Skip to main content

Connect On-Premise Storage Without Opening A Port

Files.com is the File Orchestration Platform, and the Agent is how your on-premise storage joins it. Install the Agent on a server inside your network and it makes one outbound connection to Files.com. Your file servers and NAS start moving files to the cloud with no VPN, no inbound firewall rules, and no host in a DMZ.

Outbound-only, no inbound ports
No VPN or firewall changes
Installs in five minutes
Files.com On-Premise Agent

On-Premise Storage That Finally Plays Nice With The Cloud

Some of your most important data still lives on the ground. A plant-floor file server, a legacy NAS array, a regional Windows cluster, a system-of-record repository. None of it was built to talk to a cloud platform, and the usual ways to bridge it are all painful. A VPN tunnel takes weeks of network config and approvals. A firewall pinhole is a standing vulnerability you now have to defend. A homegrown script breaks the next time something updates, usually at the worst time.

The Files.com Agent removes that work. You install it on a host inside your network, it makes one outbound connection to Files.com, and your on-premise storage starts moving files. There is no network team to negotiate with, no VPN, and no inbound ports. What used to be its own IT project becomes a five-minute install.

“Our previous solution was on-prem, so we had to allow a third-party vendor onto our entire network. With Files.com that isn't the case — everything is handled at the cloud-based level, whether it's inbound or outbound.”

Spirit Airlines
Nelson Miranda, Sr. Systems EngineerSpirit Airlines

How The Agent Stays Out Of Your Firewall

The whole point of the Agent is that it connects out, never in. That single design choice is what lets you skip the VPN, the firewall changes, and the perimeter gateway entirely.

Outbound-Only Connection

The Agent dials out to Files.com. It never opens an inbound port and never waits for a connection from the outside. Your network and security team does not have to open inbound rules, set up NAT traversal, or put a host in a DMZ.

No VPN, No Firewall Changes

Because the connection is outbound-only, there is nothing to expose and nothing to ask your network team for. The Agent connects the day you install it, not after the change-management board approves a firewall rule.

No DMZ Box To Stand Up

Legacy MFT products need a hardened gateway host in your perimeter network to accept inbound connections. The Agent has nothing to put in a DMZ. There is no gateway to provision, patch, and monitor at the edge, so that is one less attack surface and one less box on the patch list.

Your Systems Stay Invisible

End users and partners never touch the Agent directly. Every request is proxied through Files.com, so your internal systems stay hidden behind the firewall and protected.

What You Can Connect

If the host can reach the storage, the Agent can expose it to Files.com. That storage never has to face the public internet.

NAS And SAN Arrays

Point the Agent at an SMB, NFS, or CIFS share, or at directly-attached storage. If the volume is mounted on the host, the Agent can expose it to Files.com.

Amazon S3 logo

Amazon S3

Reach an S3 bucket that is only routable from inside your firewall. The Agent proxies the traffic so Files.com can read and write it like any other backend.

Microsoft Azure Blob Storage logo

Azure Blob Storage

Connect an Azure Blob container that lives on a private network segment, with no inbound rules and no public endpoint exposed.

Internal SFTP And FTP Servers

Route to an SFTP or FTP server that only listens inside your network. The Agent reaches it on Files.com’s behalf, so partners connect through Files.com instead.

Local Drives And File Servers

Plant-floor file servers, regional Windows clusters, legacy archives. Any local path on the host becomes a folder Files.com can orchestrate.

Client Sites You Don’t Control

Deploy the Agent at a client site, a colo, or a partner’s datacenter. It makes the same single outbound connection from their network, so files start moving without asking anyone’s IT team to open a port.

On-Prem Folders Inherit The Whole Platform

Once connected, your on-premise storage behaves like any cloud backend on Files.com. Same orchestration, same sharing, same automation.

Mount On-Prem Folders Live

Agent-backed paths show up as Remote Servers inside Files.com. When users browse your Files.com site, they see and work with your real on-premise files, no copying required.

Sync On A Schedule You Control

Set up scheduled sync to copy files between your on-premise storage and the cloud on rules you define. Use it for backups, distribution, or keeping a local copy of sensitive data.

Speak Modern Protocols To Partners

A legacy local share reached through the Agent can speak SFTP, FTPS, WebDAV, or HTTPS to your partners and clients, with no middleware to install. The old server keeps running as-is, and partners get the modern protocol they asked for.

Parallel, Chunked Transfers

The Agent splits files into parts and transfers them in parallel by default, so large files move at full speed.

Built To Be Easy To Run

The Agent is on the Power tier and above. Enterprise includes as many Agents as you need, plus High Availability. See what each plan includes on the pricing page.

A Single Binary

Just one installable binary. No Java, no Docker, no external libraries to install or maintain. It runs as a system service and starts automatically at boot, so there is no stack to keep patched and nothing to restart by hand.

Runs On Almost Anything

The Agent runs on Windows, Linux, and macOS with minimal CPU and memory. A $50 Raspberry Pi at the edge runs the Agent as comfortably as a full enterprise server.

Least-Privilege By Design

Each Agent is constrained to a defined root folder, and you set its permission mode to Read+Write, Read-only, or Write-only. That caps what Files.com can reach through it, so the blast radius is whatever you scoped and nothing more.

Logged In Two Places

Every Agent action is logged both locally on the host and in Files.com’s centralized audit log, and is exportable to your SIEM for full visibility.

