Orion Pharma Replaces Microsoft Azure SFTP and Workstation Staging With Direct-to-Azure Transfers Through Files.com
Orion Pharma discovers, develops and manufactures human and veterinary medicines. Headquartered in Espoo, Finland, the company employs about 4,000 people and sells its products in more than a hundred countries.
A company that originates its own compounds does not run its research alone. Orion's R&D depends on data produced outside its walls. Contract research organizations run studies, universities and sequencing labs generate omics data, imaging partners produce bioimaging files, and at the end of a trial, final statistical reports and SAS analysis output go out to the FDA and EMA. Every one of those relationships is a file crossing Orion's company boundary. The data is GxP-classified, some of it is patient-level, and much of it is enormous.
Across four R&D workflows, Orion used Files.com to replace Microsoft Azure native SFTP, its self-hosted SFTP service, and the process that routed partner data through scientists' workstations. External partners now push terabyte-scale datasets through Files.com directly into Orion-owned Azure storage, while two groups per workspace govern access instead of the previous model's more than 100 IAM roles.
Terabyte Datasets, Downloaded to Workstations by Hand
A single sequencing file can reach a terabyte. A whole dataset can reach 2 TB, and individual bioimaging files run 200 to 300 GB.
That data reached Orion the hard way. The company hosted its own SFTP server for partner exchange and used Azure's native SFTP alongside it. On the bioinformatics side, each CRO or research institution sent a link, a scientist pulled the dataset over SFTP down to their own workstation, and then pushed it back up into the internal Azure application where analysis happens. At these file sizes, that meant duplicate copies, long manual transfers in both directions, and no assurance that the complete dataset had actually arrived. GxP-relevant research data was being staged on individual workstations because that was the only path available.
Around the official paths, data also moved however was closest to hand: SharePoint, OneDrive, local downloads, each requiring someone to move files manually and each a data-integrity risk. Outbound sharing had its own gaps. Links did not force recipients to authenticate, nothing controlled expiration or archiving of what had been shared, and a previous sharing service imposed file-format restrictions that required administrators to whitelist the rare, proprietary binary formats bioimaging and sequencing produce.
The diagnosis was simple: Orion's research data exchange had grown as a collection of one-off arrangements, and none of them could answer the question GxP asks. Who had access to which dataset, and who uploaded or downloaded what?
The Data Had to Land in Orion's Own Azure
The patchwork survived because fixing it properly was difficult. Orion controls none of its partners' environments. Some CROs speak only SFTP. Universities run locked-down networks where installing a transfer client is not an option. And the sanctioned route for external access was heavy: on the clinical side, partner access ran through more than 100 distinct IAM roles, and creating a role took weeks. When proper access takes weeks per partner, side channels grow. As dataset sizes climbed into the hundreds of gigabytes and GxP and GDPR obligations demanded a real audit trail, the workstation workflow stopped being survivable.
Incoming data had to land directly in Orion's own Azure storage, not in a vendor's storage that would need copy operations afterward. Every recipient, internal or external, had to authenticate. Every access had to be logged. Accounts and shares had to expire on their own instead of waiting for someone to remember. The teams that own the data had to be able to onboard their own partners without opening an IT ticket. And partners had to keep whatever tools they already had, from a browser to a Python script to a plain SFTP client.
Orion selected Files.com to be that layer: a governed front door on storage it already owned.
Partners Now Push Through Files.com Into Orion's Storage
The build inverted the flow. Instead of Orion pulling datasets down from each CRO's SFTP endpoint, external partners now push data into Orion.
Using Files.com Remote Server Mounts, Orion mounted its own Azure Data Lake Storage containers into the folders of each research workflow. A file a CRO uploads through Files.com is written directly into Orion's container in real time. There is no intermediate storage, no copy job afterward, and no workstation anywhere in the path. The landing zone stays a landing zone: data moves on to its master analysis systems within 30 days.
Partners use the path that fits them: a credentialed browser upload link, an automated pipeline through the Files.com CLI or Python SDK, or SFTP for tooling that requires it. That SFTP traffic now points at Files.com instead of a server Orion has to run.
“The browser access would be easy to use compared to SFTP clients.”
Orion stood up all four workflows — omics, bioimaging, clinical data, and ad hoc vendor sharing — in a five-week phased build.
Two Groups per Workspace, Instead of a Hundred IAM Roles
Internal users are provisioned from Entra ID, with single sign-on, group synchronization, and device-trust checks enforced upstream. Each workflow runs as a Files.com workspace with exactly two groups, workspace administrator and contributor. That two-group model replaced the more than 100 IAM roles the old partner-access approach required.
External users are created inside the one workspace that concerns them and nowhere else, and workspace and folder administrators onboard partners themselves. Patient-level clinical trial data got harder separation: its own Files.com child site with its own dedicated administrators, so managing clinical access never intersects with any other user group.
The lifecycle controls Orion never had are now automatic. Accounts disable after 60 days of inactivity, external accounts are time-limited, and shared data carries expiration. Every upload, download and permission change lands in Files.com's access logs and permission reports, which is the record Orion's GxP workflows require. The data stays resident in the EU, with a BAA covering research data that may originate in the US.
“We have pretty critical information coming on the clinical side, so we must be very careful that no data is accidentally shared with somebody who doesn't need it.”
Research Data That Never Touches a Workstation
With the four workflows in production, Orion replaced its self-hosted SFTP server, Azure native SFTP, and the workstation staging workflow with one governed route into its own storage.
- Terabyte-scale datasets from CROs, universities and imaging partners arrive directly in Orion's own Azure containers. No scientist downloads them to a workstation, and no one re-uploads them into the analysis environment by hand.
- Granting a partner access is done by the team that owns the workspace, under the two-group model, instead of a weeks-long role-engineering exercise for each new relationship.
- Within these workflows, inbound and outbound research data travels one path where every recipient authenticates, every access is logged, and access ends on its own through lifecycle rules and expiration.
- The pattern repeats. Each workflow is a workspace, a mount into Orion's storage, and two groups, so bringing the next partner or the next data stream onto the platform is configuration, not a project.
One Governed Crossing at the Company Boundary
Today, a bioinformatician who once had to shepherd a sequencing run from a CRO's server through a workstation and back up into the analysis platform finds the data already in Orion's own containers, complete and logged, without ever handling it. A study team brings its next imaging partner onboard from inside its own workspace, with no ticket to IT. And when a collaboration goes quiet, the access goes with it, because Files.com's lifecycle rules were counting even when nobody was.
Orion did not buy another place to put files. It put Files.com in front of the Azure storage it already owned and inverted the exchange, so that partners push data across a boundary Orion governs, using the tools they already had.
Related Customer Stories
Health & Life Sciences
CommonSpirit's Edgewise GPO Replaced Email and Weeks of IT Tickets for 150+ Vendors With Files.com
A branded portal, scripted provisioning, and automated validation gave the finance team control of auditable vendor intake at scale.
Read story →
Health & Life Sciences
Fred Hutch Automates Terabyte-Scale Genomic Delivery With Disposable Files.com Accounts
Files as large as 500 GB now move from on-premise storage to outside researchers without a hand-built delivery channel for every customer.
Read story →
Health & Life Sciences
Waters Retired SolarWinds Serv-U and Made Files.com Its Company-Wide External File Exchange
The replacement had to serve both employees delivering hundreds of gigabytes of laboratory data and partners that still depended on SFTP.
Read story →