OPSWAT License provides access to cybersecurity products designed to protect critical files, removable media, endpoints, storage platforms, network traffic, and IT/OT environments from malware and other file-borne threats. Through the MetaDefender portfolio, organizations can combine multiscanning, Deep CDR, sandboxing, data loss prevention, vulnerability assessment, and secure file-transfer technologies according to their security architecture.
Quick Benefits
- Advanced protection against file-borne threats
- Multiscanning with multiple anti-malware engines
- Deep Content Disarm and Reconstruction
- Adaptive sandboxing for suspicious files
- Proactive data loss prevention capabilities
- Secure removable-media inspection
- Protection for air-gapped and isolated networks
- Secure IT and OT file-transfer workflows
- ICAP integration with WAFs, proxies, and gateways

OPSWAT License At a Glance
What it is: Enterprise cybersecurity licensing portfolio
Vendor: OPSWAT
Primary role: Prevent malicious, vulnerable, or unauthorized files from entering critical systems and networks
Security areas: File security, malware prevention, removable media, secure file transfer, storage security, endpoint protection, OT security, and network file inspection
Core technologies: Metascan Multiscanning, Deep CDR, Adaptive Sandbox, Proactive DLP, threat intelligence, and vulnerability assessment
Deployment models: On-premises, cloud, hybrid, isolated, and air-gapped environments
Activation models: Online and offline activation depending on product and deployment
Management: Product-specific consoles and My OPSWAT Central Management for supported products
Typical environments: Critical infrastructure, government, defense, manufacturing, energy, finance, healthcare, enterprise IT, and OT networks
License Overview
An OPSWAT License gives organizations the right to deploy selected OPSWAT security technologies according to the product, deployment architecture, and protection level required.
There is no single universal licensing metric across the complete OPSWAT portfolio. MetaDefender Core, Kiosk, ICAP Server, Managed File Transfer, Endpoint, and other products are deployed differently and therefore have different ordering considerations.
MetaDefender Core, for example, identifies each installation through a unique Deployment ID. The activated license determines which components and security engines are available to that instance. A Core deployment can include multiple anti-malware engines and additional technologies such as Deep CDR, Adaptive Sandbox, Proactive DLP, File-Based Vulnerability Assessment, threat intelligence, and other modules depending on the purchased configuration.
Other OPSWAT solutions may be licensed according to deployment count, protected systems, required capacity, platform, or associated Core infrastructure. This means an OPSWAT purchase should be sized from the actual security workflow rather than simply selecting a product name.
How OPSWAT Licensing Works
OPSWAT licensing begins by identifying where files enter, move through, or remain inside the organization. The required products are then mapped to those security points. A company protecting file uploads in web applications may deploy MetaDefender Core behind an API workflow or use MetaDefender ICAP Server with an ICAP-enabled WAF, proxy, load balancer, or gateway. An isolated facility receiving files through USB devices may instead require MetaDefender Kiosk, while organizations transferring files between IT and OT environments may use MetaDefender Managed File Transfer.
Once the product architecture is defined, the license is configured according to the deployment, security technologies, and capacity requirements. Supported products can use online activation, while offline licensing is available for environments where systems cannot communicate directly with OPSWAT activation services. This offline capability is particularly important in restricted, classified, and air-gapped networks.
OPSWAT Security Portfolio Overview
| OPSWAT Product | Primary Role |
|---|---|
| MetaDefender Core | Central file scanning and advanced threat prevention engine for application and security integrations |
| MetaDefender Kiosk | Secure inspection and sanitization of removable media before files enter critical networks |
| MetaDefender Managed File Transfer | Secure, policy-controlled file transfer across IT, OT, cloud, and segmented environments |
| MetaDefender ICAP Server | Integrates file security with ICAP-enabled WAFs, proxies, gateways, load balancers, and MFT systems |
| MetaDefender Storage Security | Protects files stored in cloud, hybrid, and on-premises storage platforms |
| MetaDefender Endpoint | Controls removable-media access and protects endpoints from peripheral and file-based threats |
| MetaDefender Email Security | Adds advanced file inspection and threat prevention to email security workflows |
| MetaDefender Cloud | Cloud-delivered file analysis, reputation, and security APIs |
| MetaDefender Industrial Firewall | Provides industrial network segmentation, inspection, and threat prevention for OT and cyber-physical systems |
| MetaDefender Drive | Portable inspection capability for checking endpoint systems and files before network access |
These products can operate independently in some architectures, while others are designed to work closely with MetaDefender Core or additional OPSWAT components.
