Skip to main content

A Biopharmaceutical Company Automates Partner SFTP Into Internal SMB Storage With an Outbound-Only Files.com Agent

The Agent kept the company's internal file servers behind the firewall while Files.com added centralized automation, audit logging, and identity governance on top of them.

A commercial-stage biopharmaceutical company brought its first oncology drug to market.

Commercialization changed the shape of the company's data. A drug on the market means an external ecosystem: vendors, clients, and data providers, all exchanging files with the company, many of them carrying HIPAA-covered information, under compliance obligations that also span GDPR, SOX, and 21 CFR Part 11. When the company reached that point, it wanted one managed transfer layer built for that ecosystem, in place before the counterparties multiplied.

The company selected Files.com to be that managed transfer layer: a hosted exchange perimeter outside the firewall, with an outbound-only bridge to the storage inside it.

Three Storage Tiers and No Single Interface Over Them

The company's external counterparties exchange mostly small CSV files, some ad hoc and some on a schedule. The company wanted every one of those exchanges to run on its own, into one governed place, with a record of each transfer. Its storage was spread across two collaboration clouds and an internal file-server tier, with no single interface over the three and no automation between them.

The scale ahead set the timeline. The company's plans called for onboarding dozens of external vendor and client users, each of them a new stream of files that needed a governed place to land.

The internal tier was the hard part. It speaks SMB behind an Azure perimeter where even outbound traffic is restricted under formal change control. A plain hosted SFTP endpoint would collect partner files in the cloud and strand them there, with no route into the storage where internal teams actually work. Exposing the file servers to the internet was never a possibility. And building and operating managed file transfer infrastructure in-house was not on the table for a company whose engineering is oncology.

So the fix had a specific shape. It had to be a hosted SFTP service that partners could reach with whatever client they already use. It had to reach internal SMB storage without exposing it. Access had to come from the corporate directory rather than a hand-maintained user list. File movement had to run on its own. And it had to carry the agreements regulated data requires, a HIPAA business associate agreement and a GDPR data processing agreement among them.

An SFTP Perimeter in the Cloud, an Agent Behind the Firewall

On the outside, vendors, clients, and data providers connect over SFTP to an endpoint on the company's own branded domain, using the standard clients they already have. The company hosts and patches nothing to make that possible.

On the inside, the Files.com Agent was installed on an internal server. The Agent connects outbound to the Files.com cloud, so there is no inbound firewall rule and no service listening on the company's network. The only network change the deployment required was a single outbound port, opened through the company's Azure change-control process. Through the Agent and Files.com Remote Server Mounts, the internal SMB storage became reachable to the platform: transfers land in it and pull from it as if it were cloud storage, while the servers themselves stay where they always were.

Between the two, Files.com Automations and Sync move files between the cloud exchange and internal storage, on schedules, with every run recorded in a centralized log. That log is the audit trail behind every transfer, and nobody has to assemble it.

Access is governed from the directory. Users sign in through SSO against Azure AD, and SCIM provisioning creates and removes accounts as the directory changes, including an administrator group provisioned as a group rather than person by person.

One Governed Exchange for Every Counterparty

With Files.com in production, the company runs every partner exchange through a single governed channel.

  • Partner and data-provider exchange now runs through one SFTP channel on the company's own domain, and adding the next external counterparty means provisioning an account on that channel.
  • Internal file servers participate in external exchange without being reachable from the internet: the entire on-premises footprint is one Agent and one outbound port, and nothing internet-facing runs inside the company's network.
  • Every transfer is centrally logged, giving the company an audit trail behind obligations spanning HIPAA, GDPR, SOX, and 21 CFR Part 11, with a GDPR data processing agreement executed with Files.com.
  • File access follows the corporate directory: accounts appear and disappear with SCIM, and no one administers file users by hand.

The compounding change is that growth adds no handling: each new vendor, client, or scheduled feed rides the same channel, under the same identity governance, into the same log.

The File Infrastructure the Company Never Had to Build

Today, when a data provider sends a file, it arrives over SFTP on the company's domain, moves to the internal storage where teams work without anyone touching it, and leaves a record behind. The company's counterparties see one endpoint, and its teams see files in the storage they already use.

The company's business is oncology, not file infrastructure. Files.com gave it a compliant managed-transfer perimeter in front of the storage it already runs, without building MFT infrastructure and without moving data off the servers where it lives.

Get The File Orchestration Platform Today

4,000+ organizations trust Files.com for mission-critical file operations. Start your free trial now and build your first flow in 60 seconds.

No credit card required • 7-day free trial • Live in minutes