Skip to main content

Sonesta Makes Files.com the Control Point for Data Leaving Its 1,300-Property Hotel Business

Azure output, vendor exchanges, and financial files from dozens of managed properties now converge on Files.com for centralized access controls, logging, and classification.
Sonesta International HotelsFiles.com

Sonesta International Hotels is a U.S.-based hotel company with a multi-brand portfolio of roughly 1,300 properties. About 150 of those properties are managed directly by Sonesta, with the remainder franchised.

An operation like that is a data-exchange business as much as a lodging business. Managed properties generate financial files from their Oracle systems every day. Corporate systems in Azure produce data feeds for revenue-management vendors and other partners. Dozens of outside vendors send files in and retrieve files out. Data leaves Sonesta constantly, in many directions, and it is the information security team's job to know how and where.

Every Vendor Connection Was Another Way Out of the Company

Outbound data at Sonesta had no single shape. Each vendor relationship carried its own connection. Cloud systems fed data directly to the partners that consumed it. The channels worked, one at a time, and that was exactly the problem. The security team had no place to stand: no single point where controls could attach, no one record of what was leaving, and no way to answer a question about outbound data without chasing individual business units and vendors. Every new vendor relationship opened another path out of the company that nobody governed as a whole.

The fragmentation was structural, not sloppy. Hotel data movement converges nowhere on its own. Managed properties produce files locally, on site. Corporate data lives in Azure. Vendors both push files in and pull files out, each on its own arrangement. Securing that channel by channel would mean replicating controls across every counterparty, and then doing it again for every vendor Sonesta added.

What the security team needed was a point of convergence: one place where corporate Azure output, vendor exchange, and property financials all pass. It had to speak the SFTP the vendors already used, keep each counterparty walled into its own directories, carry heavy machine-to-machine traffic, and open itself to the security tooling Sonesta already ran. Sonesta selected Files.com to be that point.

Azure Ships Data In, Vendors Take It Out Over SFTP

Sonesta's Azure databases, blob storage, and Azure Functions now ship outbound data into Files.com, and Files.com serves it to external vendors and customers from there. The majority of movement on the platform is outbound: it is the step where data crosses from Sonesta's environment to the outside world.

Vendors connect over SFTP with SSH key authentication. Per-user and per-folder permissions in Files.com scope each vendor to its own directories, so a counterparty sees only its own exchange and nothing else on the platform. Revenue-management platforms including IDeaS and OTA Insights reach their files the same way. Machine-to-machine traffic runs on programmatic service accounts over the Files.com REST API, roughly 30,000 API transactions a day, and each vendor's account carries a named internal business owner, so every automated path out of the company has a person accountable for it.

The same platform carries the inbound spoke. Roughly 60 Sonesta-managed properties generate Oracle deposit files on local servers, scripts push those files to Files.com, and the corporate accounting team downloads them from one place. Collection from dozens of physical sites into a central finance function runs on the same governed platform that handles vendor egress.

Security Effort Now Aims at One Platform

With the hub in production, Sonesta replaced a census of outbound channels with one platform where controls attach.

  • Vendor EDI is consolidated: anyone at Sonesta doing EDI with a vendor uses Files.com as the primary method. Onboarding the next vendor means a scoped account, an SSH key, and a named owner, not another ungoverned connection.
  • Outbound data is observable at one point. What leaves the company passes through a platform that records it, instead of scattering across channels nobody could see whole.
  • Existing security tooling reached the transfer layer without adding another tool. A data-classification tool built for SharePoint and OneDrive inspects everything held on Files.com through a single read-only API key, extending Sonesta's classification coverage to the platform where data actually departs.
  • Property financial collection carries the same governance as vendor exchange, because both run through the same platform.

The compounding result is that security effort no longer scales with the number of counterparties. A new vendor lands on the existing pattern, and the controls, the logging, and the classification coverage apply to it on arrival.

One of the most critical pieces we have as infrastructure at Sonesta.
Karthik Ivaturi, Senior Information Security Lead, Sonesta International Hotels

One Place to Stand

It is the pivoting point where the data leaves our company, as simple as that.
Karthik Ivaturi, Senior Information Security Lead, Sonesta International Hotels

Sonesta did not make its data egress governable by locking down every channel one at a time. It gave data one deliberate way out of the company, and it concentrated its security effort there. Files.com is that way out, which is why the team that guards a 1,300-property hotel business calls it some of the most critical infrastructure it runs.