Protect your business from file-based threats

Email is still the top route for malware, and around 1 in 8 email-borne threats slips past at least one gateway scanner (HP Wolf Security, 2025). Our Content Disarm and Reconstruction (CDR) API doesn't try to detect threats - it removes them, rebuilding every file clean while preserving what your users need.

"The same engine already protects file uploads inside the platforms we run for our own clients - now it's available as a self-service API."

Kat Korson, Director

Infected documents pass through a glowing blue shield that strips out malware; they emerge clean with a tick

The security challenge

File-based threats remain one of the most common attack vectors leading to data breaches and ransomware infections

61%

of malware threats are delivered by email
HP Wolf Security, Q2 2025

44%

of confirmed data breaches involve ransomware
Verizon DBIR 2025

67%

of UK medium-sized businesses identified a breach or attack in the last 12 months
UK Gov Cyber Security Breaches Survey 2025

£3,550

average cost of a UK business's most disruptive breach, where costs were incurred
UK Gov Cyber Security Breaches Survey 2025

Traditional antivirus solutions only catch known threats, leaving you vulnerable to zero-day exploits and targeted attacks. Red Eagle Tech's CDR API provides comprehensive protection against document-based threats. Read our guide on cybersecurity essentials for UK SMEs.

How Content Disarm and Reconstruction works

A proactive security approach that treats every file as potentially dangerous

Four-stage CDR process diagram: 1 evaluate, 2 disarm, 3 rebuild, 4 deliver

Validate file type and consistency. Prevent file-type masquerading attacks by verifying the true file format matches the claimed extension.

Separate the file into discrete components and remove potentially harmful objects such as macros, scripts, embedded objects, links, or any content not conforming to specifications.

Rebuild a safe file and reconstruct metadata, preserving all benign file characteristics that ensure functionality and usability.

Recompile, rename, and deliver the file, preserving file structure integrity so end users can safely use the document with all its original functionality.

Want the deeper story - the history, the trade-offs, and where CDR fits in a layered defence? Read our complete guide to Content Disarm and Reconstruction.

Key benefits of our CDR API

Add enterprise-grade document security to your applications with minimal effort

True zero-day protection

Unlike traditional antivirus that relies on signatures, CDR removes threats regardless of whether they've been seen before, providing protection against even the newest attacks. See how CDR fits alongside antivirus, EDR and MDR.

Simple API integration

One REST call with ?wait=true returns the cleaned file link for most documents; larger files fall back automatically to submit-and-poll. Quickstarts in curl, C#, JavaScript and Python get you live in minutes.

Document usability

Our CDR process preserves the functionality and appearance of documents while removing only the potentially harmful elements, ensuring a seamless experience for end users.

Fully managed service

No infrastructure to maintain and no security engines to update - we manage the CDR engine so you don't have to, and your integration never changes when the engine underneath improves.

High performance

Small documents typically clean in under 3 seconds through one synchronous call (measured July 2026: median 1.9 s). Larger files process asynchronously with a simple polling contract - no timeouts to babysit.

Wide format support

Support for all major document and image formats including Microsoft Office documents (Word, Excel, PowerPoint), PDFs, and common image types (JPG/JPEG, PNG, GIF, BMP, TIF/TIFF). Protect your users regardless of file type.

Common use cases

Protect your organisation wherever documents are handled

File upload portals

Sanitise documents uploaded by customers, partners, or employees before storing them in your systems. Prevent malicious files from entering your environment through web applications. Read our guide to file upload security.

Email attachments

Clean email attachments before they reach users' inboxes. Integrate with your email gateway or mail processing workflow to neutralise threats before they can be opened.

Supply chain security

Secure document exchange between organisations. Ensure that files shared with partners, vendors, or customers are free from malware without affecting document functionality.

Document management systems

Integrate CDR with your document management or content management system to ensure all stored documents are sanitised, protecting your users whenever they access files.

Simple per-document pricing

No credits, no multipliers, no quotes.

