Skip to main content

AIPAC Made Bank File Transfers Both Encrypted and Scannable With Files.com

A governed perimeter now scans outside files before they move inward and records every access, without requiring counterparties to adopt AIPAC’s systems.
American Israel Public Affairs Committee (AIPAC)Files.com

The American Israel Public Affairs Committee (AIPAC) works to persuade the U.S. federal government on policy that shapes the U.S.–Israel relationship. It does that through year-round lobbying from Washington, with an affiliated super PAC operating as a separate entity.

Almost nothing AIPAC handles is routine data. Its government-relations material is politically sensitive. Its committees’ financial records are federally regulated. Its HR files carry passports and personal information bound for outside vendors. And much of it has to leave the building: to the banks that handle its committees’ transfers, to vendors, to outside counsel, and to each incoming class of interns and consultants. AIPAC’s files are sensitive by default and its counterparties are outsiders by necessity. Email forced AIPAC to choose between confidentiality and inspection. For years, email carried those exchanges.

Encrypted for Confidentiality, Quarantined as a Threat

Until early 2026, external file exchange at AIPAC ran on email. Finance exchanged files with outside vendors as password-protected ZIP attachments. Inbound transfer files from banking partners, mostly smaller local and regional banks, arrived over plain unencrypted email. And when a bank did encrypt, AIPAC’s own defenses turned on it: the email security tooling could not inspect an encrypted attachment, so it flagged the message as a possible compromise attempt and quarantined it.

The two protections cancelled each other out. Encrypting a file made it confidential and made it unscannable. Scanning email caught attacks and caught the banks. At the gateway, a legitimate transfer file from a financial counterparty was indistinguishable from a threat, so real exchanges with real banking partners stalled in quarantine while unencrypted ones sailed through unprotected.

Outbound sharing was no better governed. Staff across Finance, HR, Legal, and IT shared sensitive material through links that spread across the organization with no central control, and nobody could say who had accessed or downloaded anything. Onboarding a new vendor or staff member meant exchanging files with someone who had no established system access at all, over whatever channel was at hand.

Counterparties AIPAC Could Not Control

The problem could not be fixed by tightening email policy, because AIPAC did not control the systems at its counterparties. A small regional bank will not adopt a client’s internal systems. The people the Leadership Institute onboards each cycle, including interns, consultants, and new coaches, have no system accounts yet. And inside an email pipeline the conflict is structural: a gateway cannot inspect what a sender has sealed for confidentiality, so every hardening of one protection weakens the other.

Any replacement had to sit at the organization’s boundary and scan everything inbound before it reached internal systems. It had to work in a browser for a non-technical outsider with nothing to install. It had to serve a recurring vendor differently from a one-time sender, and both differently from someone with no account at all. And it had to put every access on the record. AIPAC selected Files.com to be that boundary.

A Perimeter for Files, Modeled on the One They Already Had for Email

AIPAC’s CISO set the design principle: Files.com would function as the security perimeter for inbound file transfer, playing the same role CrowdStrike scanning already played for inbound email. External files would no longer arrive wherever a sender happened to put them. They would arrive at one controlled point, be inspected, and only then move inward.

Using Files.com’s CrowdStrike integration, every external file crossing that boundary is scanned. Clean files route automatically to the working folder. Flagged files route to quarantine for the security operations team to review. External-origin files are scanned without re-scanning internal traffic already covered by endpoint agents. This is what dissolves the old standoff. The channel itself is encrypted in transit, so a bank no longer needs to seal an attachment to protect it, and the platform inspects the file on arrival, so protection no longer costs inspection.

On top of that boundary, regular vendors received scoped accounts, while other counterparties used one-time-password share links or registration-gated upload pages. Notifications told teams when files arrived, and every path fed the same audit log.

Okta single sign-on and SCIM provisioning tied access to directory groups, while separate Files.com child sites maintained governance separation between the advocacy organization and its separately registered super PAC.

The rollout ran department by department, Finance first. The site went live in January 2026, the first banking partner moved onto the new intake that same month, and the remaining partners followed by the end of February. Training took the same path: sessions by department, then a discovery round with each team to learn how they actually worked, then job aids built from what was found. A perimeter only holds if non-technical people choose to use it, and that is where the reaction from the business side mattered.

It feels very accessible and doable.
Natalie Lascar, Director, Leadership Institute, AIPAC

One Scanned Boundary, and a Record of Every Download

With the Files.com workflow in production, AIPAC replaced an external exchange built on email, encrypted ZIPs, and improvised links with a single boundary that scans, segments, and records.

  • Files from banks and vendors now arrive through a channel that inspects them before anything reaches internal systems. Finance no longer fishes legitimate bank files out of email quarantine, and nothing unscanned crosses the boundary.
  • Every external access and download is on the record. Where the old links left no trace, the audit log now answers who reached which file, and when.
  • Onboarding a counterparty is a pattern instead of an improvisation. A recurring vendor gets an account, a one-time sender gets an expiring one-time-password link, and someone with no system access gets a registration-gated page. The next bank, vendor, or intern class is a choice among three ready channels, not a new ad hoc exchange.
  • Sensitive financial, HR, and government-relations material in these external workflows stopped traveling as email attachments.

Confidential in Transit, Inspected on Arrival

Before, AIPAC lived with a trade: encrypt a file and blind its own defenses, or leave it inspectable and unprotected. Today, when a regional bank sends a transfer file, it lands on Files.com inside an already-encrypted channel, gets scanned, and, once clean, reaches Finance’s working folder. Nobody has to guess whether an encrypted attachment is the bank or an attacker.

The portable lesson is that confidentiality and inspection conflict inside an email pipeline, because a gateway cannot read what a sender has sealed. They stop conflicting on a governed perimeter, where the channel carries the encryption and the platform does the inspecting. AIPAC never resolved the standoff. It moved its file exchange onto Files.com, where the standoff does not exist.