Kyndryl Replaced IBM Testcase FTP and IBM Sterling File Gateway Without Rewriting Batch Jobs
Kyndryl is the world's largest provider of managed IT infrastructure services. It designs, runs and modernizes mission-critical systems for large enterprises in more than 60 countries, and its deep mainframe practice operates the systems behind banks, insurers, healthcare systems, retailers and airlines.
Managing a client's mainframe estate is, among other things, a continuous file exchange. Software packages, PTFs, license files and OEM maintenance flow out from Kyndryl's mainframes to the client mainframes it manages. Dumps, usage telemetry and TADz measurement reports flow back. One mainframe pushes, many mainframes pull, and the batch jobs on both ends run largely without people.
Kyndryl was spun out of IBM in November 2021. On day one of its independence, the machinery carrying all of that traffic belonged to the company it had just left.
The File Transfer Backbone Belonged to the Former Parent
In the IBM era, Kyndryl's mainframe file movement ran on IBM's Testcase FTP service, with Sterling File Gateway acting as the bridge between mainframes. Every managed client estate depended on the same paths: the same directories delivered maintenance to a bank's z/OS systems and collected measurement reports from the estates Kyndryl managed.
The transition services agreement that governed the separation put a hard end date on every connection into IBM's systems. When that date arrived, Testcase and Sterling would be gone, and with them the mechanism by which Kyndryl delivered software to its client estates.
Client Firewalls, Isolated Mainframes, and a Contractual Shutdown Date
The obvious fixes did not fit. Standing up another internet-facing SFTP server, the IBM-era approach, was off the table: Kyndryl had committed to a SaaS-first strategy and was not going to rebuild the problem in its own data center.
The endpoints made everything harder. Kyndryl's clients are mainframe shops, and mainframe shops are reticent to open firewall ranges; asking each one to whitelist a rotating set of cloud hostnames, IP addresses and certificates was never going to be acceptable. Some of Kyndryl's own internal mainframes had no direct internet access at all, reachable only over the company's internal backbone. Certificates on z/OS are loaded by hand into RACF keyrings. And batch jobs across client estates pointed at fixed Testcase directory paths, so rewriting that JCL client by client was not a project that fit inside the deadline.
The replacement had to present one stable hostname under Kyndryl's own name, backed by a small fixed set of IP addresses each client firewall team could approve once. It had to speak the protocols z/OS already spoke. It had to carry the old directory structure so existing jobs could be repointed instead of rewritten. It had to keep every client's data apart from every other's. And it had to run as SaaS rather than as another box to operate.
Kyndryl selected Files.com to be that layer: the transfer service between its mainframes and its clients' mainframes, controlled by Kyndryl instead of a former parent.
One Hostname, Two Fixed IPs, and the Old Paths Remapped
Kyndryl mapped a custom domain under its own name to its Files.com site, and Files.com issued two dedicated IP addresses immediately so client firewall teams could begin their changes. From then on, every client connection pointed at a Kyndryl hostname and two fixed addresses, whatever sat behind them.
The legacy Testcase directory tree was remapped one-for-one onto Files.com folders. A batch job that pulled maintenance from a given Testcase path pulled the same path on the new host: the JCL changed a hostname, not a workflow. The legacy service ran in parallel through the transition, and the Files.com side went live ahead of the shutdown.
The z/OS estate connected over protocols it already had: FTPS with TLS client certificates, SFTP through z/OS OpenSSH, and HTTPS. Kyndryl's own z/OS teams added static routes through the internal backbone so isolated internal mainframes could reach Files.com. Existing FTP API and Tectia batch jobs continued to run unattended.
Each managed client got its own folder, isolated with Files.com folder-level permissions. General accounts are write-only, so a client estate can deposit its reports without reading anything, and read access is reserved to superusers. One site serves every client, and no client can see another.
Multi-Gigabyte Dumps Moved Unattended
With the cutover complete, Kyndryl had replaced IBM Testcase FTP and Sterling File Gateway with a single transfer layer it controls, and that layer now runs the mainframe practice's file movement day to day.
Software delivery and report collection for the client mainframe estates Kyndryl manages—spanning banks, insurers, retailers and manufacturers—all run from one Files.com site, with each client's data walled into its own folder. z/OS batch jobs push software out and pull telemetry back with nobody handling a file.
Multi-gigabyte mainframe dumps move routinely, and an 11 GB dataset uploaded from z/OS in 4 minutes 21 seconds. Bringing the next client estate onto the pattern means a per-client folder and one firewall change against the same two fixed addresses, not a new integration.
The layer also carries centralized governance. Users are provisioned from Okta over SAML with SCIM, so access follows the corporate directory. Sitewide IP allowlisting was rolled out under an internal security mandate, and history logs are retained for seven years for audit. The Office of the CIO, which now owns the platform, extracts data from Files.com to build the KPI metrics presented to executives in monthly operational reviews, so the file transfer layer is measured like the rest of the business.
The Mainframe Workflows Did Not Have to Be Rewritten
Today, the path between Kyndryl's mainframes and its clients' mainframes is Kyndryl's own. An engineer distributing maintenance drops it once, and every estate that needs it pulls it on schedule. Nothing about that depends on a former parent's infrastructure or a contractual clock.
What is worth taking away is what did not change. Batch jobs written against an FTP service from another era still run; their workflows did not have to be rewritten. They point at a Kyndryl hostname now, and Files.com answers. Meeting a divestiture deadline did not require modernizing the endpoints. It required giving the old paths a new platform underneath them, and Files.com is what that platform turned out to be.
Related Customer Stories
Software & Technology
Zillow Retires Ombud for Files.com to Send KYC Documents Across Six Countries
Browser-based links let recipients Zillow could not train securely view or download each sensitive document according to its own retention requirements.
Read story →
Software & Technology
Alight Replaced Progress MOVEit’s Person-to-Person Transfer With Self-Service Client Exchange on Files.com
Custom domains, automatic identity provisioning, and centrally enforced policies let Alight remove its MFT team from every client exchange without weakening control.
Read story →
Software & Technology
Modaxo Moved a 1,300-Camera Evidence Pipeline Off Conduent's Data Center With Files.com
Files.com gave field teams a cloud ingestion point while Modaxo repointed cameras and rebuilt its application estate without pausing daily evidence uploads.
Read story →