Skip to main content

Baldwin Used Files.com to Pass PCI Without Moving Its 10-Year AWS S3 Call Archive

Files.com gave approved staff a searchable, play-only path to millions of recordings while tying every access to a named user and streaming it to Baldwin's SIEM.
BaldwinFiles.com

The Baldwin Group is one of the largest independent insurance distribution firms in the United States, delivering insurance, risk management, and employee benefits to more than two million clients in all 50 states. A meaningful part of that business happens on the phone. Baldwin's National Health Plans & Benefits Agency division sells individual health plans and Medicare coverage through enrollment centers and a network of more than 2,000 agents, and enrolling by phone often means a customer reading a payment card number to a representative on a recorded line.

Compliance rules require Baldwin to keep call recordings for ten years. So the business builds, one call at a time, an archive of millions of recordings, and a large share of them contain cardholder data. Baldwin used Files.com to put governed, self-service access in front of that existing AWS S3 archive and pass PCI without moving or duplicating the recordings.

A Decade of Recordings Only IT Could Reach

Recordings start in Five9, Baldwin's contact-center platform, and in Zoom. Both keep a recording for 60 days. After that, each call moves into Baldwin's own AWS S3 buckets, much of the volume in cold storage, where it sits for the rest of its ten-year retention period.

The people who needed those recordings had no way to reach them. When a state regulator or an insurance carrier raises a complaint, operations leaders have to go back to the original calls, listen, and analyze what was said, on a deadline. But the archive was raw object storage, with no interface a business user could touch.

We don't have a way to provide those to colleagues, or allow colleagues to retrieve those on their own.
William Young, Systems Administrator, The Baldwin Group

Every retrieval meant asking IT, and a time-sensitive complaint review waited on someone with AWS access to pull a file out of cold storage.

The second cost was larger. A PCI assessment requires that access to stored cardholder data be authenticated, limited to the people who need it, and logged. An archive reached directly through AWS credentials could show an assessor none of that. Baldwin needed a demonstrable wall in front of the recordings, with a record of every access behind it.

The Archive Could Not Move

The obvious fixes were all closed off. Migrating the archive onto some other compliant platform meant re-platforming millions of files under ten-year holds and paying to store a decade of audio twice, against cold-storage economics that existed for a reason. Cleaning the data was not possible either. On new calls, a representative can press a button that blanks the recording while a card number is read, so card data never lands in a new recording. But ten years of historic calls cannot be re-recorded, and the card numbers already in the archive are there for the life of the retention period. And handing non-technical staff direct access to the buckets was never on the table.

So the requirement was precise: an authentication wall in front of storage Baldwin already owned, self-service search and playback for approved staff, permissions granular enough to let someone listen without letting them download, and a per-access log that both the security team and a PCI assessor could consume. All of it without moving or duplicating a single file.

Baldwin chose Files.com to be that wall.

A Window Into Their Own AWS

Files.com became the governed front door to storage Baldwin already owned. Nothing migrated, and nothing is stored twice.

We have call recordings in AWS, and we use Files.com as a window into our AWS. We don't really keep anything in Files.com.
Killean Colton, Unified Communications Team Lead, The Baldwin Group

Using Files.com Remote Server Mounts, Baldwin connected multiple S3 buckets, including the cold-storage-backed archives, into a single Files.com site. Every operation passes through to the bucket in real time, so the recordings stay in Baldwin's storage under Baldwin's retention rules without giving staff direct AWS access.

Staff sign in through Microsoft Entra ID with SAML single sign-on, and SCIM provisioning keeps accounts matched to the directory, so access follows employment rather than a manually maintained user list. Group-based folder permissions decide who can reach which recordings, and a play-only role lets a reviewer listen to a call in the browser without taking a copy of it.

Finding a call matters as much as gating it. The Remote Server Mount metadata index lets staff search across an entire mounted bucket, including one holding hundreds of thousands of files, instead of needing to know a path in advance.

And everything is on the record. Every login and every access lands in the Files.com audit log and streams to Baldwin's SIEM, Google SecOps, where the security team watches it alongside the rest of the estate. Files.com's PCI Attestation of Compliance and responsibility matrix feed Baldwin's own annual assessments.

Through the Audit, Out of the IT Queue

With Files.com in production over the buckets, Baldwin replaced an archive only IT could touch with a governed retrieval path, and that path is what its PCI audit measured.

  • Baldwin passed its PCI audit, with the Files.com-over-S3 configuration standing as the authentication wall and audit-logging layer over the cardholder data in the archive. Killean Colton, who ran the build, credited that configuration with getting Baldwin through.
  • Operations staff across multiple teams now retrieve and play recordings themselves. A state or carrier complaint review starts with a search, not with a request to IT.
  • Every retrieval is tied to a named, SSO-authenticated user, scoped by permission, and streamed to the SIEM, so who accessed which recording is a lookup rather than a reconstruction.
  • The archive never moved. It stays in Baldwin's own buckets, at cold-storage prices, with nothing paid twice.

The configuration also compounds. Bringing another bucket or another team under the same wall is a mount and a group permission, with the single sign-on, roles, and SIEM feed already in place, and Baldwin has since extended the same setup to additional divisions.

The Access Layer Became the Compliance Posture

Today, when a complaint lands, the reviewer signs in with company credentials, searches the archive, and presses play. What used to open with a request to IT, against a regulatory deadline, now opens with the analysis itself.

Behind that login, Files.com is doing the compliance work: a decade of recordings containing card numbers can be reached only by named, authorized people, one recording at a time, with every access written to the record. Baldwin never migrated the archive, never re-recorded a call, and never handed a business user an AWS credential. A regulated archive does not have to move to be made compliant. Baldwin made the access layer the compliance posture, and Files.com is that layer.