Licensing Options and Models
| Licensing Option | Description | Suitable For |
|---|---|---|
| Deployment-Based Licensing | License associated with a specific installed product instance or deployment identity | MetaDefender Core and similar server-based products |
| Security Engine Packages | Provides selected combinations of anti-malware scanning engines | Organizations requiring higher malware detection coverage |
| Feature and Module Licensing | Adds technologies such as Deep CDR, Sandbox, DLP, vulnerability assessment, or other security modules | Environments requiring advanced file inspection |
| Platform-Specific Licensing | License selected according to supported operating system or deployment platform | Server-based OPSWAT products |
| Appliance / Kiosk Licensing | Licensing associated with physical or virtual security inspection deployments | Removable-media and controlled-entry environments |
| Integrated Solution Licensing | Combines multiple OPSWAT components in a larger workflow | IT/OT, air-gapped, and critical infrastructure environments |
| Centralized License Management | Allows supported OPSWAT licenses to be monitored and administered centrally | Organizations operating multiple OPSWAT instances |
The correct model depends heavily on the selected product. OPSWAT configurations should therefore be built around the required workflow, not a generic license quantity.
Features and Benefits
The key advantage of OPSWAT is its focus on files as a major attack vector. Instead of relying on a single anti-malware engine, MetaDefender can analyze files through multiple security technologies before they are accepted into a protected environment.
Metascan Multiscanning allows organizations to inspect files using multiple anti-malware engines. This increases detection coverage and reduces dependence on the detection logic of a single vendor.
Deep CDR takes a different approach. Rather than attempting only to determine whether a file is malicious, it can reconstruct supported documents by removing potentially dangerous active content while preserving usable business information.
Adaptive Sandbox provides deeper behavioral analysis for suspicious and evasive files, while Proactive DLP can help identify and control sensitive information.
These technologies can be applied at different points: a USB inspection kiosk, an application upload interface, an MFT workflow, a storage platform, a network gateway, or an endpoint.
This architecture is particularly relevant for critical infrastructure where allowing an unverified file into a protected environment may represent a significant operational risk.
Compatibility and Requirements
Before selecting an OPSWAT License, organizations should document both the security workflow and technical environment.
Important considerations include:
- Required OPSWAT product
- Number of deployments or locations
- Operating system and platform
- Average and peak file-processing volume
- Maximum file sizes
- Number of anti-malware engines required
- Deep CDR requirements
- Adaptive Sandbox requirements
- Proactive DLP requirements
- Storage or transfer architecture
- Internet-connected or offline environment
Activation and Deployment
OPSWAT supports both online and offline activation for several products. In an internet-connected deployment, the activation key can be used by the product to communicate with OPSWAT licensing services and retrieve the applicable entitlement. For restricted environments, offline activation allows administrators to use the product’s Deployment ID and activation key to obtain a license file from another internet-connected system and then transfer that file into the protected environment.
A typical deployment process includes:
- Confirm the OPSWAT products and required modules
- Size processing and deployment requirements
- Install the required components
- Generate or confirm deployment identifiers
- Activate licenses online or offline
- Install licensed engines and security modules
- Configure file-processing workflows
- Test security policies before production rollout
Pricing and Quote Process
Pricing for an OPSWAT License depends on the selected product, deployment count, security engines, optional modules, processing requirements, architecture, and support term.
Before requesting a quote, define:
- Required OPSWAT products
- Number of sites and deployments
- MetaDefender Core level or configuration
- Number of anti-malware engines
- Required security add-ons
- Estimated file volume
- Maximum file size
- Kiosk or MFT requirements
- ICAP integration requirements
For example, a single MetaDefender Core used through an application API will require a very different configuration from a multi-site critical infrastructure project involving Kiosk, Core, MFT, endpoint controls, and offline activation. Accurate sizing helps avoid both unnecessary capacity and under-licensed security workflows.
OPSWAT pricing depends on your product family, MetaDefender modules, deployment model, file security requirements, license term, and support needs.
