OPSWAT is positioning its Deep CDR technology as a definitive defense against evolving file-borne threats by leveraging a prevention-first security architecture. The company announced that the independent testing lab AV-Comparatives recorded a 100% sanitization rate for the technology across more than 300 test cases. This result marks the third time an independent laboratory—joining SE Labs and SecureIQLab—has reported a 100% protection outcome for the technology. For enterprise leaders managing critical infrastructure, this validation attempts to demonstrate that proactive reconstruction can outperform traditional detection-based security models.
AV-Comparatives Validates Deep CDR Sanitization Effectiveness
The AV-Comparatives evaluation focused on the ability of Deep CDR to neutralize diverse attack vectors while maintaining the functional integrity of the files. The testing protocol spanned approximately 50 different file formats and included more than 300 specific test cases. These scenarios targeted high-risk elements such as AI-assisted malicious content, zero-day exploits, malicious macros, embedded executables, and nested archives. According to the announcement, the technology passed every case under the tested configuration. Crucially, the testing also assessed file fidelity, confirming that the reconstruction process preserved the original layout, formatting, tables, and formulas. Thomas Uhlemann, a Cybersecurity Evangelist at AV-Comparatives, noted that the test operates on a strict pass-or-fail basis, with no provision for partial credit. This rigorous testing aims to prove that the technology can strip out evasive threats, including steganography and malformed archives, without rendering the files unusable for end-users.
Integrating Prevention-First Security into Enterprise Workflows
OPSWAT is marketing Deep CDR as a core component of its MetaDefender platform, designed to address the limitations of detection-centric security. While traditional methods rely on recognizing a threat to stop it, the company’s approach treats every file as untrusted by default. The technology disarms and rebuilds files in milliseconds, removing embedded or out-of-policy content. This capability is intended to support over 200 file types across various enterprise entry points, including email, web, file-transfer, and endpoint workflows. To accommodate diverse digital infrastructure requirements, the platform allows for deployment in on-premises, cloud, or air-gapped environments. This flexibility is particularly relevant for critical infrastructure protection (CIP) where cross-domain security is required. By focusing on the removal of risky content—whether the threat is known, unknown, or AI-generated—OPSWAT is attempting to provide a layer of resilience that does not depend on the immediate identification of a specific malware signature or an AI-adapted payload.
Key Takeaways
- AV-Comparatives recorded a 100% sanitization rate for Deep CDR across 300-plus cases and roughly 50 file formats.
- Deep CDR is the third technology to receive 100% protection results from independent labs, following SE Labs and SecureIQLab.
- The MetaDefender platform supports over 200 file types and can be deployed in cloud, on-premises, or air-gapped environments.
TechInsyte's Take
In our view, the emphasis on "prevention-first" rather than "detection-first" signals a necessary shift in how critical infrastructure must approach file security. As AI-assisted payloads and zero-day exploits become more sophisticated, the window for effective detection is narrowing. OPSWAT is betting that the ability to reconstruct a file from scratch is a more reliable defense than attempting to identify every possible variation of a malicious macro or embedded executable. If these 100% sanitization results hold across broader, real-world deployments, it suggests that the industry may move away from signature-heavy models toward more deterministic, reconstruction-based security architectures to manage high-risk data transfers.
Questions & Answers
How does Deep CDR maintain file usability during the sanitization process?
The technology disarms and rebuilds files in milliseconds, specifically designed to remove embedded and out-of-policy content while preserving the original layout, formatting, tables, and formulas.
What specific types of advanced threats were included in the AV-Comparatives testing?
The test included AI-assisted malicious content, zero-day exploits, malicious macros, embedded executables, nested archives, and other evasive file-borne attacks.
In what environments can the MetaDefender platform be deployed?
The platform can be deployed across on-premises, cloud, and air-gapped environments, supporting IT, OT, and cross-domain workflows.
Why is the distinction between detection and prevention significant for C-suite leaders?
Detection-based security requires recognizing a threat to stop it, whereas OPSWAT’s prevention-first approach removes risky content regardless of whether the threat is known, unknown, or AI-generated.
Source: Businesswire