Skip to main content

D'Or Consultoria Replaced a Manual Bank SFTP/GPG Relay With Automated Files.com Decryption

The new workflow had to preserve the bank’s endpoint, encryption, and keys while automating retrieval and producing a single LGPD audit trail.
MDS Group / D'Or ConsultoriaFiles.com

MDS Group is the largest independent insurance broker in Brazil, part of the UK's Ardonagh Group and a market leader in Portugal and Angola. D'Or Consultoria, its Brazilian operating entity, built that position in corporate health: brokerage and benefits management serving over two million beneficiaries, contracted through thousands of corporate clients. Under Brazil's LGPD, the data behind that book — enrollment, claims, health records — counts as sensitive personal data, and the broker must be able to account for every file it handles.

A brokerage sits between its corporate clients and the insurance market, and the files flow both ways. When the corporate client is a bank, the client sets the terms of that flow: its own SFTP endpoint, its own GPG encryption, its own keys. A bank does not adjust its file transfer practices to suit a broker. Whatever those terms cost, the broker's side absorbs.

A Jump Host, Two Servers, and a Person in the Middle

For one bank client, absorbing the terms meant a relay that people had to operate. To collect the bank's encrypted files, D'Or Consultoria's infrastructure team connected through an Azure Desktop private session, a jump host with a public IP, out to the bank's SFTP server, and downloaded the GPG-encrypted files by hand. Those files went to one server whose job was to receive them, then to a second server whose job was to run PGP decryption. Only then could internal teams come to that second server and pick up the readable output.

Every encrypted exchange with this client carried that full cost. Nothing moved unless someone moved it. Two servers existed solely to receive and decrypt, each one more machine to maintain. And the LGPD question — who touched each file, and when — had no single answer: the evidence lived in fragments across a jump host and two servers, and had to be assembled after the fact.

None of it could be simplified from the other end. The endpoint, the encryption, and the keys were the bank's to decide, so the fix had to work entirely on the brokerage's side: reach out to the bank's server on the bank's terms, decrypt files automatically the moment they arrived, and keep one record of everything that happened to them. D'Or Consultoria built that replacement on Files.com.

The Bank's SFTP Server Became a Files.com Integration

The team configured the bank's own SFTP server in Files.com as a remote server integration, a connection the platform maintains itself, with no jump host standing between them. A Files.com Automation reaches out to that server, pulls the new files, and moves them into a receiving folder. Automatic GPG decryption uses the private key held in the platform and places the readable output in a second folder, where the teams that need it already look.

Files does this whole automation like magic.
Franthesco Ferrari, Infrastructure Coordinator, D'Or Consultoria

Every pull, move, decryption, and download along the way lands in the platform's access log, attributed to the automation or the person that did it.

I can have one folder to receive the files, the other one to move and decrypt the file, and that's it.
Franthesco Ferrari, Infrastructure Coordinator, D'Or Consultoria

One Folder Receives, One Folder Decrypts

With the pipeline in production, D'Or Consultoria replaced a relay that had to be operated with an exchange that runs itself. Collecting the bank's files no longer involves a person. No jump-host session, no manual download, no hand-off between machines: the automation pulls, and the folder decrypts on arrival.

The receive server and the decryption server are out of the exchange path entirely. There is no machine whose only job is to hold encrypted files, and no machine whose only job is to run PGP. The LGPD record is now a property of the platform: who took which file, and when, is one access log rather than evidence stitched together from a jump host and two servers.

I have the automation to let me know who did it, who took the file, when they took the file, so I have the whole picture of what is happening toward those files.
Franthesco Ferrari, Infrastructure Coordinator, D'Or Consultoria

An Exchange on the Bank's Terms, Run Like Any Other Folder

Today, an exchange whose every term is dictated by the bank runs at D'Or Consultoria like an ordinary folder workflow. When a compliance question arrives about a file that carries sensitive data, the answer is in the Files.com access log, not reconstructed from three machines.

The bank changed nothing. Its endpoint, its keys, and its encryption all still stand, and that is the point.