Skip to main content

Chevron Federal Credit Union Replaced Progress MOVEit DMZ and On-Premises SFTP With Files.com—One Vendor Feed at a Time

The phased migration kept live banking feeds running while bringing credentials, identity, logging, delivery, and external sharing under one governed Files.com platform.
Chevron Federal Credit Union (CFCU)Files.com

Chevron Federal Credit Union is a member-owned financial cooperative in the top 1% of US credit unions by asset size, with more than $4.8 billion in assets and over 100,000 members around the world. Founded in 1935, it serves the employees and retirees of Chevron, Bechtel, and a select group of other employers, including expatriates on international assignment who bank with CFCU without ever holding a US Social Security number.

Like most credit unions, CFCU delivers much of that service through outside vendors. A banking core provider, a digital banking platform, loan companies, and survey and marketing vendors all exchange files with the credit union, and dozens of vendor transfer jobs run every day between those vendors and the on-premises servers where CFCU's back-office automation processes them. For a regulated financial institution, every one of those transfers carries member data, and every one has to be governed.

Two Aging Transfer Systems, and No Sanctioned Way to Send a File Out

By early 2025, that exchange ran on two systems the infrastructure team wanted gone.

The first was Progress MOVEit DMZ, a legacy managed file transfer product with a well-publicized security history. CFCU had already shut most of it down: the web interface was disabled, external link generation was cancelled, and the remaining footprint was locked to vendor FTP transfers only. The second was a self-managed SFTP server in CFCU's own data center, which vendors connected to for push and pull, alongside an FTP/SFTP client that reached out to vendors' servers. That server was CFCU's to patch and keep online.

Neither system sat behind the credit union's identity stack. Accounts lived outside Okta, transfer activity was invisible to Exabeam, and the vendor credentials told the story of an estate that had grown without governance: some passwords shorter than 16 characters, some unchanged in seven years.

The cost showed downstream too. For many feeds, the host services team's automation carried a manual bolt-on step. After a file was FTP'd to CFCU, a job had to reach back out to the credit union's own FTP server, pull the file down, and save it on the server where processing expected it.

And for people, there was no path at all. SharePoint was deliberately locked to internal sharing only, consumer file-sharing services were barred by cybersecurity policy, and a previous external sharing service had lapsed. When an HR employee needed to deliver a 125 MB zipped coaching video to outside instructors, there was no compliant way to send it.

Live Feeds Every Ten Minutes Ruled Out a Big-Bang Cutover

None of this could be swapped in a weekend. Every vendor feed was a live production dependency of the banking back office. The digital banking platform alone sends a 300–400 KB text file every ten minutes, and other vendors send on hourly, daily, and quarterly cadences. Each cutover meant coordinating new credentials with an outside party, on that party's timeline. And the downstream automation expected each vendor's files in a specific folder on a specific on-premises server, so any replacement had to land files exactly where a legacy platform already expected them, on a schedule that ran ahead of the automation.

The requirements were clear before any product was. Vendors had to keep connecting over plain SFTP with nothing new to install. Staff web access had to run through Okta and nothing else. Password standards had to be enforceable rather than aspirational. Logs had to stream to Exabeam. Files had to reach on-premises paths without opening an inbound firewall port. And staff needed a governed way to send a file to someone outside the credit union.

CFCU selected Files.com to be that single transfer layer, replacing both MOVEit and the data-center SFTP server and bringing vendor file exchange under the same regime as everything else the credit union operates.

Cloud SFTP for Vendors, the Agent for the Servers Behind the Firewall

On the vendor side, Files.com is now the endpoint roughly a dozen vendors connect to over SFTP. Each vendor lands in its own root-jailed folder with its own credential, held to a 16-character minimum, and its own IP whitelist, so each vendor sees only its own data. Vendor accounts are flagged as shared bot users, so the scripted logins that drive dozens of daily jobs are never broken by CFCU's password expiration policy.

