Skip to main content

American First National Bank Makes Its Dropbox Ban Stick With a Files.com Portal Easier Than Email

One-time borrowers needed only a browser link, while loan officers got isolated, bank-branded workspaces governed by the security team.
American First National Bank (AFNB)Files.com

American First National Bank (AFNB) is a nationally chartered commercial bank headquartered in Houston, with 20 branches across Texas, Nevada, and California, plus a Loan Production Office in California.

Lending sits at the center of that business. Every loan, consumer or commercial, begins the same way: an applicant handing personal and financial records to a loan officer, and the officer sending documents back. Across 20 branches in three states, that exchange ran on whatever channel was closest to hand.

The Bank's Most Sensitive Files Moved Over Its Least Governed Channels

Bank-wide, that channel was email. Loan officers received application documents from borrowers as attachments and sent files back the same way. At the California branches, staff had gone a step further and adopted Dropbox, putting borrower documents on consumer accounts outside the bank's control.

Neither channel could be governed. An attachment could not be recalled, expired, or scoped, and once sent it sat in an inbox indefinitely. Dropbox was worse: the accounts belonged to the tool rather than the bank, so the security team could neither limit what officers put there nor see what already had been. The bank was carrying risk on every loan application, over channels it could not see into.

The Dropbox adoption was itself the verdict. Officers had reached for a consumer tool because the sanctioned path was email, and email was not enough. The security team wanted Dropbox gone, but a ban with no replacement would have broken the California branches' working process and pushed the whole workload back onto attachments.

What made the problem hard to fix was the counterparty. A loan applicant was a one-time outside party. Applicants could not be asked to install software, hold an account on the bank's systems, or learn a procedure. The loan officers themselves were bankers, not IT staff, spread across 20 branches in three states. Any replacement with more friction than email would be quietly routed around, and the bank would be back where it started.

The Replacement Had to Beat Email, Not Just Dropbox

The requirement was not simply a secure tool. The sanctioned channel had to let an applicant send and receive files with nothing but a browser and a link. It had to give each officer a space of their own, scoped so no officer could reach another's borrower files. It had to present as the bank, so the applicant clicking a link saw American First National Bank rather than a third-party file service. And it had to expire sensitive documents on a schedule instead of letting borrower data accumulate wherever it landed.

AFNB selected Files.com to be that channel, with the bank's Chief Information Security Officer leading the rollout.

A Folder Per Officer, a Link Per Applicant

Files.com gave AFNB a borrower-document exchange under the bank's own brand, one that enforced the security team's policy on every file without the officer or the applicant having to invoke anything.

Each loan officer received a home folder and signed in with bank credentials through Azure AD single sign-on. Folder permissions kept each officer inside their own directory: an officer saw their own borrowers' files and nobody else's.

To exchange files with an applicant, the officer sent a Files.com Share Link by email. The applicant opened a web page, uploaded their documents or downloaded the bank's, and was done. There was no account to create and nothing to install. The custom domain and email both carried the bank's name, while notifications told the officer when an applicant uploaded or downloaded a file.

Policy rode along on every exchange. Share Links expired after 15 days. Files followed a 15-day purge cycle, with a 30-day retention window supporting restoration. Borrower documents did their job and left, rather than accumulating on the site.

Kevin Hajek, AFNB's Senior Vice President and Chief Information Security Officer, wrote and tested the end-user procedures himself, ran a live pilot with a volunteer officer, and then rolled the portal out to the loan officer population.

One Governed Channel Across 20 Branches

With the Files.com portal in production, AFNB replaced the lending document channels it could not govern—email across the bank and Dropbox in California—with one where the security team set the rules.

  • The Dropbox ban held. The workload that had lived on consumer accounts moved onto Share Links, and the California branches kept working without their banned tool.
  • Officers moved because the new path was less work. In the bank's own comparison, uploading through Files.com was easier than the email process it replaced.
  • The pattern expanded beyond lending. Departments from HR and compliance functions to bookkeeping took folder structures on the same site, extending the governed channel through permissions rather than another tool and security review.

Why the Ban Stuck

Today, a loan applicant in any of the bank's three states clicks a link carrying American First National Bank's own name, sends their documents from a browser, and their loan officer knows the moment the files arrive. What that replaced—attachments nobody could recall and consumer accounts nobody could see into—is gone from the lending workflow.

A security team can ban a tool. The ban only holds when the sanctioned replacement is easier than the habit it displaces. AFNB's held because Files.com asked less of its loan officers than email did, and nothing at all of their applicants.