How Diplomat Kept Its Outbound-Only DMZ While Moving Five SFTP Estates to Files.com

Diplomat is one of the five largest suppliers of fast-moving consumer goods in Israel by market share, and the only distributor among them: the other four are manufacturers. The group imports, markets, and distributes branded products for international manufacturers through fully owned business units in Israel, Georgia, South Africa, New Zealand, and Cyprus, reaching more than 51,000 direct points of sale, from national retail chains to rural kiosks served by van. SAP runs the distribution process in most business units, and Power BI reports on it.
A distributor's position is the middle. On one side sit the manufacturers whose brands it carries; on the other, the retail chains, pharmacies, wholesalers, and foodservice customers it supplies. What flows between them, continuously and mostly without a person involved, is data, moving as files between Diplomat's systems and those of its suppliers, customers, and sister companies. Unattended file exchange is not a side function at Diplomat. It is how the business connects to its trading partners, and it feeds the ERP and BI systems the whole operation runs on.
Diplomat's mandate was demanding: consolidate the fragmented estate onto one SaaS platform hosted in Western Europe, patched by the vendor, with day-to-day administration staying with each country's IT team. The platform had to enforce geo-blocking and per-partner protocol restrictions centrally, keep an audit trail that answers which user touched which file and when, apply retention schedules that differ by business unit, and deliver partner files onto on-premise storage without opening an inbound connection or changing any of the systems that read them.
Five Servers, Five Firewalls, and No Record of Who Used Them
Each of the five business units ran its own on-premise SFTP/FTP server, administered by that country's IT team. Diplomat had outgrown running its partner-facing perimeter that way: five separate installations meant no consolidated user management, no unified audit trail, and security controls only as good as each local firewall.
The cost showed up first as questions nobody could answer. Ely Manevich, Senior System Security Engineer on Diplomat's global team, described what the legacy servers could tell him about who actually used them:
“The local FTP servers didn't have any login enabled. So I couldn't even see who used this stuff. All I have is this list of users who are set up. Some of them don't even work for the company anymore and are disabled, but they are still set up with FTP.”
It showed up next as hand work. Every new partner or temporary user was created manually on the relevant regional server, and when a file was too large for email, local IT built a temporary account, uploaded the file, sent a password-protected link, and passed the password along by email or a consumer messaging app.
And it showed up as controls that had to be maintained five times over. Diplomat blocks access from countries where it is not permitted to have clients, and on five independently operated servers that policy lived in five local firewalls. Manevich explained why the blocking is not optional:
“It's mostly enemy countries that we just don't want hackers to access, because we don't have clients there. We are not allowed to have clients there, so obviously no one is legitimately accessing our stuff here.”
Underneath all of it sat five servers that global IT had to keep patched and online, and no longer wanted to own.
Why the Servers Survived: Everything Downstream Read Local Disk
The servers lasted because they were more than endpoints. They were the landing pad. A partner pushed a CSV onto the server's hard drive, and a separate scheduled job picked it up off local disk and moved it onward, most importantly into the on-premise folder that a Power BI gateway read over CIFS. Every downstream consumer assumed files arrived on a local disk.
Diplomat's security model raised the bar further, and deliberately so. External files passed through an intermediate Windows host where Microsoft Defender scanned them before they reached the internal network, and connections crossed the DMZ boundary in one direction only, initiated from the LAN. A cloud platform that delivered partner files straight into the internal network would have broken the scanning hop and the one-way rule at the same time.
Diplomat selected Files.com to provide the new platform.
One Perimeter in the Cloud, One Agent Behind the Firewall
Files.com became the partner-facing perimeter for the whole group, and the Files.com Agent became the governed bridge between that perimeter and the on-premise systems that consume the files.
The perimeter is a single Files.com site on Diplomat's own branded domain with dedicated IP addresses, so a partner whitelists two addresses and connects over SFTP exactly as before. Countries Diplomat cannot serve are blocked by geolocation across the whole site, IP whitelisting applies site-wide and per user, plain FTP is confined to a single named partner's address, and retention runs per business unit: a month in one country, two weeks in another, five days for temporary files.
