Athennian Replaced AWS Transfer Family With Files.com and Took Client Legal Records Off Staff Laptops

Athennian makes entity-management software for legal, corporate-secretarial, and compliance teams that keep business records transaction-, audit-, and compliance-ready. Its clientele holds some of the most confidential records a business produces and treats a leaked or missing document accordingly.
That business model creates a file problem before a single line of the product is used. Athennian wins customers by migrating them off legacy entity systems, so every new customer begins by handing over its corporate records: spreadsheets, Word documents, and large volumes of PDFs of legal filings. Athennian's implementation team sorts those files, works on them, and keys their contents into the product by hand. A typical project brings hundreds of documents. A large one can run to 6,000, arriving in weekly drops over two to three months. And Athennian is a distributed, remote-first company that gave up its physical office, which meant a business built on hands-on work with other people's confidential files had to find a governed place to do that work.
The Office Closed, and the Working File Layer Went With It
While Athennian had an office, that place was an on-premise NAS everyone connected to. When the company went remote and wound the office down, the NAS was retired with it, and the working file layer disappeared overnight.
The interim answer was AWS. Amazon S3 with AWS Transfer Family gave clients an SFTP endpoint to drop records into, and FSx handled internal sharing. It covered secure storage and secure transfer. It did not cover the work. S3 is object storage, not a file system, so even renaming a folder was slow, and editing in place was impossible.
“I can't do anything. We can't edit a Word document without downloading it. We can't rename it. We can't even make a new folder or move it into a different folder. I just need it to be able to do everything a regular file explorer can do.”
So the real workflow became download, edit, re-upload. Every document a specialist touched passed through a personal laptop, and afterward came a manual cleanup that the team itself had flagged as a problem in its own process, because there was no way to verify that a law firm's entity records had actually been removed from every local machine.
“We would prefer everything to stay out of everyone's local computers from a security perspective.”
Getting Files From Clients Meant Finding Their One SFTP Person
The same gap showed on the client side. Intake ran over SFTP only, which meant a paralegal or corporate secretary with thousands of documents to send needed their own IT department in the loop before a project could start.
Most of Athennian's customers did not know how to send files over SFTP at all, so projects waited on the one technical person at the client who did. When that proved too hard, some clients fell back to emailing confidential legal documents, the exact channel the process existed to avoid.
As the project load grew, the arrangement stopped being survivable. Athennian was running as many as 50 customer projects at a time, roughly 20 of them active at once, with weekly inbound drops on each. A workflow that routed every document through a laptop and every intake through a client's IT calendar could not carry that.
What the fix had to do was clear before any product was named: keep each client's records segregated from every other client's; give non-technical clients a browser upload while keeping SFTP for those who wanted it; let the implementation team work on files in place, so nothing lands on a local machine; pin each client's data to the country it must stay in, Canadian client data in Canada and US client data in the US; and log every action. Athennian selected Files.com to be that governed file layer.
One Governed Layer Between the Client and the Product
Files.com became the single file layer between Athennian's clients and its own product: the intake surface where records arrive and the working surface where they are prepared, running as a branded portal on Athennian's own domain with staff signing in through Google SSO.
On the intake side, every client got its own segregated folder. Longer projects get the client created as a Files.com user with access to that folder and nothing else. Shorter ones get a share link instead. Non-technical clients upload through the web page, and clients who prefer SFTP still connect that way, into the same folder under the same controls.
On the working side, the Files.com Desktop App gave the implementation team what the NAS used to provide: native Finder and Explorer access, renaming, sorting, drag-and-drop between systems, and unzipping archives in place, all executed against the platform rather than a laptop.
Governance sits underneath both. Each client's folder is pinned to the region its data must stay in, so residency is decided by where the folder lives, not by anyone's diligence. The regionally separated S3 buckets stayed in the picture, but behind the platform, connected through Files.com remote server mounts as back-end repository and backup rather than as the surface anyone works on. Audit logs record every action, and client source records are retained for roughly a year and then deleted. Athennian completed the cutover in phases, first moving the professional-services team onto real customer data and then retiring the old SFTP endpoint.
The Local Download Is Gone, and So Is the Cleanup Nobody Could Verify
With Files.com in production, Athennian replaced a workflow built around local downloads and manual cleanup with a single governed path from client upload to product entry.
- Confidential client records no longer touch staff laptops. Editing, renaming, and sorting happen on the platform, so the local-download step, and the unverifiable manual cleanup behind it, is gone from the process rather than policed.
- Getting data from a client no longer depends on their one technical person. Clients upload through a branded web page, and the team has a sanctioned path to point them to instead of email.
- Data residency holds per client, automatically. A Canadian client's records stay in Canada and a US client's stay in the US, enforced by the folder itself.
- Onboarding the next client is a repeatable pattern: a folder, a user or a share link, and a region.
“They love the desktop app, and that was one of the primary reasons we purchased it, because it had the ability to be a desktop app that made it easy to move files around.”
Securing the Work, Not Just the Transfer
The AWS endpoint Athennian ran before was secure in the narrow sense: encrypted transfer into encrypted storage. What it never secured was the work. The moment someone had to rename a document or fix a spreadsheet, the file left that perimeter for a laptop, and the safety of a law firm's records came down to a cleanup step nobody could verify. Files.com closed that gap by governing the working layer itself. Today an implementation specialist opens a client's records where they landed, prepares them where they sit, and keys them into Athennian's product, and the files never leave a platform that logs every action and keeps each client's data in its required country. Securing the drop point was never the same thing as securing the work. Athennian now has both in one place.
Related Customer Stories
Software & Technology
GoDaddy Registry Replaces Its Amazon EC2 SFTP Server With Self-Service Zone File Distribution on Files.com
The registry separated vetting and entitlement from account creation, giving hundreds of approved outsiders self-service access without putting them in GoDaddy's identity systems.
Read story →
Software & Technology
Zillow Retires Ombud for Files.com to Send KYC Documents Across Six Countries
Browser-based links let recipients Zillow could not train securely view or download each sensitive document according to its own retention requirements.
Read story →
Software & Technology
Redis Gives Every Support Ticket Its Own HTTPS or SFTP Intake Route With Files.com
API-driven, write-only intake lets customers deliver diagnostics through their firewalls while Redis keeps no standing credentials for external uploaders.
Read story →