One document costs one document's price - no opaque credit systems, no per-megabyte surcharges. Our pay-as-you-go balance is plain pounds, and we publish the whole price card, including the big-volume rates other providers only quote privately. Start in minutes, any time: no sales call required.

How many documents a month?

Drag the slider (or type a number) and see what every plan would cost you. The best-value option is highlighted.

docs/month

All prices exclude VAT. Subscriptions are rolling monthly with no minimum term.

Pay as you go

15p/document

Prepaid credit, £10 minimum top-up

  • No subscription, no commitment
  • Credit valid 12 months
  • Optional auto top-up with your own daily cap
  • Hard stop at zero - never goes into debt
  • 30 requests/minute · 250 MB per document

Starter

£55/month

500 documents · effectively 11p/document

  • 500 documents per month
  • 60 requests/minute
  • 250 MB per document
  • All file formats, full API
  • Cancel, upgrade or downgrade any time

Business

£520/month

8,000 documents · effectively 6.5p/document

  • 8,000 documents per month
  • 180 requests/minute
  • 450 MB per document
  • All file formats, full API
  • Cancel, upgrade or downgrade any time

Volume

£1,250/month

25,000 documents · effectively 5p/document

  • 25,000 documents per month
  • Custom rate limits
  • 450 MB per document
  • All file formats, full API
  • Activated within 1 business day

Enterprise

from 4p/document

50,000+ documents · annual agreement

  • 50,000+ documents per month
  • Service-level agreement
  • Data processing agreement
  • SSO and dedicated support
  • Custom rate and size limits

Billing that behaves

  • The billable unit is one accepted submission. No credit multipliers, no minimum batches, no per-megabyte surcharges.
  • If we fail, you don't pay. A document that fails because of a fault on our side is automatically credited back - you don't need to ask.
  • Hard stops, never surprise bills. When an allowance or credit balance runs out, the API refuses politely and tells you why. We never silently bill for more than you bought.
  • No rollover, no lock-in. Subscriptions are rolling monthly with no minimum term; unused allowance doesn't roll over, and you can cancel, upgrade or downgrade any time.
  • Prepaid credit is valid for 12 months from purchase, and VAT invoices are always available in the account portal. All prices exclude VAT.
  • The full detail lives in our plain-English CDR API terms of service.

What does a document really cost elsewhere? Specialist CDR vendors are typically quote-only - no published prices at all. We publish our whole price card instead - what you see above is what everyone pays. For a tour of the market, read our comparison of CDR tools.

Market comparison checked July 2026.

Support: email support@redeagle.tech - UK business hours, 09:00–17:30 Monday to Friday (excluding bank holidays in England and Wales). On paid plans we aim to respond within four business hours - and on Business and Volume, within two business hours for production-impacting faults, with a named contact included from activation on Volume. On pay-as-you-go, within one business day. Enterprise plans add contractual SLAs with agreed response times.

Ready to protect your documents from cyber threats?

Create your account, add credit or pick a plan, and make your first API call in minutes - no sales call required.

Technical specifications

Designed for easy integration and reliable operation

API features

  • API Type RESTful
  • Authentication OAuth2 client credentials; API keys for integration platforms
  • Processing modes Synchronous and asynchronous
  • Request Format Multipart form
  • Response Format JSON
  • Documentation OpenAPI + interactive reference

Operational details

  • File Size Limit Up to 450 MB per document (plan-dependent)
  • Processing Time Typically under 3 seconds (small documents, measured)
  • Availability 24/7 service; SLA available at Enterprise
  • Data Retention Transient - cleaned files 24 hours, deletable sooner via the API
  • Hosting & processing United Kingdom (Microsoft Azure UK South)

Our CDR API is built on enterprise-grade infrastructure with security and reliability at its core. The service is hosted in Microsoft Azure's UK South region and document sanitisation is processed in the United Kingdom. Submitted content is deleted once processing completes; we never use your files for anything except sanitising them.

