Skip to main content

Geron Automates HIPAA-Covered Partner SFTP Into Internal SMB Storage With Files.com

An outbound-only Agent kept Geron’s Windows file servers behind the firewall while adding centralized automation, audit logging, and identity governance.
GeronFiles.com

Geron Corporation is a commercial-stage biopharmaceutical company built on one scientific idea: inhibiting telomerase, the enzyme that lets cancer cells divide indefinitely. The underlying science, telomere research by the company's early collaborators, won the 2009 Nobel Prize in Physiology or Medicine. Geron's product, RYTELO (imetelstat), is the first and only telomerase inhibitor approved in the United States and Europe, treating adults with lower-risk myelodysplastic syndromes who depend on red blood cell transfusions. It is sold in the United States and authorized across Europe.

Commercialization changed the shape of the company's data. A drug on the market means an external ecosystem: vendors, clients, and data providers, all exchanging files with Geron, many of them carrying HIPAA-covered information, under compliance obligations that also span GDPR, SOX, and 21 CFR Part 11. When Geron reached that point, it had no managed file transfer capability at all.

Geron selected Files.com to be that managed transfer layer: a hosted exchange perimeter outside the firewall, with an outbound-only bridge to the storage inside it.

Regulated Files, Handled by Hand

Geron's external counterparties exchange mostly small CSV files, some ad hoc and some on a schedule. Before Files.com, every one of those exchanges depended on a person. Files were handled by hand across Box, SharePoint, and on-premises Windows file servers, with no single interface over the three, no automation, and no centralized log. When a regulated file moved, someone moved it, and nobody could produce a record afterward of who had moved what.

The scale ahead made it untenable. Geron's plans called for onboarding dozens of external vendor and client users, each of them a new stream of regulated files arriving with no governed place to land.

Nothing about the estate made this easy to fix. Storage was fragmented across two collaboration clouds and an internal tier, and the internal tier speaks SMB behind an Azure perimeter where even outbound traffic is restricted under formal change control. A plain hosted SFTP endpoint would collect partner files in the cloud and strand them there, with no route into the storage where internal teams actually work. Exposing the file servers to the internet was never a possibility. And building and operating managed file transfer infrastructure in-house was not on the table for a company whose engineering is oncology.

So the fix had a specific shape. It had to be a hosted SFTP service that partners could reach with whatever client they already use. It had to reach internal SMB storage without exposing it. Access had to come from the corporate directory rather than a hand-maintained user list. File movement had to run on its own. And it had to carry the agreements regulated data requires, a HIPAA business associate agreement and a GDPR data processing agreement among them.

An SFTP Perimeter in the Cloud, an Agent Behind the Firewall

On the outside, vendors, clients, and data providers connect over SFTP to an endpoint on Geron's own branded domain, using the standard clients they already have. Geron hosts and patches nothing to make that possible.

On the inside, the Files.com Agent was installed on an internal Windows server. The Agent connects outbound to the Files.com cloud, so there is no inbound firewall rule and no service listening on Geron's network. The only network change the deployment required was a single outbound port, opened through Geron's Azure change-control process. Through the Agent and Files.com Remote Server Mounts, the internal SMB storage became reachable to the platform: transfers land in it and pull from it as if it were cloud storage, while the servers themselves stay where they always were.

Between the two, Files.com Automations and Sync move files between the cloud exchange and internal storage, on schedules, with every run recorded in a centralized log. That log is the audit trail the old arrangement never had.

Access is governed from the directory. Users sign in through SSO against Azure AD, and SCIM provisioning creates and removes accounts as the directory changes, including an administrator group provisioned as a group rather than person by person.

A Governed Exchange Where There Was None

With Files.com in production, Geron replaced manual, unrecorded handling of regulated files with a single governed exchange channel.

  • Partner and data-provider exchange now runs through one SFTP channel on Geron's own domain, and adding the next external counterparty means provisioning an account on that channel, not inventing a new manual arrangement.
  • Internal file servers participate in external exchange without exposure: the entire on-premises footprint is one Agent and one outbound port, and nothing internet-facing runs inside Geron's network.
  • Every transfer is centrally logged, giving Geron an audit trail behind obligations spanning HIPAA, GDPR, SOX, and 21 CFR Part 11, with a GDPR data processing agreement executed with Files.com.
  • File access follows the corporate directory: accounts appear and disappear with SCIM, and no one administers file users by hand.

The immediate change was to the files already moving. The compounding one is that growth no longer adds handling: each new vendor, client, or scheduled feed rides the same channel, under the same identity governance, into the same log.

The File Infrastructure Geron Never Had to Build

Today, when a data provider sends a file, it arrives over SFTP on Geron's domain, moves to the internal storage where teams work without anyone touching it, and leaves a record behind. Before Files.com, that same exchange meant a person shuttling the file by hand between Box, SharePoint, and a file server, with nothing written down afterward.

Geron's business is telomerase inhibition, not file infrastructure. Files.com gave it a compliant managed-transfer perimeter in front of the storage it already runs, without building MFT infrastructure and without moving data off the servers where it lives.