Two Dedicated Files.com IPs Let a Payroll and Benefits Provider Move Regulated Transfers Off Legacy SFTP
A professional employer organization runs payroll, benefits, workers' compensation, and HR compliance on behalf of its clients under the PEO co-employment model.
That model makes file exchange the business itself, not a task beside it. Every pay cycle and every enrollment window produces files bound for outside institutions: direct-deposit and tax files to banks, enrollment data to insurance providers, premium and claims data to workers' compensation carriers. Much of it carries employee PII. And the institutions receiving it are among the most security-conscious counterparties a company can have. They set the terms on which anyone connects to them.
Banks Whitelist Source IPs, and a Shared Cloud Has Hundreds
One of those terms is IP whitelisting. Before a bank, insurer, or carrier accepts sensitive data, its network team requires the specific addresses the data will come from, and it opens its firewall to those addresses and nothing else.
A static on-premise SFTP server answers that requirement trivially. It has one address, written into the partner's firewall once. That is a large part of why regulated counterparty transfers stay pinned to aging servers long after everything else in a company has moved to the cloud.
The PEO was retiring exactly those servers. Its DevOps team was moving legacy on-premise SFTP procedures onto Files.com, partner by partner, as each connection came up. That migration surfaced the cloud side of the trade: a multi-tenant platform runs on shared infrastructure, and its default pool of possible source addresses runs to the hundreds. Presenting a bank with that list means asking its network team to allow traffic from hundreds of third-party addresses in order to receive a payroll file. Security-minded network teams refuse that ask, and the refusal lands on exactly the wrong partners. The banks, insurers, and carriers the whole exchange exists to serve would have been the hardest ones to connect at all.
The Fix Had to Change What Partners See on the Wire
The requirement was imposed by the partners, not by the PEO. No cipher setting or permission change on the PEO's own side touches what a bank's firewall team will accept. The further the migration reached into banking and insurance counterparties, the more often this one question decided whether a workload could leave the old server.
That set the requirements. The PEO needed a source identity that was small, fixed, and permanent: addresses that never change, regardless of what infrastructure runs underneath. It needed that identity under its own name, because the files are the PEO's obligations to its clients. And it needed the encryption those partners separately demand, on the connection and, for banking partners, on the file contents themselves.
The PEO got all of it as a platform capability: it runs its Files.com site on its own branded domain with dedicated IP addresses.
Two Dedicated Addresses Under the PEO's Own Domain
With Files.com Dedicated IP Addresses bound to its custom domain, every transfer the platform makes on the PEO's behalf originates from the same two addresses. The shared infrastructure underneath can grow and shift, and the partner never sees any of it. A bank's network team whitelists two entries, once. It is the same conversation a server in the PEO's own rack would have required.
The rest of the exchange runs on top of that identity. The PEO set up each counterparty as its own remote server connection across dozens of client, vendor, and carrier SFTP and AS2 endpoints. Files.com also met the partners' transport- and file-encryption requirements. Its enforced-SSL configuration supplied evidence for the PEO's SOC 2 auditors, while Files.com applied GPG encryption to file contents for banking partners that required it.
Two Whitelist Entries for Banks, Insurers, and Carriers
With the dedicated-IP identity in place, the PEO replaced a firewall request most partners would have refused with a two-entry whitelist that never changes.
- Partners that whitelist source IPs list two addresses instead of hundreds. It is the same ask an on-premise server would have made, with a cloud platform behind it.
- Onboarding the next regulated partner starts with a simpler network conversation. The addresses never change, so the partner's firewall work is limited to the same two entries while the PEO exchanges credentials and keys and sets the delivery schedule.
- The most sensitive transfers moved onto the platform instead of staying behind on legacy servers. Payroll, banking, and benefits-enrollment files carrying PII run through Files.com as the standard path.
- The deployment behind those addresses runs at real scale: the PEO has peaked at more than a hundred thousand transactions through Files.com in a single day.
Cloud File Transfer on Terms a Bank Will Accept
Every connection with an IP-whitelisting requirement used to carry an architecture question: could this transfer leave the building at all? One counterparty's firewall policy was enough to pin a whole workload to a static server. A partner's whitelisting requirement no longer decides where the PEO's file transfer runs.
Related Customer Stories
A Hospitality and Entertainment Company Brings Vendor File Transfer In-House With One Files.com SFTP Endpoint
A daily vendor exchange became shared infrastructure for gift card, ticketing, outside-party, and internal file flows—without adding an SFTP server for IT to operate.
Read The Story
An Energy Company Retires Cerberus FTP Without Giving Locked-Down Servers Internet Access
The replacement had to sustain a contractual file pickup or dropoff every few seconds through Automate, the backend estate's only permitted path out.
Read The Story
A Hospitality and Entertainment Company Dropped Azure SFTP for Files.com Without Rewriting Its Integrations
The swap had to preserve Azure Blob landing paths, Azure AD controls, and programmatic access for a fully automated ETL pipeline.
Read The Story
Get The File Orchestration Platform Today
4,000+ organizations trust Files.com for mission-critical file operations. Start your free trial now and build your first flow in 60 seconds.
No credit card required • 7-day free trial • Live in minutes