A Single Binary
Just one installable binary. No Java, no Docker, no external libraries to install or maintain. It runs as a system service and starts automatically at boot, so there is no stack to keep patched and nothing to restart by hand.
Files.com is the File Orchestration Platform, and the Agent is how your on-premise storage joins it. Install the Agent on a server inside your network and it makes one outbound connection to Files.com. Your file servers and NAS start moving files to the cloud with no VPN, no inbound firewall rules, and no host in a DMZ.
Some of your most important data still lives on the ground. A plant-floor file server, a legacy NAS array, a regional Windows cluster, a system-of-record repository. None of it was built to talk to a cloud platform, and the usual ways to bridge it are all painful. A VPN tunnel takes weeks of network config and approvals. A firewall pinhole is a standing vulnerability you now have to defend. A homegrown script breaks the next time something updates, usually at the worst time.
“Our previous solution was on-prem, so we had to allow a third-party vendor onto our entire network. With Files.com that isn't the case — everything is handled at the cloud-based level, whether it's inbound or outbound.”

The whole point of the Agent is that it connects out, never in. That single design choice is what lets you skip the VPN, the firewall changes, and the perimeter gateway entirely.
The Agent dials out to Files.com. It never opens an inbound port and never waits for a connection from the outside. Your network and security team does not have to open inbound rules, set up NAT traversal, or put a host in a DMZ.
Because the connection is outbound-only, there is nothing to expose and nothing to ask your network team for. The Agent connects the day you install it, not after the change-management board approves a firewall rule.
Legacy MFT products need a hardened gateway host in your perimeter network to accept inbound connections. The Agent has nothing to put in a DMZ. There is no gateway to provision, patch, and monitor at the edge, so that is one less attack surface and one less box on the patch list.
End users and partners never touch the Agent directly. Every request is proxied through Files.com, so your internal systems stay hidden behind the firewall and protected.
If the host can reach the storage, the Agent can expose it to Files.com. That storage never has to face the public internet.
Point the Agent at an SMB, NFS, or CIFS share, or at directly-attached storage. If the volume is mounted on the host, the Agent can expose it to Files.com.
Reach an S3 bucket that is only routable from inside your firewall. The Agent proxies the traffic so Files.com can read and write it like any other backend.
Connect an Azure Blob container that lives on a private network segment, with no inbound rules and no public endpoint exposed.
Route to an SFTP or FTP server that only listens inside your network. The Agent reaches it on Files.com’s behalf, so partners connect through Files.com instead.
Plant-floor file servers, regional Windows clusters, legacy archives. Any local path on the host becomes a folder Files.com can orchestrate.
Deploy the Agent at a client site, a colo, or a partner’s datacenter. It makes the same single outbound connection from their network, so files start moving without asking anyone’s IT team to open a port.
Once connected, your on-premise storage behaves like any cloud backend on Files.com. Same orchestration, same sharing, same automation.
Agent-backed paths show up as Remote Servers inside Files.com. When users browse your Files.com site, they see and work with your real on-premise files, no copying required.
Set up scheduled sync to copy files between your on-premise storage and the cloud on rules you define. Use it for backups, distribution, or keeping a local copy of sensitive data.
A legacy local share reached through the Agent can speak SFTP, FTPS, WebDAV, or HTTPS to your partners and clients, with no middleware to install. The old server keeps running as-is, and partners get the modern protocol they asked for.
The Agent splits files into parts and transfers them in parallel by default, so large files move at full speed.
The Agent is on the Power tier and above. Enterprise includes as many Agents as you need, plus High Availability. See what each plan includes on the pricing page.
Just one installable binary. No Java, no Docker, no external libraries to install or maintain. It runs as a system service and starts automatically at boot, so there is no stack to keep patched and nothing to restart by hand.
The Agent runs on Windows, Linux, and macOS with minimal CPU and memory. A $50 Raspberry Pi at the edge runs the Agent as comfortably as a full enterprise server.
Each Agent is constrained to a defined root folder, and you set its permission mode to Read+Write, Read-only, or Write-only. That caps what Files.com can reach through it, so the blast radius is whatever you scoped and nothing more.
Every Agent action is logged both locally on the host and in Files.com’s centralized audit log, and is exportable to your SIEM for full visibility.
Across the customers Files.com has profiled, the Agent is the piece that puts an on-premises system on the far side of a hosted exchange. These are the jobs it shows up in most.
The on-premises HR or payroll system writes its export to a local folder, and the Agent carries it to the folder that encrypts it and delivers it to the provider before the cutoff. Payroll and benefits feeds run this way at most customers with the system still in the building.
Partner files arrive on the hosted endpoint and the Agent lands them on the server or share the warehouse loader already reads, so partner data feeds reach an on-premises pipeline with nothing inbound opened.
An Agent on the store’s back-office server pushes the nightly POS and accounting export to head office over an outbound connection, which is how multi-site collection works at chains, restaurant groups and hotel portfolios without a hole at hundreds of sites.
Files pulled from custodians, banks and administrators are decrypted and renamed on the platform, then written by the Agent to the on-premises landing folder the portfolio or treasury batch job already polls, so counterparty exchange changes nothing downstream.
Database dumps and appliance backups on a local disk go off-site through the Agent on a schedule, into hosted storage or the company’s own bucket, so an out-of-band copy exists the night the job runs.
Purchase orders and ship notices from trading partners land on the hosted hub and the Agent delivers them into the ERP’s import folder inside the network, while outbound invoices travel the other way, which is how partner EDI reaches an ERP that will never be internet-facing.
The boundary the company keeps closed, and the four ways customers move files across it without opening anything.
Partners connect to a hosted SFTP endpoint on your domain, and the Agent carries each arrival onto the Windows share or NAS inside the network, so the internet-facing server in the DMZ is retired and nothing inbound is opened.
Output from a cloud ERP reaches systems on a segmented plant or lab network through an Agent that only calls out, so corporate IT delivers files into OT without the firewall exception the security team refused.
An Agent on each side of an isolated lab and the corporate network moves files between them through Files.com as the meeting point. No VPN, no trust relationship, and a log of everything that crossed.
S3 analytics output or a partner’s bucket stays mirrored to an on-premises server for local analysis, on a schedule, without a pull script running under a privileged account.
Start a 7-day free trial, install the Agent on a host inside your network, and watch your on-premise files show up in Files.com over a single outbound connection. No VPN, no firewall changes, no open ports.
No credit card required • Free for 7 days • Live in minutes