Skip to main content

How Files.com Passed Atain’s Cloud-Sharing “Strict No-No”

To keep confidential client files out of email and Microsoft SharePoint, the travel-services provider needed a cloud channel that did not behave like conventional cloud sharing.
Atain (formerly IGT Solutions)Files.com

Atain, formerly IGT Solutions, provides business-process outsourcing and customer-experience services to airlines and other travel companies. Its Information Systems Group centrally manages the document exchange between client-facing teams and the customers they serve.

That work produces a steady flow of confidential documents, marketing materials, contracts for external review, and files too large to send by email. Company policy keeps sensitive customer-facing material off email and SharePoint. Yet Atain’s internal servers are air-gapped from the internet, while its compliance stance rejects conventional cloud file sharing. Atain needed a sanctioned cloud channel that did not behave like conventional cloud file sharing.

Confidential Files for Clients, and No Sanctioned Way to Send Them

Atain’s bar for this traffic was an audit trail on every file: what was sent, to whom, and whether the recipient downloaded it. Email attachments could not provide that record or be recalled, and the policy treated SharePoint links the same way. The company had a mandate without a sanctioned channel.

The obvious fixes were closed off from both directions. Hosting an exchange on Atain’s own infrastructure was impossible because its internal servers were air-gapped from the internet for compliance reasons. The standard alternative, a cloud file-sharing tool, collided head on with the company’s compliance stance.

Anything which can share files over the cloud would be a strict no-no from a compliance perspective because we handle some very critical customer data.
Amit Kumar Verma, Head of Information Systems Group, Atain

What made generic cloud sharing unacceptable was specific. An open link, forwarded once, could expose a critical file beyond its intended recipients. Atain also required a per-file record its compliance team could stand behind and its own identity and branding on client-facing material.

So the channel had to be a cloud platform that behaved like nothing the compliance team associated with the phrase. It had to authenticate every internal user against Atain’s Entra ID directory. Every share had to be limited to its intended recipients, protected by a password, set to expire, and recorded in an audit trail. Outside reviewers needed to be able to view documents without editing or downloading them, and the entire experience had to run under Atain’s domain and branding.

Atain selected Files.com to be that platform.

One Governed Channel, With Every Control Enforced by the Platform

Files.com became the single channel for confidential traffic between Atain and its clients, used by a deliberately closed group of client-facing users. The controls the policy demanded were not guidance for those users. They were properties of the platform.

Atain put the site behind SAML SSO against its Azure AD / Entra ID directory and gave each user a home folder with controlled sharing permissions. Files.com Share Links were restricted to their intended recipients, password-protected, and configured to expire, including on schedules as short as one day.

For external review, Atain used Files.com file preview with editing and downloading disabled. A draft contract could go to outside counsel, who could read it in the browser but could not change it or download it through the link.

The experience ran on Atain’s own domain and carried the company’s logos in the interface and file previews. A client who clicked a link saw Atain, not a third-party tool.

Notifications for user changes, uploads, link shares, and recipient downloads went to a controlled distribution list. The Files.com audit log recorded what file was sent and who downloaded it.

Transfer protocols followed the same least-exposure rule. SFTP was granted to exactly one machine account, secured with an SSH key and IP whitelist, for an automated daily upload from a cloud service. Every person went through the web interface under SSO.

The Channel Puts the Policy Into Practice

With Files.com carrying the traffic, Atain paired its written prohibition with a governed channel. Users no longer have to interpret the policy file by file: recipient restrictions, expiration, view-only review, and audit logging are already part of the way they share.

The model also applies itself to whoever comes next. Bringing another client-facing user under the policy requires a home folder and an SSO account, with the controls in force from the first file they share.

A Cloud Platform That Survived a No-Cloud Compliance Stance

Today, a company whose internal servers cannot touch the internet, and whose compliance stance treats cloud file sharing as a strict no-no, runs its confidential client-facing exchange on a cloud platform. That is less of a contradiction than it sounds. What Atain’s policy forbade was ungoverned sharing: links anyone could open, files nobody could trace, and another company’s brand on client material. Files.com removed each of those objections while allowing the compliance stance to hold.

The difference shows at the level of a single task. When an Atain manager needs a client’s lawyer to review a draft contract, they can send a view-only link from a page carrying Atain’s own domain, set it to expire the next day, and retain an audit trail of the share. Now the compliant path is also the easy one.