Penske Automotive Group Moved Its Internet-Facing SFTP Endpoint to Files.com Without Rewriting Its Batch Pipeline

Penske Automotive Group is a diversified international transportation services company and automotive and commercial truck retailer. Its global estate includes some 240 dealerships and retail locations.
A retail operation of that size runs on data that crosses the company boundary every day. Inventory files, orders, and shipment status move constantly between PAG, its vendors, and its dealers: which vehicles are on a truck, which have arrived, what sold. Those files feed the performance reporting and inventory analysis the business runs on. And every one of them has to enter the company through some door.
PAG needed to move that door without forcing dealers and vendors onto new transfer methods—or rewriting years of internal batch processing first.
The Front Door Was a Server PAG Had to Host, Patch, and Defend
For years, that door was an FTP/SFTP server PAG hosted on-premises and exposed to the internet. Vendors and dealers uploaded their daily files directly to it.
An internet-facing file server is infrastructure the company itself has to keep online, keep patched, and keep defended, and every partner credential and access decision lives on that one machine. It also gave PAG none of the governance a publicly traded retailer wants around external data exchange: no way to restrict access by country, no tie between internal access and corporate sign-on, no standing record of configuration changes. Everything the feeds depended on rested on how well one server at the edge of the network was maintained.
Years of Batch Processing Sat Behind the Endpoint
The endpoint survived because of what depended on it. Dozens of external counterparties had working scripts and credentials pointed at it. Behind it sat internal batch processing built up over many years, which consolidates the daily files and loads them into SQL for reporting across PAG’s retail estate. A replacement that forced partners to change how they send, or forced that pipeline to be rewritten first, was never going to happen. Tommy Rypina, Vice President of Technology Services, takes a deliberately incremental approach to modernizing the estate: declaring that everything stops while everything gets refactored is, in his experience, a plan that never actually happens.
So the fix had a specification. It had to take over the internet-facing feed role while preserving the protocols and processing behind it. It had to decide access by country and identity rather than by server hardening. It had to give internal tooling a programmatic path in. And it had to reach back to the on-premises file server when a file still needed to land there, without opening PAG’s network to do it.
PAG selected Files.com to be that endpoint.
Files.com Took Over the Internet-Facing Role
PAG moved its external transfer users off the on-premises SFTP endpoint and onto SFTP hosted by Files.com. Dealers and vendors upload the same daily files over the same protocols. What changed is where the endpoint lives and who defends it.
Access became a policy rather than a hardening exercise. PAG’s security team configured Files.com Access Control by Country across the whole tenant, blocking connections from outside an allowed country list, with per-user IP exceptions for the accounts that legitimately need to connect from elsewhere. Internal users authenticate through corporate SSO, and settings changes across the site land in an audit log.
Internal systems retained a programmatic path through the Files.com REST API and Files-CLI. The Files.com Agent runs on the remaining internal file server over an outbound-only connection, so files still move between Files.com and on-premises processing without any inbound firewall path into PAG’s network.
Access by Policy, With the SFTP Perimeter Moved
With Files.com carrying the external SFTP endpoint, PAG replaced an internet-facing role it had to defend with a platform it configures.
- PAG no longer operates its former internet-facing SFTP endpoint. That perimeter is no longer something the company has to host, patch, or harden.
- Who can reach the feeds is a policy decision: blocked by country by default, excepted per user, authenticated through SSO, with configuration changes on the record.
- Partners kept the protocols and transfer methods their feeds already used. The daily inventory, order, and shipment feeds kept flowing through the cutover.
- The batch pipeline behind the feeds was never rewritten, and it did not have to be. The perimeter moved on its own timeline, and the Agent keeps on-premises processing supplied.
“It’s just working, move on to the next thing, either the next fire or the next big thing.”
The lesson in PAG’s move is that the internet-facing transfer perimeter did not have to wait for the systems behind it. The pipelines stayed put, the partners kept their protocols, and the one piece that faced the internet moved to Files.com on its own.
Related Customer Stories
Retail & Consumer
Barnes & Noble Moves 30 GB Vendor Files With Files.com—Without Vendor Accounts or a New Repository
A thin, governed transfer layer now carries about a terabyte a month to changing external partners while existing storage stays in place.
Read story →
Retail & Consumer
Marc Jacobs Retired Its FTP/SFTP Servers One Workload at a Time With Files.com
Amid simultaneous ERP and cloud migrations, Marc Jacobs kept dozens of live retail flows moving while completing its data-center exit.
Read story →
Retail & Consumer
One Counterparty at a Time, Jockey Moves Off Its Progress Ipswitch FTP Server With Files.com
Files.com runs alongside the old endpoint, letting Jockey remove workloads it controls while vendors and remaining third parties move on their own schedules.
Read story →