Skip to main content

An Automotive Retailer Moved Its Internet-Facing SFTP Endpoint to Files.com Without Rewriting Its Batch Pipeline

Dealer and vendor feeds kept their existing protocols, while an outbound-only Agent connected the new endpoint to years of on-premises batch processing.

An international automotive and commercial truck retailer runs a global estate of dealerships and retail locations.

A retail operation of that size runs on data that crosses the company boundary every day. Inventory files, orders, and shipment status move constantly between the retailer, its vendors, and its dealers: which vehicles are on a truck, which have arrived, what sold. Those files feed the performance reporting and inventory analysis the business runs on. And every one of them has to enter the company through some door.

The retailer needed to move that door without forcing dealers and vendors onto new transfer methods—or rewriting years of internal batch processing first.

The Front Door Was a Server the Retailer Had to Host, Patch, and Defend

For years, that door was an FTP/SFTP server the retailer hosted on-premises as its internet-facing endpoint. Vendors and dealers uploaded their daily files directly to it.

An internet-facing file server is infrastructure the company itself has to keep online, keep patched, and keep defended, and every partner credential and access decision lives on that one machine. The retailer wanted the replacement to decide access by country and by identity, tie internal access to corporate sign-on, and keep a standing record of every configuration change.

Years of Batch Processing Sat Behind the Endpoint

The endpoint survived because of what depended on it. Dozens of external counterparties had working scripts and credentials pointed at it. Behind it sat internal batch processing built up over many years, which consolidates the daily files and loads them into SQL for reporting across the retailer’s estate. A replacement that forced partners to change how they send, or forced that pipeline to be rewritten first, was never going to happen. The retailer’s Vice President of Technology Services takes a deliberately incremental approach to modernizing the estate: declaring that everything stops while everything gets refactored is, in the team’s experience, a plan that never actually happens.

So the fix had a specification. It had to take over the internet-facing feed role while preserving the protocols and processing behind it. It had to decide access by country and identity rather than by server hardening. It had to give internal tooling a programmatic path in. And it had to reach back to the on-premises file server when a file still needed to land there, without opening the retailer’s network to do it.

The retailer selected Files.com to be that endpoint.

Files.com Took Over the Internet-Facing Role

The retailer moved its external transfer users off the on-premises SFTP endpoint and onto SFTP hosted by Files.com. Dealers and vendors upload the same daily files over the same protocols. What changed is where the endpoint lives and who defends it.

Access became a policy rather than a hardening exercise. The retailer’s security team configured Files.com Access Control by Country across the whole tenant, blocking connections from outside an allowed country list, with per-user IP exceptions for the accounts that legitimately need to connect from elsewhere. Internal users authenticate through corporate SSO, and settings changes across the site land in an audit log.

Internal systems retained a programmatic path through the Files.com REST API and Files-CLI. The Files.com Agent runs on the remaining internal file server over an outbound-only connection, so files still move between Files.com and on-premises processing without any inbound firewall path into the retailer’s network.

Access by Policy, With the SFTP Perimeter Moved

With Files.com carrying the external SFTP endpoint, the retailer replaced an internet-facing role it had to defend with a platform it configures.

  • The retailer no longer operates its former internet-facing SFTP endpoint. That perimeter is no longer something the company has to host, patch, or harden.
  • Who can reach the feeds is a policy decision: blocked by country by default, excepted per user, authenticated through SSO, with configuration changes on the record.
  • Partners kept the protocols and transfer methods their feeds already used. The daily inventory, order, and shipment feeds kept flowing through the cutover.
  • The batch pipeline behind the feeds was never rewritten, and it did not have to be. The perimeter moved on its own timeline, and the Agent keeps on-premises processing supplied.

The lesson in the retailer’s move is that the internet-facing transfer perimeter did not have to wait for the systems behind it. The pipelines stayed put, the partners kept their protocols, and the one piece that faced the internet moved to Files.com on its own.

Get The File Orchestration Platform Today

4,000+ organizations trust Files.com for mission-critical file operations. Start your free trial now and build your first flow in 60 seconds.

No credit card required • 7-day free trial • Live in minutes