Frequently asked questions

Content Disarm and Reconstruction (CDR) is a proactive security technology that assumes all files might contain malicious code. It works by disassembling files, removing potentially harmful elements, and rebuilding clean versions that maintain functionality. Unlike traditional detection-based methods, CDR provides protection against known and unknown (zero-day) threats.

Traditional antivirus software works by detecting known threats using signatures or heuristics. This approach can miss zero-day exploits and sophisticated attacks. CDR takes a fundamentally different approach by assuming all files are potentially dangerous and removing any elements that could be used for malicious purposes, regardless of whether they've been seen before.

Pricing is per document, published in full on this page: pay-as-you-go at 15p per document (prepaid, £10 minimum top-up, no subscription), or monthly sizes from £55 for 500 documents down to an effective 5p per document at volume, with Enterprise pricing from 4p. The billable unit is one accepted submission - and if a document fails to process because of a fault on our side, it is automatically credited back. There are no credit multipliers and no per-megabyte surcharges.

Yes. Pay-as-you-go has no subscription: create an account at account.redeagle.tech, top up from £10, and you're processing documents in minutes at a flat 15p each. Prepaid credit is valid for 12 months, and subscriptions - if you later move to one - are rolling monthly with no minimum term and can be cancelled at any time.

Our CDR API supports all major document and image formats including Microsoft Office files (Word, Excel, PowerPoint), PDFs, and common image types. Specifically, we support DOC, DOCX, XLS, XLSX, XLSM, PPT, PPTX, PDF, JPG, JPEG, PNG, GIF, BMP, TIF, TIFF, and many other variations. Please refer to our technical documentation for a complete list of supported formats.

Integration is a straightforward REST API with OAuth2 client-credentials authentication, plus API keys for integration platforms such as Zapier, Power Automate, n8n and Make. For most documents a single synchronous call returns the cleaned file link in seconds; larger files fall back automatically to a submit-and-poll flow. We provide quickstarts in curl, C#, JavaScript and Python plus a live OpenAPI reference. Our software engineering team can assist with custom integrations.

Our CDR API is designed to preserve document functionality while removing potentially harmful elements. Basic content, formatting, and structure will remain intact. However, active content like macros, scripts, and certain embedded objects will be removed as these are common malware vectors. For most business documents, users will notice no difference in functionality.

The service runs on Microsoft Azure in the UK, and document processing takes place in the United Kingdom. All communication uses HTTPS with TLS 1.2+, and authentication uses OAuth2 client credentials (short-lived bearer tokens) by default, with individually revocable per-platform API keys available for integration platforms. Files are held only transiently: submitted content is deleted once processing completes, cleaned files are retained for 24 hours (you can delete them sooner via the API), and download links are valid for 24 hours. We never use the content of your files for any other purpose, including training models.

Your first API call

Two commands: swap your credentials for a token, then send a document. Small files come back clean in one synchronous round trip.

TOKEN=$(curl -s https://identity.redeagle.tech/connect/token \
  -d grant_type=client_credentials \
  -d client_id="$CDR_CLIENT_ID" \
  -d client_secret="$CDR_CLIENT_SECRET" \
  -d scope=cdr.api | jq -r .access_token)

curl -s "https://api.cdr.redeagle.tech/v1/documents?wait=true" \
  -H "Authorization: Bearer $TOKEN" \
  -F "file=@quarterly-report.pdf"
{
  "status": "completed",
  "outcome": "cleaned",
  "modifications": ["rebuilt"],
  "downloadUrl": "https://..."
}

That's the whole happy path - the response links straight to your cleaned file. Quickstarts in curl, C#, JavaScript and Python, the polling contract for larger files, and the interactive OpenAPI reference all live in the documentation.

View API Documentation

Discovery call

A friendly 15-minute video call with Kat to understand your needs. No preparation needed.

  • Discuss your project
  • Get honest advice
  • No obligation
Kat Korson, Founder of Red Eagle Tech

Kat Korson

Founder & Technical Director

Our team has 10+ years delivering software solutions for growing businesses across the UK.

Send us a message

Your information is secure. See our privacy policy.

Find us