AIPAC Took Its Monthly FEC Filing Off Email and Onto Files.com Between Two Deadlines

The American Israel Public Affairs Committee (AIPAC) works to persuade the federal government to enact policies that strengthen the US–Israel relationship. Its political engagement runs through federal committees whose finances must be disclosed to the Federal Election Commission. For AIPAC, that disclosure was a monthly event: a filing assembled, reviewed, approved, and submitted on a deadline that did not move.
Until early 2026, that filing ran on email.
A Federal Filing That Ran Over Email
An FEC filing is not one document. Each month, AIPAC's filing vendor generated the reports, in PDF and spreadsheet form, that Finance reviewed, executives signed off on, and the vendor then submitted to the Commission. Every handoff in that chain was an email attachment, moving inside the same regime AIPAC used for sensitive external exchange generally: password-protected ZIP files sent over email.
That regime was failing on its own terms. AIPAC's email security tooling flagged encrypted attachments as possible compromise attempts and quarantined them, so the files a federal deadline depended on were being held up by the controls meant to protect the organization. And nothing enforced the process itself. No system decided who saw which stage, told a reviewer that reports had arrived, or recorded who had accessed or downloaded anything. A federally regulated submission depended on people watching inboxes.
The workflow had survived this way because there was never a safe moment to replace it. It spanned an outside vendor and two tiers of internal review, and the calendar never paused: a replacement had to be designed, built, tested, and trusted in the space between one month's filing and the next. Anything that slipped meant running the filing over email for another month.
When AIPAC decided to move its sensitive external file exchange off email entirely, Finance went first, and the FEC filing set the requirements. The replacement had to give the vendor a controlled intake point, hold each review stage behind its own permissions, notify reviewers the moment files arrived, and keep a record of every access. And it had to be in production before the next filing. AIPAC selected Files.com to carry that workflow.
Five Weeks From Site Activation to a Production Filing
The Files.com site went live in January 2026, with Finance as the first department in a phased rollout. AIPAC mapped the filing onto a folder structure that mirrored its stages: an intake point where the vendor delivered each month's reports, a Finance review stage, an executive review stage, and the handoff back to the vendor for submission. Folder-level permissions in Files.com determined who could reach each stage, so the vendor saw its intake, Finance worked its review, and executives saw what was ready for them and nothing else.
Files.com notifications, delivered by email and Slack, were configured to announce each arrival. A stage advancing became something reviewers were told about, not something they discovered by checking an inbox. Every upload, access, and download along the way landed in the Files.com audit log.
The timing was designed in, with stages and notifications tuned to the monthly FEC cadence. The finished workflow went through a one-time, four-day testing and validation cycle ahead of the vendor's February 2026 filing, then carried that filing in production, roughly five weeks after the site first went live.
A Filing Process Finance Can See and Control
With the workflow in production, AIPAC replaced an inbox-driven regulatory process with one Files.com makes visible and controlled.
- The FEC filing now follows a defined four-day process each month. Each stage has a folder and a permission boundary, and reviewers are notified when it advances, so the deadline is met by a process rather than by whoever was watching email that week.
- The filing's reports no longer travel as encrypted ZIP attachments, so they are no longer quarantined by AIPAC's own email security. The conflict between the organization's security controls and its compliance calendar is gone.
- There is a record. Every access and download of a filing report sits in the Files.com audit log, where the email workflow left nothing behind.
The pattern also proved reusable. Within weeks of launch, three more third-party file feeds moved onto the same platform: expense extracts arriving from Concur over SFTP and decrypted automatically with GPG for Finance, data feeds for Salesforce Marketing Cloud, and an outbound SFTP payroll feed to UKG running under AIPAC's own branded domain on dedicated IPs.
A Deadline That No Longer Depends on an Inbox
A regulated, deadline-bound workflow is exactly the kind of thing organizations leave on email for years, because there is never a safe month to rebuild it. AIPAC rebuilt its filing workflow on Files.com in the space between two filings, validated it in four days, and ran the very next filing on it.
Related Customer Stories
Nonprofits & Associations
YMCA of Greater Dayton Handles County Biometric Data With Files.com’s HIPAA BAA—Without Building Healthcare Infrastructure
The channel had to give county users scoped access, keep other senders out of new software and account setup, and notify YMCA staff as soon as files arrived.
Read story →

Nonprofits & Associations
Goodwill of Middle Tennessee Automates DocuSign Delivery to Its File Server Without Opening the Firewall
Files.com Email Inboxes, date-stamp renaming, and an on-premises Agent created an unattended path from emailed paperwork to the Finance share.
Read story →
Nonprofits & Associations
American Psychiatric Association Replaces Its Progress MOVEit Book-Order Relay—and the Scripts Behind It—with Files.com
Files.com let APA prove each vendor-specific workflow against a mock network before cutover, so its fulfillment partners did not have to change their systems.
Read story →