Skip to main content

InCrowd Replaced Its SFTP Server with Files.com—and Ended Weekly Incidents

One governed cloud service replaced InCrowd’s fragmented exchange paths, so its file infrastructure needed no new physical home when the company left its data centre.
InCrowdFiles.com

InCrowd is a UK sports technology and fan-engagement business. It builds the digital platforms, data products, and marketing campaigns that sports rights holders use to reach and monetise their fans, working with football clubs, cricket boards, rugby competitions, leagues, and federations across the UK, Europe, and the Middle East and North Africa. Its whole business is sport, and its work runs on other organisations' data: audience records, campaign results, and transaction data arrive from the vendors each club or league already uses, get processed by InCrowd, and flow back out as products and reports.

That puts file exchange underneath everything InCrowd sells. Every engagement means files moving between InCrowd, the client, and the client's own data vendors, and much of what moves is personal fan data. When the exchange path fails, the product fails with it.

Files.com gave InCrowd a way to replace those fragmented paths with one governed cloud service. The weekly incidents stopped, and when InCrowd left its data centre, the file infrastructure did not need a new physical home.

A Weekly Incident Cycle on the Path Clients Depended On

For years, that path ran on an on-premises SFTP server, and the server failed constantly. It had chronic problems with file permissions and availability, and outages and major incident reports arrived on a weekly cadence. Every week, someone at InCrowd was writing up why the channel its clients and vendors used to deliver and collect data had gone down again.

The server was only part of the problem. Around it sat several more paths doing overlapping jobs. A homegrown client file portal, built in-house, carried roughly 70 external users, with its folder structures and permissions maintained by hand. Nextcloud handled internal sharing. Custom SFTP scripts ran weekly to collect recurring files. And when someone needed to send something large or urgent, the sanctioned tools were awkward enough that files went out by email attachment or through personal Dropbox accounts instead. Client exchanges carrying personal fan data were leaving through channels IT could not see, expire, or revoke.

The estate had survived because no single piece of it could be swapped in isolation. The SFTP server carried more than 30 external and system connections, and individual clients imposed their own SSH key and cipher requirements on how they would connect. The portal had its own population of external users. The shadow-IT path existed precisely because nothing sanctioned did that job. Replacing the server alone would have left the hand-maintained portal and the ungoverned sharing exactly where they were.

An MFA Mandate the Old Estate Could Not Meet

Two things made the arrangement untenable at once. Management made multi-factor authentication and single sign-on a hard requirement across the business, and the file estate structurally could not deliver it: not on the aging SFTP server, not on the homegrown portal, and certainly not on email attachments and personal Dropbox. At the same time, InCrowd was migrating out of its data centre, which meant every piece of physical infrastructure had to be rehomed somewhere. The file servers were on that list.

The replacement had to bring the client and vendor exchange paths under one set of controls. It had to enforce MFA site-wide and plug into Google SSO. It had to give every client and vendor an SFTP endpoint that honoured that counterparty's own key and cipher requirements. It had to give clients a place to deliver files and confirm their uploads landed. It had to give staff a governed way to send large files that was easier than the workaround. And it had to run somewhere other than a data centre InCrowd was leaving.

InCrowd selected Files.com to consolidate those paths onto one cloud platform.

It provides that one-time password thing, so we shared one-time shareable links and after that it expires.
Karthik Kumar, Head of IT and Systems, InCrowd

A Clean-Slate Cutover for Clients, Vendors, and Bots

InCrowd chose a clean-slate migration: fresh folder structures built on Files.com, with legacy data left behind rather than dragged along. Files.com groups made membership the single source of access, replacing permissions that had been edited by hand across the portal and the server. Internal staff and roughly 70 external portal users moved to the new structure together.

Each client and vendor received a dedicated folder and its own SFTP credential, with key types and ciphers configured to that counterparty's requirements. Clients deliver files into their folder and can log in to confirm the upload landed and is displaying correctly, and InCrowd's commercial team checks receipt of data in the same place instead of asking IT.

The machine population moved onto the same platform. System users hold their own SFTP credentials and run unattended pipelines: a push-notification analytics vendor places click data into a dedicated folder on a schedule, and InCrowd pulls it down programmatically for processing. Through the Files.com S3 integration, those credentials also let partners transact against InCrowd's AWS buckets without AWS access. More than 30 external and system SFTP connections now run this way.

The ad hoc path was the last piece. One-time, expiring Files.com share links replaced email attachments and personal Dropbox for outbound delivery, and a 14-day retention policy on client project folders expires delivered data automatically instead of leaving personal fan data sitting wherever it landed. MFA is enforced site-wide, with Google SSO handling sign-in. Partners were given cutover timelines and switched, while Nextcloud’s internal content moved to Google Drive. The SFTP server, the client portal, and Nextcloud were then deprecated.

The Weekly Incidents Stopped

Since the cutover, InCrowd has run its client and vendor file exchange on one governed platform instead of a failing server, a hand-maintained portal, and unmanaged sharing paths. The difference showed up first in what stopped happening.

Every week we used to have some outage or major incident report, which we are not doing anymore.
Karthik Kumar, Head of IT and Systems, InCrowd
  • The management mandate is met: MFA is enforced site-wide with Google SSO, something the previous estate could not deliver at all.
  • Personal fan data no longer leaves by email or personal Dropbox. It moves through expiring links and retention-controlled folders, so deliveries remain governed and data is cleaned up after itself.
  • Onboarding a new client or vendor feed is now a folder, a group, and a credential configured to that counterparty's requirements. The 30-plus external and system connections all run on that one pattern, and usage has spread from a handful of IT users at rollout to staff and system accounts across the business.

One Less Thing to Move

The deeper change is what the data centre migration turned out to be. InCrowd did not rehome its file infrastructure; it stopped owning any. When the racks were emptied, there was no SFTP server to move, no portal to re-host, and no permission tree to rebuild, because all of it was already running on Files.com.

That's one less thing.
Karthik Kumar, Head of IT and Systems, InCrowd

Today, a club's campaign data lands in its own folder, the commercial team confirms receipt in a browser, a pipeline pulls it down for processing, and a report goes back out on an expiring link, with nobody at InCrowd operating a server underneath any of it. For a business built on moving other organisations' data, the migration was not the moment to find the file infrastructure a new home. It was the moment to take it off the physical estate for good.