A Credit Union Replaced MOVEit With Files.com One Vendor Feed at a Time
A US credit union, a member-owned financial cooperative, serves the employees and retirees of a select group of employers.
The credit union, like most, delivers much of that service through outside vendors. A banking core provider, a digital banking platform, loan companies, and survey and marketing vendors all exchange files with the credit union, and dozens of vendor transfer jobs run every day between those vendors and the on-premises servers where the credit union's back-office automation processes them. For a regulated financial institution, every one of those transfers carries member data, and every one has to be governed.
Two Transfer Systems to Replace With One
By early 2025, that exchange ran on two systems the infrastructure team wanted gone.
The first was Progress MOVEit DMZ, a legacy managed file transfer product. The credit union had already shut most of it down: the web interface was disabled, external link generation was cancelled, and the remaining footprint was locked to vendor file transfers only. The second was a self-managed SFTP server in the credit union's own data center, which vendors connected to for push and pull, alongside an FTP/SFTP client that reached out to vendors' servers. That server was the credit union's to patch and keep online.
The credit union wanted the whole exchange behind its identity stack: every staff account in Okta, every transfer event in Exabeam, and every vendor credential issued under the credit union's minimum password length.
The cost showed downstream too. For many feeds, the host services team's automation carried a manual bolt-on step. After a file was FTP'd to the credit union, a job had to reach back out to its own FTP server, pull the file down, and save it on the server where processing expected it.
Staff needed a path too. SharePoint was deliberately locked to internal sharing only, and consumer file-sharing services were barred by cybersecurity policy. The credit union wanted one sanctioned, revocable way for an employee to send a large file, such as a zipped coaching video for outside instructors, to someone outside the credit union.
Frequent Live Feeds Ruled Out a Big-Bang Cutover
None of this could be swapped in a weekend. Every vendor feed was a live production dependency of the banking back office. The digital banking platform alone sends a small text file several times an hour, and other vendors send on hourly, daily, and quarterly cadences. Each cutover meant coordinating new credentials with an outside party, on that party's timeline. And the downstream automation expected each vendor's files in a specific folder on a specific on-premises server, so any replacement had to land files exactly where a legacy platform already expected them, on a schedule that ran ahead of the automation.
The requirements were clear before any product was. Vendors had to keep connecting over plain SFTP with nothing new to install. Staff web access had to run through Okta and nothing else. Every vendor credential had to meet the credit union's minimum password length, enforced by the platform. Logs had to stream to Exabeam. Files had to reach on-premises paths without opening an inbound firewall port. And staff needed a governed way to send a file to someone outside the credit union.
The credit union selected Files.com to be that single transfer layer, replacing both MOVEit and the data-center SFTP server and bringing vendor file exchange under the same regime as everything else the credit union operates.
Cloud SFTP for Vendors, the Agent for the Servers Behind the Firewall
On the vendor side, Files.com is now the endpoint the credit union's vendors connect to over SFTP. Each vendor lands in its own root-jailed folder with its own credential, held to an enforced minimum length, and its own IP whitelist, so each vendor sees only its own data. Vendor accounts are flagged as shared bot users, so the scripted logins that drive dozens of daily jobs are never broken by the credit union's password expiration policy.
For staff, Okta is the only way in. Web access runs through Okta SAML single sign-on, with Okta groups pushed to Files.com and mapped to folder permissions, and the whole experience runs on the credit union's own branded domain. Every login and file event streams to Exabeam, so transfer activity sits in the same SIEM as the rest of the credit union's security telemetry.
On the inside, the Files.com Agent closes the gap to the data center. Installed on the on-premises servers where vendor files are processed, the Agent holds an outbound-only connection to Files.com, so nothing was opened inbound through the firewall. Per-vendor Remote Server Syncs, supplemented by Files.com Automations for feeds with several destinations, land files on the exact paths the host services automation already watches, on schedules timed ahead of its runs. No job reaches back out to an FTP server to pull a file down, and in validation, a file dropped into a vendor folder appeared on the destination server within seconds.
A Piece-by-Piece Migration With a Fresh Credential for Every Vendor
The cutover itself was deliberately slow: vendor by vendor, in parallel with the systems being replaced. The vendor user list was exported from MOVEit and bulk-imported into Files.com by CSV, with the per-vendor folder structure created in the same pass. MOVEit and the old SFTP server stayed live throughout. Each vendor was moved only after its files were confirmed flowing end to end through internal processing on Files.com, and only then was the feed disabled on the old system.
The administrators split the vendor build-out, targeting a couple of migrations each week.
The migration doubled as a credential reset. Because every vendor was being issued a new credential anyway, every credential was issued under the enforced minimum length, and the credit union took on the extra vendor coordination to do it in one pass. The first per-vendor sync and the first multi-destination Automation were kept as templates, so each subsequent vendor was a repeat of a proven pattern rather than a new build.
External Sharing as a Deliberately Separate System
Alongside the vendor work, staff got their sanctioned outbound path. A credit union employee uploads a file to Files.com, copies a link, and pastes it into an email, with an expiration date on the link and the ability to revoke it at any time. The coaching video for outside instructors went out this way.
The credit union wanted this to be a separate system from SharePoint, not an extension of it.
One Platform, Nothing Left to Patch, Nothing Pulled by Hand
With the migration complete, the credit union runs its vendor file exchange on one governed platform. MOVEit is retired, the data-center SFTP server is retired, and the manual pull steps are out of the automation.
- The credit union's vendor feeds and dozens of daily transfer jobs run through Files.com, each vendor isolated in its own folder with its own credential and IP whitelist, and there is no transfer server left for the credit union to patch.
- Every vendor holds a fresh credential issued during the cutover, and the platform enforces the minimum password length on every one.
- Vendor files land directly on the on-premises paths where downstream automation picks them up, with no job reaching back to pull anything down first. In validation, Agent delivery took seconds.
- Staff reach the platform only through Okta, and every transfer event streams to Exabeam alongside the rest of the credit union's security logs.
Staff also now have a governed, revocable way to send a file to an outsider. And because the per-vendor sync and Automation were built as reusable templates, onboarding the next vendor feed is a folder, a credential, and a sync copied from a proven pattern.
One Governed Platform for Every Vendor Feed
Vendor file exchange now runs under the same regime as everything else the credit union operates. Identity is Okta, logging is Exabeam, and there is no transfer server of the credit union's own to keep online.
A year and a half into production, the team reports the platform still fits: a legacy MFT estate replaced piece by piece, with no vendor feed ever taken down before its replacement was proven. Moving each vendor was also the moment it received its fresh credential.
Related Customer Stories
A Global Market Operator Brings Small Data Vendors Into Its Marketplace With Files.com—Without Running Its Own SFTP
A branded intake for suppliers without delivery infrastructure stayed in place through an acquisition and now supports millions of API transactions a day.
Read The Story
A Merchant Payments Provider Scales EU-Resident Merchant Data Exchange Across Hundreds of Accounts With Files.com
The exchange has run for nine years, while a site-level setting has kept every file in EU storage throughout.
Read The Story
A Payments Processor Gives Thousands of Merchants Permanent, Account-Free FINTRAC Intake Through Files.com
A dedicated folder and non-expiring Share Link for each merchant turned manual compliance collection into repeatable infrastructure.
Read The Story
Get The File Orchestration Platform Today
4,000+ organizations trust Files.com for mission-critical file operations. Start your free trial now and build your first flow in 60 seconds.
No credit card required • 7-day free trial • Live in minutes