Foresight Diagnostics' Interim IT Director Pulled CAP, CLIA, and ISO 13485 Audit Evidence from Files.com
Foresight Diagnostics, now a Natera company, runs one of the most sensitive cancer tests in existence. Its PhasED-Seq technology, developed at Stanford, detects circulating tumor DNA at concentrations below one part per million. That sensitivity has put its minimal residual disease data into clinical practice guidelines for lymphoma and into prospective trials that inform treatment decisions for patients. More than 25 biopharma and academic partners use Foresight's CLIA-certified lab to run MRD testing as an endpoint in their clinical programs.
That business model has a consequence: Foresight's product is data that leaves the building. Patient blood samples arrive by courier, get accessioned, and go into the sequencers. Somewhere in that workflow, the data becomes protected health information. The results then travel back out to the drug developer running the trial. A lab regulated under CLIA and CAP, with ISO 13485 in partner-audit scope, is accountable for every system that data touches on its way out, and that includes the transfer layer itself.
Results Measured in Terabytes, Moved with No Record
The deliveries are large. Single files run up to 400 GB and aggregate data sets up to 50 TB, drawn from roughly two petabytes of data in Foresight's Google Cloud storage. Before standardizing, that data reached partners three different ways: staff worked directly inside client-owned cloud buckets, mirror jobs copied data from bucket to bucket, and after each upload, a team member emailed the client by hand from a shared client-services mailbox.
Each path delivered files. None of them produced a record. There was no retention policy governing what stayed and for how long, no documented deletion behavior, and no single log of who had accessed what. When a partner audit reached the transfer layer, the answers would have to be reconstructed by hand, out of mailboxes and cloud consoles, by whoever held the IT seat that quarter. For a lab whose partners audit against CAP, CLIA, and ISO 13485 at once, that day was coming.
The data itself could not move to fix this. Petabytes of sequencing output live in object storage, and every partner exchange crosses a trust boundary to a company Foresight does not control. What Foresight needed was a properly constituted, highly secured SFTP service sitting over the object storage that already held client data: a sanctioned path out of the lab, with retention, access control, and logging built into the path itself. Foresight deployed Files.com as that layer. When a partner audit later spanned CAP, CLIA, and ISO 13485, an interim IT director who had not built the deployment pulled its backup, retention, and lifecycle documentation directly from the platform.
An SFTP Service Over the Buckets Foresight Already Ran
Using Files.com Remote Server Mounts, Foresight fronted its Amazon S3 and Google Cloud storage with governed folders. The sequencing data stays in the buckets Foresight already pays for, and everyone works against a folder view over SFTP and the web. Partner and client accounts get download-only access to the results staged for them. Internal users are provisioned from Okta through SCIM and sign in with SSO, while every external account carries enforced MFA. When results land, Files.com sends each partner a customized upload notification automatically. Nobody emails from a shared mailbox after an upload anymore. An executed Business Associate Agreement covers the workflow in which results return to a pharma partner as PHI.
Two Sanctioned Ways to Move a File, by Written Policy
Foresight then made the path exclusive. A written, company-wide policy states that transfers happen exactly two ways: over a partner's own SFTP process if it passes Foresight's security audit, and over Foresight's Files.com site otherwise. The policy is globally accepted across the company.
The same discipline covers the evidence. Retention and deleted-file lifecycle settings are configured in Files.com and documented for auditors. Every login, download, and permission change streams through the Files.com SIEM connector into Rapid7, so the security team reviews transfer activity in the same pane as the rest of its logs instead of in one more console.
A Three-Framework Audit, Answered by an Administrator Who Didn't Build It
With Files.com in production, Foresight had replaced an exchange assembled from bucket access, mirror jobs, and a shared mailbox with a governed path that generates its own evidence. In October 2025, that evidence got tested. A partner audit spanning CAP, CLIA, and ISO 13485 reviewed Foresight's systems, and Files.com stood in scope as one of the named key systems.
The person answering the auditors was an interim IT director, not the architect who designed the deployment. He sourced the backup, retention, and lifecycle documentation directly from the platform. Reviewing the retention and lifecycle documentation, his verdict:
“One of the best tools I've typed in for retention.”
Producing that evidence on demand is the sharpest proof, and it sits on top of a broader set of changes:
- Audit evidence comes off the platform, not out of a reconstruction: retention, lifecycle, and backup documentation pulled on demand by an administrator who had not built the system.
- The manual notification step is gone: partners learn the moment their results are staged, automatically, with the delivery itself on the record.
- Reviewing the transfer layer requires no extra console: every Files.com event lands in Rapid7 alongside the rest of the security team's log estate.
- The scale runs through the layer without living on it: Files.com moved 4 TB in a single 30-day period while the data itself stayed in Foresight's own cloud storage, fronted in place.
The policy compounds from there. Every new partner engagement lands on one of the two sanctioned paths, so each one inherits the same retention rules, the same logs, and the same trail. The next audit cycle starts with its evidence already accumulating.
Evidence as a By-Product, Not a Project
Today, when an auditor asks Foresight how results reach a partner, what is retained, and for how long, the answer is a written policy and documentation pulled from Files.com. It used to be a reconstruction across mailboxes and cloud consoles, owed by whoever happened to hold the IT seat. The evidence was never prepared for the audit, because it is a by-product of the platform the transfers already run on, and that is why it survived a change of hands: producing it required knowing Files.com, not knowing the history. For a regulated lab, the transfer layer does not have to be the thing you explain to auditors. At Foresight, it became the system of record they audit against.
Related Customer Stories
Health & Life Sciences
Nestlé Health Science Moves 10 TB of Regulated Acquisition Data in One Month with Files.com
A repeatable SFTP staging and verification workflow keeps multi-terabyte GxP data moving without waiting six months to a year for internal infrastructure.
Read story →
Health & Life Sciences
Abcam Retired Its Self-Hosted FTP Servers With Files.com at MuleSoft’s Transfer Edge
A UK-locked landing zone now handles machine traffic from FTP-only counterparties while MuleSoft continues to orchestrate the integrations behind it.
Read story →
Health & Life Sciences
Everly Health Solutions Configures 40 Health Plan SFTP Connections in Files.com, Not Custom Code
Files.com Remote Servers and automations now move regulated clinical reports from AWS to payer-owned endpoints while operations staff handle routine delivery.
Read story →