Sonesta Makes Files.com the Control Point for Data Leaving Its 1,300-Property Hotel Business
Sonesta International Hotels is a U.S.-based hotel company with a multi-brand portfolio of roughly 1,300 properties. About 150 of those properties are managed directly by Sonesta, with the remainder franchised.
An operation like that is a data-exchange business as much as a lodging business. Managed properties generate financial files from their Oracle systems every day. Corporate systems in Azure produce data feeds for revenue-management vendors and other partners. Dozens of outside vendors send files in and retrieve files out. Data leaves Sonesta constantly, in many directions, and it is the information security team's job to know how and where.
Every Vendor Connection Was Another Way Out of the Company
Outbound data at Sonesta had no single shape. Each vendor relationship carried its own connection. Cloud systems fed data directly to the partners that consumed it. The channels worked, one at a time, and that was exactly the problem. The security team had no place to stand: no single point where controls could attach, no one record of what was leaving, and no way to answer a question about outbound data without chasing individual business units and vendors. Every new vendor relationship opened another path out of the company that nobody governed as a whole.
The fragmentation was structural, not sloppy. Hotel data movement converges nowhere on its own. Managed properties produce files locally, on site. Corporate data lives in Azure. Vendors both push files in and pull files out, each on its own arrangement. Securing that channel by channel would mean replicating controls across every counterparty, and then doing it again for every vendor Sonesta added.
What the security team needed was a point of convergence: one place where corporate Azure output, vendor exchange, and property financials all pass. It had to speak the SFTP the vendors already used, keep each counterparty walled into its own directories, carry heavy machine-to-machine traffic, and open itself to the security tooling Sonesta already ran. Sonesta selected Files.com to be that point.
Azure Ships Data In, Vendors Take It Out Over SFTP
Sonesta's Azure databases, blob storage, and Azure Functions now ship outbound data into Files.com, and Files.com serves it to external vendors and customers from there. The majority of movement on the platform is outbound: it is the step where data crosses from Sonesta's environment to the outside world.
Vendors connect over SFTP with SSH key authentication. Per-user and per-folder permissions in Files.com scope each vendor to its own directories, so a counterparty sees only its own exchange and nothing else on the platform. Revenue-management platforms including IDeaS and OTA Insights reach their files the same way. Machine-to-machine traffic runs on programmatic service accounts over the Files.com REST API, roughly 30,000 API transactions a day, and each vendor's account carries a named internal business owner, so every automated path out of the company has a person accountable for it.
The same platform carries the inbound spoke. Roughly 60 Sonesta-managed properties generate Oracle deposit files on local servers, scripts push those files to Files.com, and the corporate accounting team downloads them from one place. Collection from dozens of physical sites into a central finance function runs on the same governed platform that handles vendor egress.
Security Effort Now Aims at One Platform
With the hub in production, Sonesta replaced a census of outbound channels with one platform where controls attach.
- Vendor EDI is consolidated: anyone at Sonesta doing EDI with a vendor uses Files.com as the primary method. Onboarding the next vendor means a scoped account, an SSH key, and a named owner, not another ungoverned connection.
- Outbound data is observable at one point. What leaves the company passes through a platform that records it, instead of scattering across channels nobody could see whole.
- Existing security tooling reached the transfer layer without adding another tool. A data-classification tool built for SharePoint and OneDrive inspects everything held on Files.com through a single read-only API key, extending Sonesta's classification coverage to the platform where data actually departs.
- Property financial collection carries the same governance as vendor exchange, because both run through the same platform.
The compounding result is that security effort no longer scales with the number of counterparties. A new vendor lands on the existing pattern, and the controls, the logging, and the classification coverage apply to it on arrival.
“One of the most critical pieces we have as infrastructure at Sonesta.”
One Place to Stand
“It is the pivoting point where the data leaves our company, as simple as that.”
Sonesta did not make its data egress governable by locking down every channel one at a time. It gave data one deliberate way out of the company, and it concentrated its security effort there. Files.com is that way out, which is why the team that guards a 1,300-property hotel business calls it some of the most critical infrastructure it runs.
Related Customer Stories
Services
Hershey Entertainment & Resorts Brings Vendor File Transfer In-House With One Files.com SFTP Endpoint
A daily vendor exchange became shared infrastructure for gift card, ticketing, outside-party, and internal file flows—without adding an SFTP server for IT to operate.
Read story →
Services
ENGIE ANZ Retires Cerberus FTP Without Giving Locked-Down Servers Internet Access
The replacement had to sustain a contractual file pickup or dropoff every 8 to 10 seconds through Automate, the backend estate's only permitted path out.
Read story →

Services
Ryman Hospitality Properties Dropped Azure SFTP for Files.com Without Rewriting Its Integrations
The swap had to preserve Azure Blob landing paths, Azure AD controls, and programmatic access for a fully automated ETL pipeline.
Read story →