From a Hand-Managed SFTP Server to a Controlled Manufacturing Partner Exchange
An optical networking equipment manufacturer makes fiber-based network hardware for buildings and campuses, plus the software that manages it, sold through channel partners into government, education, healthcare, and hospitality. Its equipment carries sensitive traffic.
Hardware is the operative word. The company ships boards, and those boards are built and tested by a separate company in its manufacturing chain. That relationship runs on files. The company writes the code that runs on the factory's test fixtures, and updates to that code have to reach the factory. In the other direction come manufacturing logs and debug output, arriving when something goes wrong with the manufacturing of the boards. Two independent companies, exchanging files continuously, in both directions.
One Server Between Two Companies
The exchange ran on a single SFTP server that the company had set up specifically for the relationship and administered itself. A single server offers no natural boundary between ours, theirs, and shared, and every change to what the partner could reach was work on infrastructure the company also had to keep patched and online. The company wanted the answer to "who can reach it" to be a permission it sets, not a server it maintains.
The requirement was structurally hard to meet. The counterparty is a genuinely separate company, not a business unit: neither side's identity systems or network controls extend to the other. Enforcing that boundary on its own meant building and operating per-partner infrastructure. Any replacement also had to keep speaking SFTP, because that was the protocol the factory's workflow already ran on.
That was the specification. The company needed a layer between the two companies that neither had to operate: a place where it could declare which folders the partner reads and which it writes, where the factory kept connecting over SFTP with the tooling it already had, and where access on the company's side followed the corporate directory instead of a local account list.
Directional Folders, With the Factory Still on SFTP
The company selected Files.com to be that exchange layer.
The structure was a set of folders with a direction. Test-fixture code went into folders the partner could read. Manufacturing logs and debug output landed in folders the partner could write. Files.com's per-folder, role-based permissions enforced the split, so each company saw only the part of the exchange that belonged to the relationship. The company decided what the partner could reach by setting a permission rather than by administering a server.
The factory side did not have to change. Files.com presented an SFTP endpoint, so the partner's existing workflow connected to the new exchange the same way it had connected to the old server. On the company's side, access ran through its own identity stack: single sign-on through Microsoft Entra ID with Duo, two-factor authentication enforced, and SCIM provisioning creating and removing Files.com accounts from the directory. Every action on the exchange landed in one platform log.
Partner Access Became a Permission, Not a Server
With the exchange in production, Files.com replaced a server the company administered itself with a boundary it declares in configuration. The company no longer has to patch and keep a dedicated exchange server online or reconcile its employees against a local account list. Access follows the corporate directory: someone added in Entra ID gets access, and someone removed loses it. Activity across the exchange appears in one platform log.
The pattern also compounds. Nothing in the design is specific to one partner: standing up a controlled exchange with another counterparty is a set of folders and a credential, not another server to build and maintain.
A Boundary the Platform Enforces
The larger change is what that makes possible. The company cooperates closely with an outside manufacturer and controls exactly what that manufacturer sees. It put Files.com between the two companies and got both.
Related Customer Stories
An Automotive Distributor Puts Every External File Exchange on One Security-Owned Files.com Channel
Identity federated through the parent automaker, the brand’s own domain, Canadian data residency, and Inboxes that land partner documents in SharePoint, adopted across the business without an internal campaign.
Read The Story
A Semiconductor Company Uses Files.com for Modem-Log Collection Across Three Simultaneous Carrier Assessments
A shared collection layer let contractor teams upload multi-gigabyte handset logs without VPN access while the company kept its analysis systems on-prem.
Read The Story
A Computer Manufacturer Retired Its Warranty Repair FTP Server With Files.com—Without Changing the Address
A weekend cutover moved the repair channel to Files.com while preserving the endpoint and protocols its service providers already used.
Read The Story
Get The File Orchestration Platform Today
4,000+ organizations trust Files.com for mission-critical file operations. Start your free trial now and build your first flow in 60 seconds.
No credit card required • 7-day free trial • Live in minutes