Skip to main content

Aimbridge Closed Its UK Data Center After Files.com Connected Oracle Opera Where MoveIt Couldn't

The final workload depended on legacy ciphers dictated by a vendor system Aimbridge did not control.
Aimbridge HospitalityFiles.com

Aimbridge Hospitality runs hotels for the people who own them. It is the largest third-party hotel management company in the world, operating more than 1,500 properties across 20 countries and more than 80 brands. After Aimbridge migrated all of its servers into Azure, one workload kept its UK data center open: a traditional SFTP server receiving nightly files from Oracle Opera.

Running other people's hotels means running other vendors' systems. The point-of-sale platforms inside those properties answer to their vendors' roadmaps, not to Aimbridge, and yet the revenue they record every night has to land in Aimbridge's own ERP, Business Central, where the owners' books are kept. At hotel properties across Europe and Latin America, that system is Oracle's Opera point-of-sale. Every night, each property's Opera instance opens an SFTP connection, drops its revenue and transaction files, and Aimbridge's applications carry them into the ERP. Aimbridge controls one end of that connection. Oracle controls the other.

The Last Server in the UK Data Center

The traditional SFTP server, hosted and managed by a third party, remained in Aimbridge's UK data center solely to receive the nightly Opera file drops. Until that endpoint moved, the data center could not close. An organization that had finished its cloud migration everywhere else was keeping a data center arrangement alive for a single file feed.

The feed could not simply be pointed somewhere new, because Oracle Opera dictated the terms of the connection, including legacy cipher suites that modern platforms had stopped offering. The vendor set the cipher suite, and none of Aimbridge's modern endpoints would speak it. The files themselves are small, a night's revenue and transactions per property. The problem was never volume. It was negotiation, and the revenue picture in Business Central for two regions depended on the negotiation succeeding every night.

MoveIt and Azure Blob SFTP Failed the Same Connection

Aimbridge already owned a managed file transfer platform: MoveIt. As part of the hardening that followed MoveIt's widely publicized security incidents, the product's legacy cipher suites were removed, and Aimbridge had no granular control over which ciphers or protocols MoveIt would negotiate. The settings simply were not exposed. Opera could not connect.

They got rid of all old ciphers, which makes sense. But people like Oracle will just not update their intake systems, right? So we still need those old ciphers.
Imtiaz Muhammad, Director of IT Operations, Aimbridge Hospitality

Azure Blob SFTP was the obvious second answer, since every other workload had already landed in Azure. Opera could not connect to it either.

That left the fallback every IT team knows: stand up your own SFTP server and configure it to speak whatever the vendor needs. Aimbridge refused. A self-managed server meant opening a firewall path to the internet and owning the maintenance of deliberately old cipher suites, indefinitely, inside an IT organization that is intentionally lean and whose standing policy is to buy SaaS rather than build and maintain its own infrastructure.

So the requirement wrote itself: a SaaS endpoint with no infrastructure for Aimbridge to own, granular control over exactly which ciphers and protocols that endpoint negotiates, and a fixed address the European side could allowlist.

We are moving to a SaaS solution where we can tell Oracle, 'Here you go. Use it. Connect to this and start dropping your files here.
Imtiaz Muhammad, Director of IT Operations, Aimbridge Hospitality

Aimbridge selected Files.com to be that endpoint.

An Endpoint Configured to Oracle's Terms

Files.com exposes granular control over the cipher suites and protocols its SFTP endpoint will negotiate, so Aimbridge configured the endpoint to meet Opera exactly where it was. No ticket to Oracle, no waiting for a vendor to modernize an intake system it had shown no interest in modernizing.

Onboarding the vendor took a credential scoped to the feed's subdirectory and a fixed address under Aimbridge's own name, using Files.com's Custom Domain with static IP addressing. The European network side could allowlist it, and Oracle only had to connect and start dropping files.

The migration ran in parallel. The old server kept receiving files while the Files.com endpoint was validated, and only then did the feed cut over. Downstream, nothing changed: Aimbridge's applications collect the files and process them into Business Central exactly as before. The Opera feed was the last workload to leave the UK data center, and once it cut over, nothing was left to keep the facility open.

The Data Center Closed and the Files Kept Arriving

With the cutover validated, Aimbridge retired the third-party-hosted SFTP server and finished the exit it had been blocked on.

  • Oracle Opera connects to Files.com where both MoveIt and Azure Blob SFTP had failed, and the nightly drops have run ever since, with nothing changed on Oracle's side.
  • The UK data center closed. The Opera feed was the last on-premise dependency, and with it gone, so was the facility and the hosting arrangement behind it.
  • Nobody at Aimbridge patches an SFTP server or defends a hole in a firewall. The legacy ciphers Opera requires are now a setting Aimbridge controls on a scoped endpoint, not a server Aimbridge maintains.
  • Opera properties across Europe and Latin America deliver to a single endpoint, and the European side allowlists one fixed address.
Opera was never able to connect to MoveIt, so we chose Files.com as we have more control over the cipher and the security part.
Imtiaz Muhammad, Director of IT Operations, Aimbridge Hospitality

There is a compounding result underneath the immediate one. The next vendor system that dictates its own connection terms gets the same answer: a scoped credential and a cipher configuration, not new infrastructure. The pattern Aimbridge built for Opera works for any system-to-system feed where the other side will not change.

Legacy Requirements Without Legacy Infrastructure

What changed at Aimbridge is where the give happens when a vendor won't move. Keeping Opera connected used to mean paying a third party to run a server in a data center Aimbridge wanted closed, because the connection could only live on infrastructure someone was willing to operate on the vendor's terms. Now the give is a configuration on Files.com. The endpoint negotiates what Oracle Opera can speak, the nightly revenue from hotels across Europe and Latin America arrives in the ERP, and Aimbridge's IT team runs no server to make that true. A vendor that dictates the cipher suite no longer gets to dictate the infrastructure.