Skip to main content

Files.com Absorbs a Decade of Security Change for BroadTech’s UnitTracker-to-SAP Exchange

The exchange had to preserve partner protocols, firewall rules, and SAP’s rigid FTPS requirements while moving 5,000 to 15,000 XML files a day without human intervention.
Assurant / BroadTechFiles.com

Assurant is an S&P 500 specialty insurer with a distinction most insurers lack: it owns the physical machinery behind its claims. The company launched the first mobile device protection program in the United States more than 40 years ago, and today its network of Device Care Centers processes 20 million devices a year, inspecting, repairing, refurbishing, and reselling the phones that come back through carrier protection and trade-in programs.

BroadTech is the Assurant subsidiary at the front of that pipeline. Founded in 2001 by wireless-industry veterans, it handles reverse logistics and return management for carriers and device makers, and it runs UnitTracker, the line-of-business system behind device returns and warranty claims for one of the largest wireless carriers in the United States and its prepaid brand. From its earliest years, BroadTech's differentiator was information: clients could see the state of their returned inventory at any time. So every phone that moves through the operation is also a chain of data events. Purchase orders, sales orders, and warehouse confirmations have to land in the carrier's ERP for the physical logistics to count. The repair business works only if the file exchange behind it does.

A Plain-Text FTP Channel Carrying Every Customer's Data

In 2012, the channel carrying that data was a set of FTP servers BroadTech ran itself. They were the primary delivery method for data to and from every customer, and they were secured by a plain-text login password. Credentials and file contents crossed the internet unencrypted. The servers also went down on several occasions, and the customers saw it.

Our old service was only secured by a non-encrypted login password. And we had a few occasions when the FTP servers were down, which inconvenienced our customers. So we made the switch for the improved security and reliability.
Dennis Eldridge, Director, Software Engineering, BroadTech

The compliance bar made the condition untenable. BroadTech's data exchange had to meet HIPAA and Sarbanes-Oxley requirements for encrypted credentials and encrypted data in transit, a bar a plain-text FTP server cannot clear. Meanwhile the volume of unattended, system-to-system traffic across the partner base kept growing.

The server had lasted as long as it did for the same reason it was hard to replace: everything pointed at it belonged to somebody else. Partner firewall teams had whitelisted its addresses. Partner ERP jobs, Linux systems scripting lftp, and Windows clients logged into it on schedules BroadTech did not control. Nobody at a carrier or a manufacturer was going to install new software or rewrite a working transfer job because BroadTech changed infrastructure.

That constraint was the specification for what came next. The replacement had to keep speaking FTP, FTPS, and SFTP exactly as the partners already did. It had to give each partner its own folder tree and its own credentials, carry BroadTech's name on a branded domain, and present fixed, dedicated IP addresses a partner's firewall could pin. And it had to encrypt everything, in transit and at rest, without asking the far side to change anything beyond a hostname. BroadTech selected Files.com to be that exchange point. It became the layer that would absorb a decade of security change without forcing BroadTech to rebuild the carrier integration.

A Cutover the Customer Ran Himself

Eldridge ran the 2012 migration personally. The legacy and Files.com sites operated in parallel through the spring, with a hard shutdown of the old servers in April 2012. He wrote the partner-facing migration notice, published the site's IP list and FTP data-port range so partner network teams could whitelist the connection, and onboarded the whole heterogeneous client base onto the new site.

What this means is that your userid and password are no longer transmitted across the Internet in plain text, and the data that is transmitted is also encrypted, so neither your login information or your data can be intercepted or viewed by hackers.
Dennis Eldridge, then Director of Information Technology, BroadTech, in his migration notice to partners

The Interchange Between UnitTracker and the Carrier's SAP

The integration that shows what the exchange point became was built in 2014, when BroadTech connected UnitTracker directly to the carrier's SAP landscape. UnitTracker uploads XML data feeds to Files.com. On the other side, the carrier's SAP PI environment polls the site, pulls the feeds, and loads them as IDOCs: purchase order creates, sales order creates, warehouse confirmations. The exchange is fully automated in both directions, machine to machine, with no human in the loop to route around a failure. Each complete feed turns the movement of physical devices into the corresponding ERP event.

Files.com carries the parts of that arrangement neither endpoint could. Each partner exchanges files in its own folder tree under its own credentials, and the carrier's headquarters integration alone spans more than a dozen feed channels. Dedicated IP addresses let the carrier's firewall pin the connection with a standing wildcard whitelist. Transfers run over explicit FTPS with TLS 1.2. Because downstream processing depends on complete files, BroadTech's upload program verifies every upload against Files.com's file history.

A TLS 1.2 Mandate That Did Not Become a Rebuild

The hard part of a long partner integration is that the partner's side keeps moving, on the partner's schedule. In 2017 the carrier mandated TLS 1.2 across its estate, and SAP PI has rigid expectations about FTPS modes, ports, and cipher suites that BroadTech does not get to choose. Over 2017 and 2018, BroadTech and the carrier's SAP Basis team tested FTPS and worked through port and cipher-suite compatibility until the SAP handshake succeeded. SSL certificate renewals were coordinated the same way. Through all of it, the exchange pattern never changed. The mandate landed as protocol configuration on Files.com, not as a rebuild of the integration.

Ten Years, Thousands of Files a Day, One Exchange Pattern

With the Files.com exchange in production, BroadTech replaced a server it could not secure with an interchange that has now carried its largest partner integration for more than a decade. The results are the kind that only show up over years:

  • Between 5,000 and 15,000 XML files move through the site every day for the carrier's SAP process, continuously since 2014, with nobody touching a file.
  • The pattern absorbs peaks: in October 2014, an 11-day backlog of accumulated traffic cleared in a single day, with thousands of files moving in each direction.
  • The carrier's firewall whitelist structure against the site has held for more than ten years, through a TLS mandate, cipher-suite negotiations, and certificate rotations, without the integration being rebuilt.
  • Every partner exchange runs encrypted in transit and at rest, the configuration Eldridge told his own partners meets HIPAA and Sarbanes-Oxley requirements, on infrastructure BroadTech no longer has to patch or keep online.

The pattern also compounds. Onboarding the next partner stopped being an infrastructure question: it is a folder tree, a credential, and the published IP list, on the same site the strictest partner already connects to. BroadTech has run that motion repeatedly, bringing manufacturers and additional partners onto the same exchange.

The Layer That Absorbs the Churn

More than a decade on, what changed is what BroadTech's most important connection is made of. Before Files.com, the link to its customers was a server BroadTech could not keep encrypted and could not always keep online. Today, when the carrier's requirements move, and they always do (new TLS versions, new cipher policies, new certificates), the work is a negotiation over settings rather than a project against infrastructure. The endpoints of a long integration never stay still: UnitTracker evolved, the carrier's SAP landscape was retested and retightened more than once, and the security bar kept rising. The integration itself is still the one built in 2014, because the layer between the endpoints, Files.com, absorbed the churn on both sides' behalf.