Westar Replaces Gmail and Flash Drives With a Files.com Domain Defense Networks Can Allowlist
Westar Display Technologies builds the equipment that tests displays and the video components that drive them. Part of Peraton Labs, the research and engineering arm of the national security company Peraton, Westar supplies display test-and-measurement systems to display makers and integrators worldwide, including leading avionics companies that rely on its FPM systems for verification and acceptance testing.
The hardware is built to last. Many Westar products stay in service for 15 to 20 years, and over that life the firmware, installers, configuration files, and manuals that keep them running have to keep reaching them, wherever they sit. Increasingly, they sit inside some of the most locked-down networks in industry: military programs, defense contractors, and now medical device makers.
The Last Sanctioned Path Was a Flash Drive
Westar's payloads are exactly the kind of files security tooling exists to stop: .msi installers, executables, zipped applications. Corporate email rejects them outright, on Westar's side and the customer's. Consumer file-sharing domains are blocked as a category at defense sites. Physical media was the fallback, and it was closing too.
“We can't even send them our software via flash drives because their customers are shutting down the USB ports on their computers.”
What remained was a workaround that ran entirely outside anyone's sanctioned tooling.
“Most of our customers go home, download it at home because they can get it from their Gmail or home personal email, and then they download it onto their secure drives. Then they can take it into work and do the virus scans.”
That was the standing condition, not an incident. Every firmware release, every configuration file, every application update for a locked-down customer took the same route: an employee's home computer, personal email, a secure drive carried into work, and a virus scan on arrival. Across a customer base of hundreds of companies with hardware in service for decades, that path had to work again and again.
A Blocked Category, Not a Blocked Vendor
The problem could not be fixed from Westar's side, because the blocking lives in its customers' security policies, and those policies are not wrong. A shared file-sharing URL, where thousands of unrelated organizations serve files from one domain, is precisely what a defense contractor's firewall team is paid to block. The generic address of Westar's own hosted portal fell into the same category as every consumer sharing service. And the condition was worsening: access restrictions were tightening month over month and spreading beyond military contractors into the medical field, so the population of customers Westar could not reach was growing, not shrinking.
What the fix had to do was clear. It had to give customer IT departments something they could specifically approve: an endpoint carrying Westar's own name, resolving to fixed IP addresses a firewall team can allowlist. It had to leave the existing portal and its accounts untouched. And it had to be something Westar's site administrator, who runs the website and the file server alongside the engineering work, could stand up without a web operations team.
The Portal Moved to Westar's Own Domain
Westar already ran its product-support portal on Files.com, distributing firmware, configuration files, manuals, and applications through customer accounts with company-level permissions.
To reach the customers who were blocked, Westar put that portal behind its own branded domain using the Files.com custom domain and dedicated IP features. The cutover was completed in one working session with Files.com support alongside Westar's site administrator, with Files.com provisioning and managing the SSL certificate. Not one user account changed. Customers were simply issued the new address.
A Front Door a Defense Firewall Team Can Approve
With the branded domain live, Westar replaced a workaround built on personal email and physical media with an endpoint its customers' security teams can sanction.
- Defense customers whose IT blocks shared file-sharing domains now log in and download directly, from a domain that carries Westar's name and resolves to fixed IP addresses their firewall teams can allowlist.
- The home-download-and-carry-in routine is gone for those customers: no personal Gmail, no flash drive, no walking media into the facility.
- Nothing else moved. The same portal, the same accounts, the same group permissions; customers were simply issued the new address.
- The posture stands up to scrutiny: the branded domain rates A+ on SSL Labs, an answer Westar can hand to any customer's security review.
The compounding result is the larger one. As the same restrictions spread into the medical field, onboarding the next locked-down customer is an allowlist request to that customer's IT department, not the invention of another workaround.
Distribution That Fits Inside the Customers' Security
Westar did not ask any customer to loosen anything. The policies that closed email attachments, USB ports, and shared file-sharing domains all still stand. Files.com gave Westar an endpoint that fits inside them. Today an engineer at a defense contractor gets a firmware update by logging in from their own desk, where the same update used to start at a kitchen table and end at a virus-scanning station.
Related Customer Stories
Software & Technology
GoDaddy Registry Replaces Its Amazon EC2 SFTP Server With Self-Service Zone File Distribution on Files.com
The registry separated vetting and entitlement from account creation, giving hundreds of approved outsiders self-service access without putting them in GoDaddy's identity systems.
Read story →
Software & Technology
Zillow Retires Ombud for Files.com to Send KYC Documents Across Six Countries
Browser-based links let recipients Zillow could not train securely view or download each sensitive document according to its own retention requirements.
Read story →
Software & Technology
Redis Gives Every Support Ticket Its Own HTTPS or SFTP Intake Route With Files.com
API-driven, write-only intake lets customers deliver diagnostics through their firewalls while Redis keeps no standing credentials for external uploaders.
Read story →