Archway Replaced Kiteworks With a Files.com Portal That Isolates 90-Plus Client Organizations
Archway Group runs the general ledger for the upper end of private wealth. Its accounting and reporting platform serves family offices, private banks, wealth advisors, and private funds, with over $850 billion in assets on the platform.
Bringing a new client onto that ledger is not a signup flow. An implementation runs three to twelve months, and it runs on documents: account statements, spreadsheets, PDFs, files carrying account numbers and personal information, moving back and forth between the client and Archway's implementation team for the length of the engagement. That exchange is the front door of the business. Until mid-2025, the front door ran on somebody else's infrastructure.
The Exchange Ran on a Former Parent's Kiteworks
For years, Archway operated as a unit of SEI. When a private equity firm carved the business out in mid-2025, everything file-related lived inside the parent's environment, and separating meant losing all of it, including the Kiteworks instance that carried client onboarding exchange. Reaching it was not even direct: an Archway employee opened a Windows 365 session into the former parent's environment, then navigated to Kiteworks from inside it.
The workflow by which every new client arrives, months of confidential document exchange, depended on a company Archway was separating from, on a product Archway could not brand, govern, or keep.
And the bar for the replacement was set by the clients themselves. Archway serves some of the largest financial institutions in private wealth, and they audit it on every engagement. Whatever took over from Kiteworks had to hold up under that scrutiny while it was being stood up.
Links Were the Fast Answer and the Wrong One
The quickest replacement would have been share links: send a client a URL and let them upload. Archway rejected that on its clients' behalf. The people on the other end of this exchange are sending account statements with account numbers on them, and Archway's own read was that those clients would refuse a control model where holding the link is holding the data.
So the replacement had to do specific things. It had to seal every client organization off from every other, and scope third parties tighter still, so a client's auditors could upload into one subfolder without seeing the rest of the tree. It had to carry Archway's own domain and branding on every page a client touches, and it had to work through authenticated accounts rather than links. And it had to be fully hosted, because Archway was standing up an IT estate from scratch and had no appetite for more servers to run.
“I don't want to know about servers here. I want people to log in securely and do their thing in SaaS.”
Archway selected Files.com to carry the exchange and built it as a dedicated child site: a fully separate site with its own domain, branding, and security policy, under the same Files.com deployment that was absorbing the rest of the divestiture's file transfer.
One Walled Container Per Client, on Archway's Own Domain
The design turned each client relationship into its own walled space on a portal Archway owns.
The child site runs on a custom domain of Archway's own, under Archway's branding, so everything a client sees reads as Archway. And because Files.com child sites carry their own security policy, the portal's posture is set for exactly what it does. This is human-to-human exchange, so Archway deliberately disabled SFTP on the site: the only way in is an authenticated web login.
Inside, each client organization is a Files.com Partner in its own container, with a folder tree organized by document type. That boundary is enforced by the container itself. A user provisioned to one financial institution reaches that institution's folders and nothing else: not another bank's, not another family's. Where an engagement pulls in third parties, the scoping goes a level deeper, and a client's auditors can be given upload rights to a single subfolder with no visibility into anything around it.
Administration is delegated to the same boundary. Partner team leads and partner administrators create and manage their own downstream users inside their container, and every action on the site, by anyone, lands in one audit log.
The Users Carried Their Own Files Out of Kiteworks
The move out of Kiteworks was run by the people who owned the content. Internal users rebuilt their folder structures on the new site, exported their Kiteworks content as zips, and dragged it in. The rebuild doubled as a spring clean: what came across was what someone decided was still worth keeping.
Archway provisioned more than 90 client organizations in bulk through a two-stage CSV import, creating each partner container with its permissions before mapping users into it. Invitations were timed so client team leads could tell their clients what was coming before the first email from the new portal went out.
The controls held under real scrutiny: Archway passed a major audit during the migration itself.
What Runs on the Portal Now
In production, the portal changed the operating model:
- Client onboarding document exchange now runs on Archway's own domain, under Archway's branding, on infrastructure Archway governs and Files.com operates. There are no servers for Archway to patch.
- Every client organization is isolated by construction. A user at one institution sees only that institution's tree, and auditors and other third parties work inside a single scoped subfolder.
- Account administration moved out of IT. Partner team leads manage their own users inside their own container, work that previously routed through Archway's IT team.
The compounding result is what the next engagement costs. Onboarding another client organization now means creating a container, setting its permissions, and sending invitations; the folder pattern, the isolation, and the delegation come with it. It does not mean a new tool, a new access path, or a queue of account requests into IT.
The Front Door Belongs to Archway
An implementation still runs three to twelve months, and it still runs on documents. What changed is whose infrastructure carries them. An engagement used to begin with Archway staff opening a session into a former parent's environment to reach a Kiteworks instance they could not brand or keep. It now begins with the client's team signing in to a Files.com portal under Archway's own name, into a folder tree that exists only for them.
The replacement did not trade rigor for ownership, either. The fast answer, links, would have loosened control at the exact moment clients hand over their most sensitive records. Authenticated partner containers on Files.com tightened it instead. For the firm that keeps the ledger for some of the wealthiest families in America, the exchange that starts every client relationship is now something Archway owns, brands, and can prove control of.
Related Customer Stories
Banking & Finance
Nasdaq Data Link Brings Small Data Vendors Into Its Marketplace With Files.com—Without Running Its Own SFTP
A branded intake for suppliers without delivery infrastructure stayed in place through the Quandl acquisition and now supports roughly three million API transactions a day.
Read story →
Banking & Finance
SumUp Scales EU-Resident Merchant Data Exchange Beyond 500 Accounts With Files.com
The exchange has run for nine years, while a site-level setting has kept every file in EU storage since 2018.
Read story →
Banking & Finance
Bambora North America Gives Thousands of Merchants Permanent, Account-Free FINTRAC Intake Through Files.com
A dedicated folder and non-expiring Share Link for each merchant turned manual compliance collection into repeatable infrastructure.
Read story →