FLCBank Replaced Progress MOVEit With Files.com to Reunite Its Client-to-Vendor File Flow

Florida Capital Bank, N.A. (FLCBank) is a nationally chartered commercial bank headquartered in Jacksonville, Florida. It runs two businesses at once. In Florida, it is a commercial and specialty bank serving privately held businesses and professional firms. Nationally, it is a wholesale mortgage lender, funding loans for brokers and selling those loans on to larger buyers such as Fannie Mae and Freddie Mac.
Both businesses run on files exchanged with other institutions. Payment processors, merchants, and mortgage partners send files to the bank. The bank moves them onward to a third-party verification vendor and, for ACH, on toward the Federal Reserve. Deposit Operations and the Commercial Loan team work the same files internally. For a bank whose counterparties are institutions, the file transfer layer is not a back-office utility. It is where the business actually moves.
The Bank's Half of the Workflow Sat on a Platform Its Own Vendor Had Left
That layer ran on Progress MOVEit, the legacy managed file transfer platform. As a financial institution holding customer PII on the platform, FLCBank needed a governance and compliance story it could stand behind annually.
The misalignment went further. The bank's verification vendor had already moved from MOVEit to Files.com a couple of years earlier and built its automation and scripts there. The two halves of one workflow—the bank receiving files and the vendor collecting them—sat on different platforms.
Then MOVEit went down for two days. While it was down, the file traffic it carried stopped with it.
Platforms like this survive at banks for a reason. Every counterparty connection is a dependency: SFTP credentials, SSH keys, folder paths, and schedules that other institutions' own systems point at. Replacing the platform meant moving the entire external user base without breaking regulated payment and mortgage file flows in transit. That inertia keeps legacy MFT in place long after the reasons to leave have piled up.
The Cutover Started From a Spreadsheet
The replacement had a clear specification. It had to speak SFTP to the systems already connecting, give less technical clients a browser path with nothing to install, keep every counterparty walled into its own folder, and let the bank set up clients and schedules itself. It also had to come with a compliance package a bank holding PII could file annually: SOC 2 Type II and penetration-test evidence. One more fact tipped the choice. The verification vendor was already on Files.com, so landing there would put both halves of the workflow back on one platform.
FLCBank selected Files.com to replace MOVEit and carry the client-to-bank-to-vendor exchange.
The cutover started from a spreadsheet listing every MOVEit user. The bank bulk-imported the list into Files.com, and because Files.com created a home folder automatically for each new user, every counterparty arrived with its own folder, full access to it, and no reach into anyone else's. Most of those users were systems rather than people. They continued connecting over SFTP with SSH keys, while GPG encryption and user-specific IP whitelisting protected each exchange. Clients without technical teams used the Files.com web interface on the bank's own domain, so what a merchant saw was FLCBank.
Internal access was layered on second. Deposit Operations and the Commercial Loan team received folder permissions onto the same per-partner folders, so the file a processor dropped was the file bank staff worked, with no copy into a second system. Files.com email notifications on file activity went to distribution lists in the bank's mail system, so the teams who needed to know a file had landed found out in their inbox without each person holding a Files.com account.
The bank went live on that foundation of SFTP, folder permissions, user management, and IP whitelisting.
Both Sides on One Platform
With the Files.com workflow in production, FLCBank replaced a legacy MFT platform its own vendor had left with the platform both sides of the exchange now use.
- The client-to-bank-to-vendor flow now runs on one platform: inbound ACH and mortgage files land in per-partner folders, and the verification vendor's existing Files.com automation collects from those same folders.
- For ACH, Files.com governs the inbound exchange through verification; the files then continue onward toward the Federal Reserve.
- The annual due diligence answer changed. The bank now files Files.com's SOC 2 Type II and penetration-test evidence for the platform holding its PII.
- Onboarding the next counterparty is the bank's own work. Creating the user generates its folder; the bank sets the keys, permissions, and allowlist itself.
One Platform to Answer For
The larger lesson is the one legacy MFT operators tend not to believe: replacing the platform under a regulated, multi-party file flow did not require counterparties to adopt a new way of connecting. FLCBank imported its user base, stood up SFTP and folder permissions first, and its counterparties kept connecting the way they always had. The platform changed underneath them.
Related Customer Stories
Banking & Finance
Nasdaq Data Link Brings Small Data Vendors Into Its Marketplace With Files.com—Without Running Its Own SFTP
A branded intake for suppliers without delivery infrastructure stayed in place through the Quandl acquisition and now supports roughly three million API transactions a day.
Read story →
Banking & Finance
TMX VettaFi Moved Daily Index Distribution From Consultant-Run MFT To Files.com—Without A Cutover Day
VettaFi bulk-synced years of history and migrated institutional clients one at a time while daily index publication continued.
Read story →
Banking & Finance
Moelis & Company Replaced GlobalScape EFT With Files.com—Without Rebuilding 15 Years of File Flows
Moving the bank’s sensitive production transfers took a flow-by-flow lift-and-shift that preserved its encryption, service accounts, and surrounding integrations.
Read story →