Skip to main content

From Kleopatra to Files.com: A Beverage Distributor Moved PGP Encryption Out of the Data Center

A business systems manager built the encrypted payroll and benefits automations in a browser, with on-platform PGP, audit logs, and event-triggered email notifications.

A regional beverage distributor sells soft drinks, beer, wine, and spirits across several states, through a network of distribution centers and thousands of employees.

A company shaped like that runs on data moving between systems. Its people are spread across several states, and the platforms that pay them and administer their benefits are SaaS products run by other vendors. The hours a field rep punches into the Green Mile application have to reach UKG payroll. COBRA benefits files have to reach the company's benefits administrator, PGP-encrypted. None of those systems talk to each other directly. Files carry the data between them, and for years, the machinery that moved those files lived in the distributor's own data center. When the company prepared to exit that data center, PGP encryption for payroll and benefits still depended on Kleopatra installed on one local machine.

Payroll Hours, a Scheduled Task, and a Desktop Utility

The pipeline that fed UKG showed how these feeds ran. A PowerShell script on an on-premises server, kicked off by a scheduled task, pulled a file of employee punch hours from the Green Mile API. Before that file could go out, it had to be PGP-encrypted, and that job belonged to Kleopatra, a desktop encryption utility installed locally on the machine. The script then placed the encrypted result on UKG's SFTP site. The COBRA benefits feed carried the same requirement: sensitive files, encrypted before delivery.

The cost of that design was where it lived. Payroll data for thousands of people had one specific machine in its path. The encryption was not a property of the workflow. It was a property of one desktop install, and everything downstream depended on that machine.

The Data Center Exit Left the Encryption Nowhere to Run

The pipeline ran daily for years. What changed was structural. The distributor committed to exiting the data center, and the on-premises servers hosting the scheduled tasks were being deprecated. The pipelines could not simply be re-pointed at new hardware, because the encryption step was welded to a locally installed desktop application. The encrypt and decrypt function itself had to move somewhere.

The replacement had to encrypt and decrypt files with counterparties' keys inside the transfer, deliver on schedule to the SFTP endpoints those counterparties already ran, keep a record of every run, and send an email when something happened. And it had to be operable by the distributor's business systems team, because these are business feeds, not an engineering product.

The distributor selected Files.com to carry the encrypted feeds.

Encryption as a Folder Setting, Delivery as an Automation

On Files.com, each feed is a folder and a rule rather than a script and a machine. When a punch-hour file reaches its folder, Files.com's on-platform PGP encrypts it automatically with UKG's public key, and a Files.com Automation delivers it over an outbound SFTP connection to UKG's server. The COBRA feed runs the same way, syncing files out PGP-encrypted to the benefits administrator's endpoint, and inbound encrypted files decrypt on the platform. No desktop utility touches any of it. The Kleopatra install was retired. Staff reach the site through the company's existing Entra ID sign-in, with MFA enforced.

The IT manager who runs the distributor's business systems built these automations herself, in the browser, without an engineering project. She names the logging and the event-triggered email notifications as the capabilities that matter most to her team: every run is recorded, and the platform emails when an event fires.

Encryption With No Desktop in the Path

With the feeds in production on Files.com, the distributor replaced a machine-bound encryption step with a workflow the platform runs and records.

  • PGP encryption and decryption for punch hours and COBRA benefits files run with no desktop utility and no particular machine hosting that step. Encryption happens inside the transfer, on every file, the same way every time.
  • Every automation run lands in the log, and event-triggered emails tell the team what moved.
  • The encrypted feeds cleared the data center exit. Encryption and delivery no longer run on servers the company has to keep alive.
  • The next counterparty that requires PGP is a folder, a key, and an automation, built by the business systems team in the browser rather than scoped as an engineering project.

Encryption That Belongs to the Workflow

The distributor did not find a new machine for the encryption step. It stopped being a machine's job at all.

Get The File Orchestration Platform Today

4,000+ organizations trust Files.com for mission-critical file operations. Start your free trial now and build your first flow in 60 seconds.

No credit card required • 7-day free trial • Live in minutes