction, G-Cloud 14, Digital Marketplace (accessed July 2026). applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/306985675814048
- Glasswall - Meteor product page and Supported file types documentation, last updated 13 February 2026 (accessed July 2026). glasswall.com and docs.glasswall.com
- OPSWAT - Content Disarm and Reconstruction (CDR): 8 Best Vendors in 2026 (accessed July 2026). opswat.com/blog
- OPSWAT - MetaDefender Cloud product page and Deep CDR technology page (accessed July 2026). opswat.com
- Everfox - Enterprise Solutions Customer Agreement, 24 September 2024 (accessed July 2026). static.carahsoft.com
- Menlo Security - Menlo Security Acquires Votiro, press release, 19 February 2025. menlosecurity.com/press-releases/menlo-acquires-votiro
- Garrison Technology - Everfox to Purchase Garrison Technology Ltd, press release (2024); acquisition completed August 2024. garrison.com
- Sasa Software - Content Disarm and Reconstruction service via API, GateScanner Integration Server (accessed July 2026). sasa-software.com
- SE Labs - CDR Protection: OPSWAT Deep CDR, October 2023 (published 2024). selabs.uk
- SecureIQLab - OPSWAT CDR Report, Q3 2024. secureiqlab.com
- Freedom of the Press Foundation - Dangerzone, project site and source repository; Include Security audit, December 2023 (accessed July 2026). dangerzone.rocks and github.com/freedomofpress/dangerzone
- DocBleach - source repository, archived 9 November 2020 (accessed July 2026). github.com/docbleach/DocBleach
- Philippe Lagadec - ExeFilter, presented at CanSecWest 2008 (accessed July 2026). github.com/decalage2/exefilter
- Cross Domain Solutions - Vendors and Products landscape (accessed July 2026). xdomainsolutions.org/learn/landscape/vendors
- Mordor Intelligence, The Insight Partners, Future Market Insights, Global Growth Insights and ReAnIn - Content Disarm and Reconstruction market reports (2024 to 2026), used only for the range of published growth estimates
Narrowing it down
Most of the work in choosing a CDR product is eliminating the ones that were never going to fit, and the constraints that do the eliminating are architectural rather than commercial. If you'd like a second opinion on which route suits what you're building - including when that route isn't us - we're happy to give you one.