Skip to main content

Hampton Roads Transit Automates Four ADP Feeds with Files.com—Without Putting Plaintext in the Cloud

Outbound-only Files.com Agents connect HRT’s on-premises systems to scheduled PGP delivery while audit copies remain on servers the agency controls.
Hampton Roads Transit (HRT)Files.com

Hampton Roads Transit is the regional public transportation provider for southeastern Virginia, running bus, light rail, ferry and paratransit service across six cities: Chesapeake, Hampton, Newport News, Norfolk, Portsmouth and Virginia Beach. The agency carried roughly 9.5 million riders in 2025 across a 369-square-mile service area. It operates The Tide, Virginia's first light rail line, and scheduled passenger ferries on the Elizabeth River, something few transit agencies its size run at all.

Moving that many people takes more than a thousand employees: operators, mechanics, ferry crews, dispatchers, administrators. Paying and administering them spans systems on both sides of HRT's own network. HR and payroll records originate in the agency's on-premises HCM system, while payroll processing and benefits administration happen at outside providers, with ADP first among them. On every cycle, files carrying salary data and protected health information had to leave HRT's servers, reach those providers encrypted, and arrive on their schedule and their terms. To automate that exchange, HRT needed cloud orchestration that never stored unencrypted payroll data in the cloud and kept the audit copy on servers the agency controlled.

Payroll Files Moved by Hand, Against ADP's Clock

The systems generated the files automatically. Everything after that was a person. The HCM system dropped its exports into a folder on an internal server, and staff took over from there: processing the CSV files and sending them to ADP by hand.

That meant the delivery of a public agency's payroll and benefits data depended on someone remembering to run a manual routine against a hard external deadline. ADP ingested files inside fixed windows and under strict naming rules. Its automation expected a specific file name, and a file that arrived misnamed dropped into an unprocessed folder on ADP's side instead of into the run. The only control on all of it was a person doing the routine correctly, every time.

The workload was also multiplying. HR, leave-of-absence, payroll and benefits feeds each needed the same treatment, which meant the same manual handling repeated across four parallel streams of sensitive data. HRT had outgrown moving payroll data by hand.

Why the Manual Process Outlived an MFT Platform

HRT was not short of file transfer tooling. The agency ran Axway Secure Transport, a legacy managed file transfer platform, for its vendor data feeds. But a single Axway job took more than four months to implement, and the platform was difficult to support. Building the payroll automation there never happened, because the manual routine was faster than the tool that was supposed to replace it.

What replaced the manual process had to satisfy a constraint HRT's cybersecurity team set from the start: encryption applied as the file moved, with unencrypted payroll data never stored in the cloud. An unencrypted copy had to be archived on HRT's own servers for audit. Delivery had to run over SFTP, inside ADP's windows and under its naming rules. HR staff had to be able to trigger runs themselves, without administrator access to anything. And with protected health information in scope, the platform had to operate under a HIPAA business associate agreement.

HRT selected Files.com to be that encryption-and-delivery layer.

Axway proved to be very cumbersome, very inefficient, very difficult to support. That's why I bought Files.com.
Afonso Alves, Manager, Cybersecurity Services, Hampton Roads Transit

An Encryption and Delivery Layer That Leaves Plaintext at Home

For the payroll workflows, Files.com became the layer between HRT's on-premises HR systems and its outside processors. It handled the pickup, archiving, encryption, delivery and notification, while unencrypted data stayed inside HRT's network.

Files.com On-Premise Agents ran on servers inside HRT's environment with read access to the directory where the HCM system dropped its files. The Agent connected outbound to Files.com, so nothing on HRT's network had to be exposed to reach it.

When a file appeared, a chain of Files.com Automations took over. An unencrypted copy moved into an archive on HRT's side, preserving the audit record on servers the agency controlled. The file was then PGP-encrypted and delivered over SFTP to ADP and HRT's internal Optima ERP. The design rule was simple: apply the PGP and send, so that nothing unencrypted ever sat in the cloud. Deliveries were named to ADP's rules and scheduled against its fixed monthly window, and stakeholders received an email confirming each completed run.

After validating the HR feed as a pilot, HRT extended the same pattern to leave-of-absence, payroll and benefits feeds in a single working session. HRT also kept the least-privilege requirement intact: the HR staff who run deliveries were granted access to just the automations their standard procedure names. They can trigger a run on demand and see its history, and nothing else.

HRT kept the manual process running in parallel until the automated workflow had been validated end to end, then shut it off.

Four Feeds, One Agent, No Hands

With the workflows in production, HRT replaced a hand-run payroll routine with a repeatable, encrypted integration pattern.

  • Payroll, HR, benefits and leave-of-absence files reach ADP and Optima with nobody handling them. ADP's fixed monthly window is met by a scheduled automation instead of a person's calendar, and on the first end-to-end validation, ADP's own automation processed the delivered file immediately.
  • Encryption is enforced by the workflow rather than by procedure. Every file leaves PGP-encrypted, unencrypted payroll and health data never leaves HRT's environment, and the audit copy stays on HRT's own servers.
  • The pattern compounds. The first workflow went from design session to validated encrypted delivery in about five weeks, and extending it to four parallel feeds took a single working session. Adding the next feed is a folder and an automation, not a months-long integration project.
  • HR staff run their own deliveries. Non-admin users trigger exactly the automations their procedure calls for and confirm the outcome from the run history and completion emails, with no ticket to IT.

Cloud Orchestration, With the Data at Home

The lesson in HRT's build is that moving orchestration into the cloud did not mean moving the data there. Files.com runs the scheduling, encryption and delivery from the cloud, while unencrypted payroll data never leaves the servers HRT controls. A public agency got the automation without giving up custody of the data.