The Jobs The Agent Is Running Right Now

Across the customers Files.com has profiled, the Agent is the piece that puts an on-premises system on the far side of a hosted exchange. These are the jobs it shows up in most.

Payroll Exports Off The HR Server

The on-premises HR or payroll system writes its export to a local folder, and the Agent carries it to the folder that encrypts it and delivers it to the provider before the cutoff. Payroll and benefits feeds run this way at most customers with the system still in the building.

Vendor Feeds Into The On-Premises Pipeline

Partner files arrive on the hosted endpoint and the Agent lands them on the server or share the warehouse loader already reads, so partner data feeds reach an on-premises pipeline with nothing inbound opened.

Store Files Pushed From The Back Office

An Agent on the store’s back-office server pushes the nightly POS and accounting export to head office over an outbound connection, which is how multi-site collection works at chains, restaurant groups and hotel portfolios without a hole at hundreds of sites.

Custodian Files Into The Folder The Batch Job Watches

Files pulled from custodians, banks and administrators are decrypted and renamed on the platform, then written by the Agent to the on-premises landing folder the portfolio or treasury batch job already polls, so counterparty exchange changes nothing downstream.

Backups Off The Box That Made Them

Database dumps and appliance backups on a local disk go off-site through the Agent on a schedule, into hosted storage or the company’s own bucket, so an out-of-band copy exists the night the job runs.

EDI Documents Into The On-Premises ERP

Purchase orders and ship notices from trading partners land on the hosted hub and the Agent delivers them into the ERP’s import folder inside the network, while outbound invoices travel the other way, which is how partner EDI reaches an ERP that will never be internet-facing.

How Teams Cross The Firewall With It

The boundary the company keeps closed, and the four ways customers move files across it without opening anything.

Partner Uploads That Land On The Internal Share

Partners connect to a hosted SFTP endpoint on your domain, and the Agent carries each arrival onto the Windows share or NAS inside the network, so the internet-facing server in the DMZ is retired and nothing inbound is opened.

Cloud ERP Files Into The Plant

Output from a cloud ERP reaches systems on a segmented plant or lab network through an Agent that only calls out, so corporate IT delivers files into OT without the firewall exception the security team refused.

Two Networks That Will Never Be Joined

An Agent on each side of an isolated lab and the corporate network moves files between them through Files.com as the meeting point. No VPN, no trust relationship, and a log of everything that crossed.

The On-Premises Copy Of A Bucket

S3 analytics output or a partner’s bucket stays mirrored to an on-premises server for local analysis, on a schedule, without a pull script running under a privileged account.

On-Premise Agent Questions

The Files.com Agent never opens an inbound port. It makes a single outbound-only connection to Files.com, so your network team does not have to open inbound rules, set up NAT traversal, or place a host in a DMZ.

The Files.com Agent needs no VPN and no firewall changes. Because its connection is outbound-only, there is nothing to expose: no VPN tunnel, no firewall pinhole, and no DMZ gateway host to provision, patch, and monitor at the edge.

The Files.com Agent connects SMB, NFS, and CIFS shares, directly-attached storage, internal S3 and Azure Blob endpoints, internal SFTP and FTP servers, and any local path the host can reach. None of that storage ever has to face the public internet.

Partners reach your on-premise storage through Files.com, never through the Agent directly. A local share reached through the Agent can speak SFTP, FTPS, WebDAV, or HTTPS to partners and clients with no middleware to install, and your internal systems stay hidden behind the firewall.

The Files.com Agent runs on Windows, Linux, and macOS as a single native binary with minimal CPU and memory, installed as a system service so it survives reboots. It runs on everything from a $50 Raspberry Pi to a full enterprise server.

The Files.com Agent supports both live mounting and scheduled sync. Mount on-premise folders so Files.com reads and writes them in real time, or sync them to a destination on a schedule you control. Transfers are chunked and run in parallel by default, so large files move at full speed.

Partners upload to your Files.com site over SFTP, and the Files.com Agent, running on a machine inside your network, writes each arrival to the Windows share path you choose over its outbound-only connection. Partners never see the network, no inbound rule is opened, and every file is logged in both places.

Yes. Run a Files.com Agent on each network. Each Agent connects outbound to Files.com and syncs its folder with a folder on the site, so files move between the two networks through Files.com as the meeting point, with no direct path between them and an audit record of every transfer.

Run the Files.com Agent on a host inside the plant network. It calls out to Files.com and pulls the files corporate systems dropped there onto the plant paths, so nothing on the plant side accepts a connection and the segmentation policy stays as written.

Yes. The cloud system delivers to your Files.com site, or Files.com pulls from it, and the Agent writes each arriving file to the server path you choose from inside the network over its outbound-only connection. Nothing inbound is opened, and the file lands where the existing import job already looks. The same path in reverse carries the system’s exports out to a partner, a bank or a payroll provider.

No. The Files.com Agent runs on any Windows, Linux or macOS host that can reach the storage over the local network, so it can sit on the file server itself, on a utility host beside it, or on a store or plant machine that reaches the share. One single binary, provisioned from the web app, with every transfer logged on both sides.

Connect Your On-Premise Storage In Minutes

Start a 7-day free trial, install the Agent on a host inside your network, and watch your on-premise files show up in Files.com over a single outbound connection. No VPN, no firewall changes, no open ports.

No credit card required • Free for 7 days • Live in minutes