Skip to main content

A Regional Bank Exchanges Loan Documents With Applicants Through a Bank-Branded Files.com Portal

Applicants need nothing but a browser link, each loan officer works in an isolated home folder under single sign-on, and links and files expire on the security team's schedule.

A regional commercial bank runs a branch network spread across multiple states.

Lending sits at the center of that business. Every loan, consumer or commercial, begins the same way: an applicant handing personal and financial records to a loan officer, and the officer sending documents back. Across all of those branches, the bank wanted that exchange on one governed, bank-branded path.

One Governed Path for Every Loan Application

Bank-wide, the exchange had run on attachments. An attachment cannot be recalled, expired, or scoped, and once sent it sits in an inbox indefinitely. The security team wanted every loan file on a channel it could see into, with rules it set.

What made the requirement hard to meet was the counterparty. A loan applicant was a one-time outside party. Applicants could not be asked to install software, hold an account on the bank's systems, or learn a procedure. The loan officers themselves were bankers, not IT staff, spread across every branch.

A Channel That Asks Nothing of the Applicant

The requirement was specific. The sanctioned channel had to let an applicant send and receive files with nothing but a browser and a link. It had to give each officer a space of their own, scoped so no officer could reach another's borrower files. It had to present as the bank, so the applicant clicking a link saw the bank's own name rather than a third-party file service. And it had to expire documents on a schedule the security team set.

The bank selected Files.com to be that channel, with the bank's Chief Information Security Officer leading the rollout.

A Folder Per Officer, a Link Per Applicant

Files.com gave the bank a borrower-document exchange under the bank's own brand, one that enforced the security team's policy on every file without the officer or the applicant having to invoke anything.

Each loan officer received a home folder and signed in with bank credentials through Azure AD single sign-on. Folder permissions kept each officer inside their own directory: an officer saw their own borrowers' files and nobody else's.

To exchange files with an applicant, the officer sent a Files.com Share Link by email. The applicant opened a web page, uploaded their documents or downloaded the bank's, and was done. There was no account to create and nothing to install. The custom domain and email both carried the bank's name, while notifications told the officer when an applicant uploaded or downloaded a file.

Policy rode along on every exchange. Share Links expired on a schedule. Files followed a purge cycle, with a retention window supporting restoration. Borrower documents did their job and left, rather than accumulating on the site.

The bank's Senior Vice President and Chief Information Security Officer wrote and tested the end-user procedures, ran a live pilot with a volunteer officer, and then rolled the portal out to the loan officer population.

One Governed Channel Across Every Branch

With the Files.com portal in production, the bank put lending document exchange across every branch on one channel where the security team sets the rules.

  • Every branch works the same way. A loan officer in any branch sends the same bank-branded link, and the security team's expiry and permission rules apply to every one of them.
  • Officers adopted the portal because it was less work. In the bank's own comparison, uploading through Files.com was easier than the attachment process it replaced.
  • The pattern expanded beyond lending. Departments from HR and compliance functions to bookkeeping took folder structures on the same site, extending the governed channel through permissions rather than another tool and security review.

Easier Than an Attachment

Today, a loan applicant at any of the bank's branches clicks a link carrying the bank's own name, sends their documents from a browser, and their loan officer knows the moment the files arrive. Every one of those files sits in the officer's own folder, under the expiry schedule the security team set.

A governed channel only works if people use it. The bank's portal holds because Files.com asks less of its loan officers than an attachment did, and nothing at all of their applicants.

Get The File Orchestration Platform Today

4,000+ organizations trust Files.com for mission-critical file operations. Start your free trial now and build your first flow in 60 seconds.

No credit card required • 7-day free trial • Live in minutes