Skip to main content

CompoSecure Keeps Vendor Card Artwork Out of SharePoint With Files.com

Files.com gives each outside counterparty a tightly scoped workspace protected by app-based MFA, account expiration, and scheduled file retention.
CompoSecureFiles.com

CompoSecure designs and manufactures premium metal payment cards and secure authentication products for banks, fintechs, and card issuers around the world. It sits inside the payments supply chain, and it carries the security posture that position demands.

Building a card program is outward-facing work. Artwork moves between CompoSecure and outside card-graphics vendors. Contract manufacturers exchange files on the programs they build. Finance files move between affiliated companies under the corporate parent, GPGI. That work puts sensitive files in motion across company lines, and a supplier to leading card issuers cannot let that movement go ungoverned.

Vendors Need the Files, Not a Way Into SharePoint

Inside CompoSecure, collaboration runs on SharePoint. Outside it, the counterparties change with every project: a graphics vendor on one card program, a contract manufacturer on the next, finance teams at corporate affiliates. Each of them needs files. None of them needs an account inside the company's internal collaboration environment.

That was the standing problem. Sharing through SharePoint would put external accounts in the same environment as internal work, with access that somebody has to remember to remove when a project ends. Sharing around SharePoint would send sensitive artwork and financial data out with no identity control, no limit on how long files persist, and no MFA standard applied to the people receiving them. Either way, the company would carry risk on every exchange, on every project, indefinitely.

CompoSecure refused both. The diagnosis was simple: external file exchange is a different job from internal collaboration, and it needed a platform of its own. Sharing with outside partners is deliberately routed away from SharePoint on security grounds, and SharePoint stays what it was meant to be: internal. And the bar was not standing still. Over the life of the deployment, the company's security requirements kept rising, and its security team kept tightening the controls on the exchange platform to match.

One Site That Holds Two Populations to Two Standards

What that platform had to do was specific. Employees needed to sign in through the corporate directory, with no separate credentials and no redundant MFA prompts on top of a login the directory had already verified. Outsiders needed the opposite treatment: access scoped to exactly one partner's folder, mandatory MFA from an authenticator app rather than SMS or email, accounts that end on a date, and files that delete themselves on a schedule instead of accumulating. One platform had to hold both populations at once, each to its own standard.

CompoSecure selected Files.com as that dedicated external exchange layer.

Employees sign in through Microsoft Entra ID single sign-on, so the corporate directory authenticates them. For everyone else, CompoSecure configured Files.com's conditional two-factor enforcement: any user not covered by SSO must enroll in MFA, while SSO users are not prompted a second time for a login the directory has already authenticated. Company policy goes further and excludes SMS and email as MFA factors entirely. An outside user authenticates with an app or not at all.

Segmentation does the rest. Using Files.com folder-level permissions and groups, each counterparty is scoped to its own space: a card-graphics vendor reaches the artwork for its project and nothing else, a contract manufacturer sees only its own files, and finance transfers between GPGI affiliates run through folders of their own. Partner accounts carry expiration dates, so access created for a project ends with the project rather than waiting for someone to notice it. And Files.com retention rules delete shared files after a defined period, a limit CompoSecure set deliberately so that sensitive material never sits on an exchange surface longer than the work requires.

SharePoint Stays Internal, and the Next Vendor Is a Folder

With Files.com carrying the external workload, CompoSecure replaced a choice between two bad defaults with a standing pattern: outsiders get a scoped, expiring, MFA-protected space on Files.com, and SharePoint never opens to them at all.

Onboarding the next counterparty is a folder, a set of permissions, and an expiration date. The pattern applies itself to every new vendor and every new program, with nothing redesigned. As the company's security requirements rose, adoption grew across departments, and more of its external exchange moved onto the governed path.

Today, when a card program needs artwork in a vendor's hands, someone at CompoSecure puts it in that vendor's folder on Files.com. The vendor signs in behind app-based MFA, reaches that one folder, and both the files and the account expire on schedule. Nothing about the exchange touches the environment where CompoSecure's internal work lives.

For a business whose products secure payments for leading banks and card issuers, working with outside vendors never required opening the inside of the company to them.