Coalition Put a File Interface Over Forensic Evidence With a Files.com Amazon S3 Mount
Coalition is a cyber insurance provider that underwrites and services cyber policies while running incident response alongside its insurance business. That work includes forensic imaging and handling artifacts that establish how an incident happened.
Forensics produces evidence, and evidence means files. Disk images and attack artifacts accumulate with every engagement, and some of them are enormous. A single forensic archive can reach 550 GB in one .tar file. Coalition needed ordinary file access to that evidence without moving it out of Amazon S3 or creating a second copy—and it needed that access governed through Okta. Files.com’s S3 Remote Server integration provided that layer.
A 550 GB Artifact Rules Out a Second Copy
Amazon S3 gave Coalition object storage independent of any one machine. What S3 does not give a team on its own is a file interface. It is object storage reached through APIs and consoles, not folders a responder browses with permissions tied to the company directory.
Uploading the archive into a file platform’s own storage would have meant copying half a terabyte per case into a second store and holding the evidence in two places. The answer had to leave the data resident in Coalition’s bucket while giving the incident response team ordinary file operations over the artifacts.
Files.com as the Doorway, S3 as the Storage
In November 2023, Coalition’s IT team tested the Files.com integration against real forensic data before putting it into production. Rather than syncing copies into Files.com, the team settled on mount mode. The folders on the Files.com site are the bucket, and Files.com performs file operations directly against it while the objects stay in Amazon S3.
Today, a responder who needs an artifact opens a folder. A 550 GB tar behaves like any other file in that folder, while the evidence remains in Coalition’s bucket.
The site itself is governed from Okta: users and groups are provisioned and deprovisioned automatically over SCIM, sign-in runs through single sign-on, and connections are restricted by IP allowlist. Putting the evidence behind Files.com put it behind that whole stack, with nothing extra to build.
Evidence Access With Minimal Administration
With the mount in production, Files.com became the shared access layer for Coalition’s forensic evidence rather than another storage destination. Responders work with artifacts as files and folders, while account access continues to follow Coalition’s directory.
The access layer also takes almost no effort to operate. Coalition’s IT team reports barely needing to touch the platform once the mount was in place.
A File Interface, Not a Destination
Coalition never migrated its forensic archive onto a file platform. It kept the archive in the Amazon S3 bucket it already used and made that bucket behave like one: folders, directory-governed access, and half-terabyte files handled as files.
For evidence this large, the answer was never to move the data. It was to put a file interface in front of where the data already lives.
Related Customer Stories
Insurance
BroadTech Retired Its FTP Servers Without Re-Integrating Its Partner Network
Files.com preserved the clients and automations BroadTech’s partners already used while adding encryption, auditability, and managed infrastructure.
Read story →
Insurance
Old Republic Replaced Box with Files.com During Its PHI Backend Migration to Azure
A governed SFTP perimeter secured chain of custody immediately without forcing 15 hospital partners to follow the infrastructure behind it.
Read story →
Insurance
CNO Financial Group Met a File-Level Encryption Mandate on Files.com Instead of an Emergency SFTP Upgrade
An existing regulated partner hub let the insurer onboard business its on-premises environment could not support without upgrades coordinated across outside organizations.
Read story →