Delegation came before data. Diplomat configured SAML single sign-on through Entra ID, SCIM provisioning, and Active Directory group synchronisation so each country's IT team could create and manage partner users under its own regional branch, with no rights over anyone else's. Global IT owns the platform and its security posture. Consolidation centralized the governance without centralizing the work.
The Files.com Agent connected outbound only from a dedicated Windows server, so no inbound firewall rule existed. It moved partner uploads from Files.com to on-premise storage and exposed a Files.com folder as a local network path. The LAN host initiated the connection, and files still crossed the jump host where Defender scanned them before they touched the internal network. The segmentation model Diplomat designed is the segmentation model that runs.
A Supplier Feed Proved the Pattern, Then Every Region Followed
The first production workflow was a data feed from one of Diplomat's largest suppliers, a multinational manufacturer that pushes CSV files over SFTP for consumption in Power BI. The supplier was provisioned as an SFTP user, connected, and its files were routed to a designated folder, synced down through the Agent, and validated end to end on the existing on-premise gateway. The migration was deliberately scoped to processes: workflows moved to the new platform while legacy data stayed where it was.
With the pilot validated, the migration proceeded across all five business units. Each region moved in two phases, automated and system users first through the summer of 2025, then human users that autumn. The migration also cleaned house: only genuinely active accounts moved, and the departed employees still provisioned on the old servers were dropped rather than carried over. Each legacy server ran in parallel until its region was verified on Files.com, then was shut down.
All Processes Moved, and Half the Accounts Are Machines
The Israel pilot proved the pattern before the migration proceeded across all five business units. With the cutover complete and the five on-premise servers switched off, Diplomat replaced five independently administered transfer estates with one governed platform.
- Every file-transfer process in the group now runs on Files.com, and there is no regional legacy transfer estate left to patch, back up, or firewall.
- The question the old servers could never answer is now a query. Per-user connection and file-access history is searchable and exportable through the Files.com API, and the team runs monthly reporting on upload volumes.
- Controls that used to depend on five local firewalls are enforced once: geo-blocking, IP whitelisting, protocol restrictions, and per-business-unit retention all live in one place.
- Roughly half of all accounts on the site are system users running unattended server-to-server SFTP with suppliers and customers. Automation, the reason for the platform, is now its primary workload.
The pattern also compounds. Adding the next unattended partner feed is a folder and an SFTP credential, created by the local IT team under its own regional branch, inside the same scanned, segmented path to the systems that consume it. No new server, and no new firewall work.
“After using Files.com so far, we've managed to move all of our processes to Files.com.”
The Security Model Never Moved
Today the partner-facing side of Diplomat's file exchange lives on a vendor-managed platform in Western Europe, and the parts Diplomat cared most about did not move at all. Files still cross a jump host where Defender scans them before entering the internal network. The LAN still initiates every connection. Power BI still reads the same folder. What changed is who carries the perimeter: the patching and the internet exposure belong to Files.com now, and a security team that once could not say who used its transfer servers holds one audit trail across five countries. Diplomat did not trade its security architecture for the cloud. It moved the perimeter to Files.com and kept everything behind it exactly where it was designed to be.
Related Customer Stories

Transportation & Logistics
AAA Northeast Replaced Progress WS_FTP Without a Big-Bang Cutover
The migration preserved partner workflows with a hostname-and-credential change while Files.com made encryption, retention, identity, and auditing enforceable.
Read story →
Transportation & Logistics
FlightSafety Moves Oversized, Confidential Aviation Documents Beyond Email With Files.com
Each outside party signs in through a branded browser experience and reaches one permission-scoped folder through an account that expires on schedule.
Read story →
Transportation & Logistics
Need It Now Delivers Retires Its In-House File Server for Unattended SFTP Dispatch
One business-side manager moved client-isolated dispatch feeds to Files.com, where nightly manifests have arrived for three years without daily intervention.
Read story →