Skip to main content

Nestlé Health Science Moves 10 TB of Regulated Acquisition Data in One Month with Files.com

A repeatable SFTP staging and verification workflow keeps multi-terabyte GxP data moving without waiting six months to a year for internal infrastructure.
Nestlé Health Science / Aimmune TherapeuticsFiles.com

Nestlé Health Science is the health-science business of Nestlé S.A., and its U.S. pharmaceutical arm builds its portfolio through acquisition and divestiture. The business operates under FDA GxP regulation.

Every one of those transactions runs on a Transition Service Agreement, and every TSA obligates the counterparty to deliver the product's regulated data by a contractual date: clinical study folders, raw scientific datasets, the documentary history of a drug. GxP rules mean none of it can simply be accepted. Each delivery has to be checked, file by file, against the data delivery and migration plans written into the contract before the business treats it as received. Underneath the deal-making, Nestlé Health Science U.S. has to move terabytes of regulated data on contract deadlines, over and over.

TSA Deadlines Arrive on the Contract's Clock, Not the Infrastructure's

The business unit had no SFTP service to receive any of it. A typical acquisition delivers 500 GB to 5 TB of data from the counterparty, and outliers run far larger. The destinations dictated the protocol: the unit's two Veeva Vaults, the final home for regulated clinical data, accept bulk transfer only over SFTP, and multi-terabyte scientific datasets are impractical to move any other way. Without an SFTP layer, a contractual delivery date was an obligation the unit had no mechanism to meet.

The obvious fix, standing up a server of its own, ran into how Nestlé is built. Inside a parent company of 270,000 employees, each business unit operates almost as a company of its own. Scott Stevens, the senior applications-development specialist who owns GxP data movement for the unit's M&A integrations, had measured what the internal route would cost.

We could set up our own server, but the amount of compliance and hoops that I have to go through within Nestlé would sometimes take up to six months to a year to get that done.
Scott Stevens, Sr. Specialist Applications Development, Nestlé Health Science U.S.

A server that clears internal compliance in six months to a year is no answer to a data delivery due this quarter. And the pattern repeats with every deal in the pipeline.

What the unit needed was a transfer service that carried none of that cycle because it sat outside the Nestlé ecosystem entirely. It had to speak SFTP in both directions. It had to keep each counterparty's feed segregated from every other. It had to produce a complete, verifiable index of every delivery, because GxP approval rests on proving exactly what arrived. And it had to move approved data onward into Box, the unit's compliance-approved system of record, and into the two Veeva Vaults. Nestlé Health Science U.S. selected Files.com to be that external SFTP service.

Stage, Verify Against the Manifest, Then Forward to Box and Veeva

Files.com became the staging layer between every acquisition counterparty and the unit's regulated systems of record: the place where data lands, is held, and is proven before the business lets it move.

Each incoming data stream gets its own Files.com user and segregated folder tree, created per project or vendor. Selected sensitive folders also carry Files.com GPG encryption.

Before anything moves downstream, Stevens exports the full folder listing to CSV through the Files.com CLI: every file name, size, and MD5 hash. That listing is reconciled against the counterparty's own manifest and goes into the internal reports that document the transfer, so business approval rests on a file-by-file record of what actually arrived rather than an assumption that everything did.

Once the business signs off, Files.com forwards approved data to Box through a Remote Server Mount and to the two Veeva Vaults over SFTP. Forwarded data then stays in Files.com under a six-month archival hold.

Nothing in the pattern belongs to any one deal. The next acquisition means a new user, a new folder tree, the same manifest reconciliation, and the same destinations.

10 TB of DNA Sequencing Data, Three Destinations, One Month

With the workflow in production, the data side of a pharmaceutical acquisition stopped being an infrastructure question and became a repeatable process. In one acquisition, 10 TB of raw DNA sequencing data was received over SFTP, staged, verified against the vendor's manifest, and forwarded to Box and both Veeva Vaults inside a single month. The contractual deadline was met.

An earlier project staged 16 TB in Files.com ahead of a transfer to Box. Files.com is now the business unit's SFTP service for regulated data movement, with a single administrator running terabyte-scale, GxP-regulated migrations through the same ingest, verify, and forward pattern.

An SFTP Service No Deal Has to Wait For

Today, when Nestlé Health Science closes its next pharmaceutical deal, receiving the counterparty's data no longer requires a new infrastructure project. Stevens creates the user, the counterparty gets its SFTP credentials, and the same Files.com pipeline that carried the last acquisition's data carries this one's, manifest reconciliation and all.

The instinct inside a heavily regulated enterprise is that the compliant path must run through the corporate ecosystem. Nestlé Health Science U.S. found the opposite. Because Files.com sits outside that ecosystem, it carries none of the internal provisioning cycle, and it still gives the business what GxP approval actually demands: segregated access per counterparty and a hash-level record of every file that arrived. The part of the deal that regulation might have made slowest, moving the data itself, now runs on the deal's own clock.