Flagship Financial Group Used Files.com to Phase Out Self-Hosted SFTP Without a Big-Bang Cutover
Flagship Financial Group is a nationally licensed specialty finance lender for non-prime auto borrowers. It originates and purchases vehicle loans through franchise and independent dealerships across the United States, refinances auto loans directly for consumers, and services every loan it holds itself. It works with a network of 15,000 dealerships nationwide.
Running origination, funding, and servicing in-house means Flagship's systems constantly exchange data with everyone else's. Documents come in from dealers. Batch loan data moves between internal systems and outside counterparties. For years, that exchange ran through an SFTP server Flagship hosted itself, until the company phased it out with Files.com and brought exchange access under directory-based governance.
An SFTP Server the Security Team Had to Own
The server carried the company's partner file exchange, a workload that typically moves more than 250 GB a month and sometimes runs into terabytes. The infrastructure team owned the machine, the patching, and the uptime. It also owned every account on it, created and maintained by hand, separate from the Active Directory that decided access everywhere else in the company. And when employees needed to share files quickly, Dropbox filled the gap, so ad-hoc sharing ran outside the security model too.
The problem was not that the server was failing. It was that a lender's security team owned a machine, a set of hand-managed accounts, and a consumer sharing tool on the side, and the company's own identity system governed none of it. At Flagship, infrastructure and information security sit in the same team.
What the Replacement Had to Keep Running
None of it could simply be switched off. Partner connections pointed at the old server. An internal file server held the files. ActiveBatch, Flagship's ETL scheduler, orchestrated batch loan-data transfers through the estate. SharePoint carried internal collaboration and was staying.
That set the requirements. The replacement had to speak the protocols partners already used, so nothing broke on their side. It had to reach the internal file server without exposing it to the internet. It had to put internal users and outside guests under the same Active Directory security groups. And it had to run alongside the old server long enough to move the work over safely. Flagship selected Files.com to be that exchange layer.
An Outbound Agent and a Parallel Run
The team installed the Files.com Agent inside its own network. The Agent makes an outbound-only, encrypted connection to the platform, so the internal file server appears as a Files.com folder with no inbound firewall change and no server opened to the internet.
The old SFTP service kept running in parallel through the transition. As work moved to the platform, the team ran a final sync and shut the old service down. There was no big-bang cutover, and no partner had to hold their breath through one.
The batch feeds moved without a rewrite. ActiveBatch keeps orchestrating the loan-data transfers, and those files now feed Files.com Automations over the Agent mount, which route them onward with retries and a logged outcome for every run.
SharePoint stayed exactly where it was. Flagship connected it to Files.com as a remote server and sync target, so content living in SharePoint reaches the same governed exchange layer without anyone changing where they work.
Entra ID and Active Directory Govern Access
Employees sign in through Entra ID single sign-on, and SCIM provisioning creates and deactivates their Files.com accounts from the directory automatically. Active Directory security groups then determine which folders those accounts can reach. A new hire has access when the directory says so. A departure loses it the same way, with no file account left for anyone to remember to close.
Permissions follow those security groups, applied to folders rather than to individual users. The same groups that govern access inside the company decide which folders anyone can reach on Files.com. External counterparties get guest accounts that only administrators create, which puts an outside user inside that same group-based model rather than through a side door, and two-factor authentication applies to external users as well.
Protocol access is set at the group level, and a new user starts with web and API access only. SFTP, FTP, or WebDAV get granted when a workload needs them, never by default.
Terabyte Months With No Server to Patch
With the Files.com workflow in production, Flagship replaced a server it had to maintain with an exchange layer its directory governs.
- The internal file server was connected about three weeks after the site went live in June 2024, and the on-premises SFTP service was retired after the parallel run and a final sync.
- Partner file exchange with the dealership network, at more than 250 GB a month and sometimes terabytes, now moves through Files.com with no machine for Flagship to patch, back up, or defend.
- Access follows the directory: Entra ID provisions and deactivates employees automatically, and Active Directory security groups decide folder access for employees and outside guests alike.
- File access is now evidence, not a mystery: Files.com logs who opens which files, and the security team reviews that history as part of its routine security work.
The adoption plan was deliberate: start with the first couple of use cases, then add more when ready. That pattern is now how new work arrives. A new workload lands as a folder and a group, and it inherits the identity model, the protocol restrictions, and the audit trail the moment it does, with no new account store and no new server. Ad-hoc sharing followed the same path. Every user gets an auto-created personal folder for individual uploads and sharing alongside managed team folders, and Dropbox came out of the estate.
The Server Went Away and the Governance Got Stronger
The value of the phased retirement was not only that the machine disappeared. A self-hosted SFTP estate came out in weeks, and the security model got tighter on the way out, not looser.
Related Customer Stories
Banking & Finance
Nasdaq Data Link Brings Small Data Vendors Into Its Marketplace With Files.com—Without Running Its Own SFTP
A branded intake for suppliers without delivery infrastructure stayed in place through the Quandl acquisition and now supports roughly three million API transactions a day.
Read story →
Banking & Finance
SumUp Scales EU-Resident Merchant Data Exchange Beyond 500 Accounts With Files.com
The exchange has run for nine years, while a site-level setting has kept every file in EU storage since 2018.
Read story →
Banking & Finance
Bambora North America Gives Thousands of Merchants Permanent, Account-Free FINTRAC Intake Through Files.com
A dedicated folder and non-expiring Share Link for each merchant turned manual compliance collection into repeatable infrastructure.
Read story →