For staff, Okta is the only way in. Web access runs through Okta SAML single sign-on, with Okta groups pushed to Files.com and mapped to folder permissions, and the whole experience runs on CFCU's own branded domain. Every login and file event streams to Exabeam, so transfer activity sits in the same SIEM as the rest of the credit union's security telemetry.

On the inside, the Files.com Agent closes the gap to the data center. Installed on the on-premises servers where vendor files are processed, the Agent holds an outbound-only connection to Files.com, so nothing was opened inbound through the firewall. Per-vendor Remote Server Syncs, supplemented by Files.com Automations for feeds with several destinations, land files on the exact paths the host services automation already watches, on schedules timed ahead of its runs. No job reaches back out to an FTP server to pull a file down, and in validation, a file dropped into a vendor folder appeared on the destination server within seconds.

A Piece-by-Piece Migration That Reset Seven Years of Credential Debt

The cutover itself was deliberately slow: vendor by vendor, in parallel with the systems being replaced. The vendor user list was exported from MOVEit and bulk-imported into Files.com by CSV, with the per-vendor folder structure created in the same pass. MOVEit and the old SFTP server stayed live throughout. Each vendor was moved only after its files were confirmed flowing end to end through internal processing on Files.com, and only then was the feed disabled on the old system.

Two administrators split the vendor build-out, targeting a couple of migrations each week.

The migration also became the lever for a credential reset that would have been hard to force any other way. Because every vendor was being issued a new credential anyway, every credential was issued under the enforced 16-character minimum. CFCU accepted more vendor coordination in exchange for retiring passwords that had gone seven years without rotation. The first per-vendor sync and the first multi-destination Automation were kept as templates, so each subsequent vendor was a repeat of a proven pattern rather than a new build.

External Sharing as a Deliberately Separate System

Alongside the vendor work, staff got their sanctioned outbound path. A CFCU employee uploads a file to Files.com, copies a link, and pastes it into an email, with an expiration date on the link and the ability to revoke it at any time. The 125 MB coaching video that had no compliant route went out this way.

CFCU wanted this to be a separate system from SharePoint, not an extension of it.

We really like the idea of having to go to a separate system for external file sharing so that it's more intentional, and there's less of a chance to accidentally share something externally.
Chris Kahila, Sr. Systems Administrator, Chevron Federal Credit Union

One Platform, Nothing Left to Patch, Nothing Pulled by Hand

With the migration complete, CFCU runs its vendor file exchange on one governed platform. MOVEit is retired, the data-center SFTP server is retired, and the manual pull steps are out of the automation.

  • Roughly a dozen vendor feeds and dozens of daily transfer jobs run through Files.com, each vendor isolated in its own folder with its own credential and IP whitelist, and there is no transfer server left for CFCU to patch.
  • Seven years of accumulated credential debt was cleared in one pass, and the 16-character minimum is now enforced by the platform rather than by a policy document.
  • Vendor files land directly on the on-premises paths where downstream automation picks them up, with no job reaching back to pull anything down first. In validation, Agent delivery took seconds.
  • Staff reach the platform only through Okta, and every transfer event streams to Exabeam alongside the rest of CFCU's security logs.

Staff also now have a governed, revocable way to send a file to an outsider, where before there was no sanctioned path at all. And because the per-vendor sync and Automation were built as reusable templates, onboarding the next vendor feed is a folder, a credential, and a sync copied from a proven pattern.

Vendor File Exchange Under the Same Rules as Everything Else

Today, the exception is gone. Vendor file exchange used to be the part of CFCU's estate that lived outside the rules, with its own server to patch, its own aging passwords, and activity no SIEM could see. Now it runs under the same regime as everything else the credit union operates.

A year and a half into production, the team reports the platform still fits: a legacy MFT estate replaced piece by piece, with no vendor feed ever taken down before its replacement was proven. The act of moving each vendor was the moment its years-old password was finally retired.