One Files.com Gateway Replaced Allied Credit’s VanDyke SFTP and Avoided 60-Plus Scripts

Allied Credit is one of Australia's larger non-bank lenders in auto and equipment finance. It builds white-label and joint-venture finance brands for vehicle manufacturers, importers, and dealer groups, then runs the lending behind each brand: origination at the dealership, credit, servicing, and collections. The company writes more than A$1.4 billion in retail loans a year, manages roughly A$2 billion in retail assets, and has twice absorbed car finance portfolios exited by a major bank.
That position puts Allied Credit between the banks that fund it and everyone else, and a business in the middle runs on files crossing its boundary. Payment and acknowledgement files pass between it and its banking partners. Credit files go to a bureau. Reports flow to the payroll and finance vendors its operations depend on. Every one of those transfers carries financial records or customer data, and every one is expected to be encrypted, on time, and on the record.
Until 2025, the company could not have told you how many of those transfers existed.
Files.com gave Allied Credit one governed gateway and let it build a major bank programme as automations instead of more than 60 planned scripts.
File Transfer Grew With the Business Until Nobody Could See It
Allied Credit's file transfer was never designed. It accreted. An aging SFTP server running VanDyke still carried work it had been given when the company was small. A Linux SFTP server sat in the Azure DMZ. Different teams used Azure's built-in SFTP as they needed it. PowerShell scripts on Windows servers pulled data out of databases, PGP-encrypted it, and pushed it to partner endpoints. Business users moved files with FileZilla or attached them to email. None of it was audited, none of it was logged, and there was no register of the SFTP endpoints or the workflows running against them.
For a lender aligning to NIST and Australia's Essential Eight, that was a standing risk: sensitive customer data left the organization through channels the security team could not see, let alone govern. Company policy kept Azure storage accounts off the public internet, so every transfer that needed an externally reachable endpoint meant a formal risk acceptance, at one to two hours of paperwork per account, with auditors entitled to ask why each exception existed.
It was also costing the business growth. Standing up a new bank or vendor connection was bespoke work every time: a script, a credential, a key exchange, and a schedule, all built by hand. The friction was heavy enough that the team had stopped trying, and inbound partner connections had stalled at around ten.
Too Complex to Script, and No Appetite for Another On-Prem Platform
The estate had survived because it worked when the company was small, and because nothing in it could be interrupted: the servers and scripts carried live bank and partner traffic on schedules the counterparties controlled. As the business grew, a board-level, multi-year security uplift put file transfer near the front of the queue. And the programme directly ahead made the old approach impossible to extend: dozens of encrypted workflows with one of its major banking partners, spread across 14 SFTP credentials and moving around 30 payment, acknowledgement, and report files a day.
“There's like 30 or 40 different workflows and encryptions, and it's just too complicated to do that via script.”
Senior Cloud Engineer Vincent Copelin tested the scripting route and estimated more than 60 PowerShell scripts just to manage that one bank exchange. The idea was rejected as unmanageable.
So the replacement had a clear specification. It had to be one controlled point through which everything crossing the boundary passes. It had to handle per-partner PGP encryption and key exchange without scripts. It had to keep data in Australia, fit a policy that keeps storage on private endpoints, and give business users a way to send files that never involves an SFTP client. And it had to be SaaS.
Allied Credit selected Files.com to be that gateway.
A Folder Tree per Vendor, Keys on the Platform, and No Scripts
The rollout ran in parallel: the legacy scripts kept carrying traffic while their replacements were built on Files.com alongside them, so no bank schedule was ever interrupted. Allied Credit put the platform on its own branded domain, connected single sign-on through Microsoft Entra ID, set Australian data residency, and separated production from non-production paths for every vendor.
On top of that sat a folder tree per vendor and service. Banks and vendors could push and pull over SFTP on their own schedules, while GPG encryption and decryption was applied at the parent-folder level. A file dropped into a bank's outbound folder was encrypted with that bank's key automatically, and inbound encrypted files were decrypted on arrival. The bank programme assessed at 60-plus scripts ran instead as Files.com Automations, defined as rules rather than code.
Files.com also gave business users a route that did not require an SFTP client. For one finance workflow, Files.com connected the company's SharePoint libraries and Azure Blob Storage so a file dropped into SharePoint flowed into Blob storage for the downstream application, and the return file appeared back in SharePoint with no user interaction.
The same design resolved the storage-exception problem. Because Files.com held the one externally reachable connection, every Azure storage account behind it stayed on private endpoints. There was one boundary to maintain instead of a risk acceptance per account. Allied Credit then made the boundary a rule.
“Any data that comes in and out of our organization will go through Files.com.”
From No Logging Anywhere to Everything on the Record
With Files.com in production, Allied Credit has a single, visible boundary for the workflows it has moved.
- Every transfer through the gateway has a full activity record, giving auditors an answer where previously there was no logging.
- The banking programme runs without the 60-plus scripts it was assessed to need. Dozens of encrypted workflows across 14 credentials run as automations the team maintains as configuration.
- Storage stays private. One maintained external connection replaced per-account public-access exceptions that each cost one to two hours of paperwork.
- Onboarding a partner stopped being a deterrent. Roughly 15 vendors are mapped across production and non-production, and adding one means a folder tree, a permission set, and a key exchange rather than a new script.
External Data Movement Is Now Policy, Not Tribal Knowledge
File movement at Allied Credit used to depend on whichever channel a team happened to have: a script someone once wrote, a desktop FTP client, or an email attachment. Now, Files.com is the mandated boundary and gives the team a repeatable pattern for bringing partner workflows under control.
For a business built on adding finance partners, the next bank or vendor is no longer a scripting project. It is a folder on the gateway.
Related Customer Stories
Banking & Finance
Nasdaq Data Link Brings Small Data Vendors Into Its Marketplace With Files.com—Without Running Its Own SFTP
A branded intake for suppliers without delivery infrastructure stayed in place through the Quandl acquisition and now supports roughly three million API transactions a day.
Read story →
Banking & Finance
TMX VettaFi Moved Daily Index Distribution From Consultant-Run MFT To Files.com—Without A Cutover Day
VettaFi bulk-synced years of history and migrated institutional clients one at a time while daily index publication continued.
Read story →
Banking & Finance
Moelis & Company Replaced GlobalScape EFT With Files.com—Without Rebuilding 15 Years of File Flows
Moving the bank’s sensitive production transfers took a flow-by-flow lift-and-shift that preserved its encryption, service accounts, and surrounding integrations.
Read story →