Home Solutions Votiro
Zero Trust CDR · DDR · Positive Selection · Real-time
Votiro logo

Instead of hunting for malware,
rebuild the file.

Votiro turns the usual CDR approach around. It skips the search for the “bad” and builds a new copy only from elements that clearly match the format specification. Active code, exploits and macro viruses never make it into the new file. It takes milliseconds.

2012
founded. A pioneer of positive-selection CDR technology.
130+
supported file types: Office, PDF, images, archives, CAD.
SOC 2 II
plus ISO 27001. Compliance with GDPR, HIPAA and PCI DSS.
Gartner
mentioned in the Hype Cycle for Email Security and Workload Protection.
Positive selection

Votiro takes the file apart and puts back only the parts described in the specification.

INPUT · invoice.docx
Document with macros + 0-day exploit
XML body Macros (VBA) Embedded EXE Remote template DDE field External JS Images Fonts
Contains active components, any of which could carry a 0-day.
⇢
OUTPUT · invoice-safe.docx
Same document, no active code
XML body ✓ Tables ✓ Images ✓ Fonts ✓ Headers/footers ✓ Hyperlinks ✓
The file looks and works just like the original. It contains only elements that follow the Office Open XML specification.
~200 ms
typical latency for disarming Word/Excel/PDF.
0 FP
positive selection doesn’t block anything, so there are no false positives.
0-day
protection doesn’t depend on signatures: an unknown exploit won’t get through.
Comparing approaches

AV. Sandbox. Votiro.

Method
Speed
0-day
Antivirus (signatures)
Lookup in a database of known threats
ms
No: it only recognizes known malware
Sandbox detonation
The file is detonated in a virtual machine
30-300 sec
Partially: evasion techniques get around it
Votiro positive-selection
Building a new file from explicitly safe elements
~200 ms
Fully: unknown code doesn’t make it into the output
Votiro DDR

DDR also classifies sensitive data in files as they pass through.

DDR finds personal data, medical records, card data, tax IDs and your organization’s own templates in files. It sends events to SIEM and DLP with context and a risk level.

  • 40+ data types out of the box (PII, PHI, PCI, IP).
  • Custom templates: Uzbek tax IDs (INN), contract numbers, internal codes.
  • Real-time classification during CDR processing, with no separate pass.
  • Integration with Splunk, Sentinel, Microsoft Purview and Forcepoint DLP.
votiro · ddr-event
file: invoice_q4_clients.xlsx
source: incoming · email · ceo@…
cdr_status: sanitized · OK
detections:
- type: PII · full_name, count: 138
- type: PII · passport_uz, count: 47
- type: PCI · card_pan, count: 12
- type: custom · inn_uz, count: 84
risk_score: 88 / high
forwarded_to: Splunk · Forcepoint DLP
Integration points

Votiro cleans files wherever they cross the perimeter.

Email · M365 / Exchange

API mode for Microsoft 365 (Graph) or SMTP relay for Exchange/PineApp/Barracuda.

Web upload & Web forms

Your frontend calls the REST API, and a customer’s file is sanitized before it is saved to your system.

File shares · SMB / NFS

Sanitization of files in shared folders and on USB drives via transfer stations.

ICAP & web proxy

Integration with Squid, McAfee Web Gateway and Symantec Proxy via the ICAP protocol.

SaaS & collaboration

SharePoint, OneDrive, Google Drive, Box, Dropbox: API sanitization of uploaded files.

Air-gap transfer

Kiosk mode for physically moving files between closed and open segments.

CYBER BOOST × Votiro

We’ll set up CDR in 2 weeks.

We supply Votiro to banks, the public sector and large corporations in Uzbekistan. We integrate it with email gateways, web applications and SharePoint. A local SaaS mode keeps data in the country.

10-14 days
typical time to integrate with an email gateway and web forms.
on-prem
Kubernetes deployment for the public sector and high-security organizations.
RU/UZ
certified engineers for Votiro Cloud and CDR integrations.
L1–L3
local support and escalation to Votiro R&D.
FAQ

Frequently asked questions about Votiro.

What is Content Disarm & Reconstruction (CDR)?
CDR is a way to “disarm” a file without searching it for malicious code. It breaks the file into structural elements, removes the extra and active ones and builds a new, safe copy from the “clean” elements. The method doesn’t rely on signatures and works against 0-day threats.
How is positive selection different from regular CDR?
Most CDR tools use “negative selection”: they try to cut out the “bad”. Votiro does the opposite. It builds a new file only from elements that clearly match the format specification. Anything not confirmed as safe is left out. This protects against unknown threats without false positives.
Do files still work after cleaning?
Yes. After cleaning, Word, Excel, PDF and PowerPoint files, images and archives look and work just like the originals. Excel formulas, Word fields and PDF annotations are all kept. Only active elements (macros, JS, embedded executables) are removed.
What is Votiro DDR?
DDR stands for Data Detection & Response. It classifies file content on the fly: personal data, medical records, card data, tax IDs, templates. All events go to SIEM and DLP with a risk level and context. It runs in parallel with CDR.
Where is Votiro deployed?
A cloud API (SaaS) for Microsoft 365, an on-prem API for integration with email gateways, file shares and web upload forms, and ICAP for proxy servers and web filters. On-prem installations can run on Kubernetes.
Request · Votiro

Free 30-day CDR PoC.

Tell us what you need to protect: email, web forms, file shares, SharePoint or an air-gapped government network. We’ll prepare a PoC plan.