Aras Unblocks Its GovCloud Migration With ITAR File Exchange on Files.com
Aras Corporation builds Aras Innovator, the product lifecycle management platform behind product development at large, complex manufacturers in aerospace and defense, automotive, high-tech electronics, shipbuilding, and medical devices. Forrester named Aras a Leader in its 2025 PLM Wave for discrete manufacturers, and more than 250,000 users work on the platform across 350-plus multinational customers.
Aras sells Innovator as a subscription, and the subscription includes the upgrades. Aras performs them. That model puts customer data in motion: an upgrade, a support reproduction, or a professional services engagement means a customer's Innovator database or a packaged instance travels between the customer and Aras, at 100 GB to 1.5 TB per transfer.
For most customers, that is a large-file problem. For Aras's aerospace, defense, and US Government customers, it is an export-control problem. The data those transfers carry is subject to ITAR, the International Traffic in Arms Regulations.
Files the Transfer Platform Could Not Hold
ITAR does not only restrict who can see a file. It restricts where the file can reside. Export-controlled data had to live in Aras's own environment, on storage carrying the appropriate certifications. It could not sit on a third-party transfer platform's storage, however secure that platform is.
For years, Aras handled ITAR file exchange on an on-premises server. Then Aras began migrating its government-facing processes into Azure Government Cloud, and the arrangement stopped being survivable. The migration needed a file-exchange pattern that worked in GovCloud, and none existed. Every export-controlled engagement, whether a database arriving for an upgrade or an instance going back out to a defense customer, still depended on the old server, and the broader GovCloud migration waited on the exchange layer.
There was a second requirement, and it was legal rather than technical. Aras's security team drew a hard line between the commercial file-exchange operation and the export-controlled one. An account on the commercial side, even a compromised one, could never be allowed a path into the regulated environment. Sharing administrators or data between the two was legal exposure, not convenience.
A Carve-Out Was Not Separation
The first framing inside Aras was modest: could five to ten users who handle government files be sequestered inside the existing environment, behind their own security wrapper? Working through the requirements answered that. A carved-out area still lives inside one site, under one set of site administrators and one credential surface. Legal separation needed a second environment, not a fenced corner of the first.
So the specification wrote itself. Export-controlled files had to land in Aras-owned Azure Government Cloud storage, certified for the purpose, and nowhere else. Customers still needed a front end that could move a 1.5 TB database without special handling. The regulated environment had to be provably walled off from the commercial one at the administrative layer. And the audit record had to flow into Azure Sentinel, where Aras's security team already watches everything else.
Aras chose to build both environments on Files.com, including the one whose files would never be stored there.
A Front Door on Files.com, Every Byte in GovCloud
The architecture makes Files.com the governed front door for export-controlled exchange without ever making it the custodian of an export-controlled file.
Aras runs two fully isolated Files.com sites under a dedicated parent: a commercial exchange and an ITAR exchange, each on its own Aras-branded domain with its own users, groups, permissions, and administrators. The parent-child structure confines each site's administrators to their own environment, and Aras verified the isolation. Nobody holding a commercial credential can reach the regulated site, so a compromise on the commercial side stops at the wall.
Inside the ITAR site, the folders are not Files.com storage at all. Using Files.com Remote Server Mounts, Aras mounted Azure Files and Azure Blob Storage from its GCC High tenancy directly into the site. When a defense customer uploads an instance package, the file passes straight through to Aras-owned, certified GovCloud storage in real time. Files.com operates as the transfer and governance layer; the bytes reside where ITAR says they must. When Aras moved existing customer folders onto the mounted storage, folder structures and share links carried over intact, so customers kept working through the same links while the storage underneath them changed.
A Files.com Agent inside GCC High reached non-internet-facing storage, including a Windows file server, over an outbound-only connection, so Aras did not have to open the GovCloud perimeter to inbound traffic.
Activity in both environments streams to Azure Sentinel through the Files.com SIEM integration. The record of who touched an export-controlled file lives in Aras's own security tooling, not in a vendor console.
Two Legally Separated Environments, Running in Parallel
With both sites in production, Aras replaced a sequestered on-premises arrangement with two parallel environments that satisfy the regulation by construction. Its GovCloud migration stopped waiting on file exchange, and ITAR customers gained the same branded exchange experience as commercial customers while every regulated upload and download passed through to storage that Aras owns.
The compounding result is what onboarding looks like now. Taking on another export-controlled customer no longer means designing a compliance answer, because the environment already is one: the next customer is a folder and a set of permissions inside an architecture that satisfies the regulation before anyone touches it.
Compliance Carried by the Architecture
Today, an aerospace subscriber sending Aras a terabyte-scale database for an upgrade works through the same kind of branded exchange as a commercial customer, and the file it sends never leaves Aras's own GovCloud. Before the rebuild, serving that customer meant an on-premises server and the question of how few users could safely be sequestered around it.
The instinct in most export-controlled shops is that a cloud transfer platform is disqualified on residency alone. Aras's build shows where the line actually sits. ITAR governs where the data resides and who administers the environment. Files.com let Aras satisfy both while never holding a regulated byte, and nothing about the regulation required the front end to be old.
Related Customer Stories
Software & Technology
GoDaddy Registry Replaces Its Amazon EC2 SFTP Server With Self-Service Zone File Distribution on Files.com
The registry separated vetting and entitlement from account creation, giving hundreds of approved outsiders self-service access without putting them in GoDaddy's identity systems.
Read story →
Software & Technology
Zillow Retires Ombud for Files.com to Send KYC Documents Across Six Countries
Browser-based links let recipients Zillow could not train securely view or download each sensitive document according to its own retention requirements.
Read story →
Software & Technology
Redis Gives Every Support Ticket Its Own HTTPS or SFTP Intake Route With Files.com
API-driven, write-only intake lets customers deliver diagnostics through their firewalls while Redis keeps no standing credentials for external uploaders.
Read story →