Skip to main content

Carnegie Replaces Hundreds of One-Off College Data Exchanges With One Files.com Workflow

The same operating layer now moves campaign leads into Slate, gives remote teams a shared record of client deliveries, and anchors Carnegie’s answers to university security reviews.
Carnegie Higher EducationFiles.com

Carnegie is a marketing and enrollment strategy firm for nonprofit higher education. Hundreds of colleges and universities work with it, from small community colleges to large state and private institutions, on research, brand strategy, digital campaigns, lead generation, financial aid modeling, and web development.

Nearly everything Carnegie does for a client ends in data changing hands. A lead-generation campaign produces prospective-student records that have to land inside the institution's own CRM, which for Carnegie's clients means Slate, fed by file import over SFTP. Financial aid modeling runs on sensitive student and institutional data. Strategy and creative work produces deliverables that a client's staff need to receive and Carnegie's own teams need to track. And Carnegie does this at scale, with a workforce that is almost entirely remote across multiple time zones, at a company that has grown through acquisitions, each arriving with its own people and its own data.

Hundreds of institutional clients means hundreds of separate endpoints for sensitive data.

Hundreds of Endpoints and No Standard Way to Reach Them

Exchange with each client was its own arrangement. Lead data from Carnegie's campaigns had no standard intermediary on the way to a client's CRM; every connection was worked out case by case. Deliverables had to reach client contacts one relationship at a time, and inside Carnegie, several staff typically worked on a single institution, each needing to see what had been provided and when. Meanwhile the company's own sensitive internal data, including finance and HR records, sat spread across multiple locations.

Carnegie had outgrown per-client arrangements. The counterparty count kept climbing, a bespoke channel per institution did not scale, a fully remote team could not coordinate any of it in a hallway, and every acquisition added more people and more data. The cost landed in the worst possible place: Carnegie's own clients were exactly the kind of organization that scrutinized its vendors. Colleges and universities sent security questionnaires and SOC 2 requests, and a firm whose sensitive data lived in several places had no single answer to give them.

Whatever carried this work had to do several things at once. Sit between the campaign systems and hundreds of client CRMs without custom development per client. Speak SFTP, the way those CRMs took file imports. Give remote staff a way to hand a deliverable to a client contact without provisioning an account for every one of them. Enforce one security policy, from sign-in to account lifecycle, across all of it. And be a place Carnegie's own internal data could live too.

The whole reason for going to Files.com, was to get all our sensitive data in one location under lock and key.
Jeffrey Cerny, Primary Admin, IT Systems & Support, Carnegie

Carnegie selected Files.com to be that layer: the exchange fabric with its clients and its own secure repository at once.

A Folder, a Share Link, and an SFTP Feed for Every Institution

On Files.com, every client relationship follows the same pattern instead of its own arrangement.

On the automated side, Zapier routes lead data from Carnegie's campaigns into Files.com, and Files.com Automations carry each file onward over SFTP into that client's Slate source folders. The route is standing infrastructure: adding an institution means adding a destination to a pattern that already exists, not building an integration.

On the human side, each institution has its own client folder on the site. There are more than 500 of them, and most carry a Files.com share link with its own access controls, so a client contact opens the link in a browser with no account to create and nothing to install. More than 800 links are active. Inside Carnegie, the folder doubles as the record of the relationship: everyone working on that client can see what has been delivered and when, whatever time zone they sit in.

One Security Policy, From Sign-In to Dormant Accounts

Access to all of it follows Carnegie's directory. Staff sign in through SSO against Azure AD and JumpCloud, SCIM provisioning creates and updates accounts from the directory, and creating users by hand outside SSO is restricted. Files.com User Lifecycle Rules disable accounts that go inactive, two-factor authentication is enforced globally, IP whitelisting narrows where connections can come from, and group-based permissions decide who reaches which folders.

The same controls made the platform the home for data that has nothing to do with clients. Carnegie pulled internal finance and HR data out of the multiple locations it had spread across and into the same repository, under the same sign-in, the same permissions, and the same lifecycle rules as everything else.

The Next Client Is a Folder, and the Next Security Review Has an Answer

With Files.com carrying the work, Carnegie replaced per-client arrangements with one repeatable exchange pattern, and scattered sensitive data with a single controlled repository.

  • Hundreds of higher-education institutions are served through the same pattern, and onboarding the next one is a folder, a share link, and an SFTP destination rather than a new project.
  • When a client institution sends a security questionnaire or a SOC 2 request, Files.com is part of Carnegie's answer. The platform is presented to Carnegie's own clients as part of its security posture.

The pattern also absorbs growth without anyone tending it. As divisions came onto the platform and acquisitions added staff, access followed the directory: new people are provisioned automatically, departing people lose access automatically, and dormant accounts shut themselves off.

We are using you as our secure file repository and transfer system.
Jeffrey Cerny, IT Systems & Support, Carnegie

One Answer to Where the Data Lives

Carnegie's business runs on being trusted with other institutions' student data. That trust used to rest on exchange arranged client by client and on sensitive data held in several places, with nothing to point a reviewer at. Today a strategist working from anywhere shares a deliverable through the same Files.com platform that moves a campaign's leads into a client's CRM, and when a university's security team asks Carnegie where sensitive data lives and how it moves, there is one answer to give. The exchange layer stopped being plumbing arranged per client and became something Carnegie shows its clients.