Space Coast Credit Union Sends Certificate Secrets to Two People, Not Fifteen, With Files.com

Space Coast Credit Union is the third-largest credit union in Florida: a member-owned cooperative with more than 685,000 members, over $9 billion in assets, and a footprint spanning 34 counties along Florida's east coast. Members reach it through branches, call centers, 24/7 online banking, and mobile apps, which means the credit union runs on software: its own platforms, and the vendor systems behind them.
That web of systems is held together by sensitive technical material. Certificates get updated. SAML sign-on configurations get set up and changed. Every one of those events puts secrets in motion between named people at more than one organization, with SCCU's internal systems teams on one side and a vendor's contacts on the other, coordinated through UAT and into production. A credit union built this way was always going to need a controlled way to move that material between specific individuals. What it had was email.
Certificate Secrets Went Out to Fifteen Inboxes at a Time
When a certificate needed updating or a SAML integration needed configuring, the details went out as an encrypted email, copied to everyone who might conceivably touch the work. Encryption protected the message in transit. It decided nothing about who was on the thread, and nothing about what happened to the material afterward. Kyle Wilson, SCCU's AVP, Digital Experience and Application Support, had two of these exchanges running in a single week, and he described the problem plainly:
“A lot of those encrypted emails end up going to 12 people or 15 people, and I'd much rather that just go to the one or two individuals who need to be involved in it.”
Twelve to fifteen mailboxes held certificate details that one or two people needed, and email gave those copies no lifetime. Nothing expired, and nothing could be recalled. At an institution that grants system access on least-privilege terms, the secrets configuring those same systems were the one thing still being broadcast.
Email Survived Because It Was the Channel Everyone Shared
The pattern lasted because the parties change with every exchange. One certificate involves one vendor; the next involves a different one; the internal teams differ by system. Email is the single channel all of those people already have, which is why every exchange defaulted to it, and why every exchange over-shared.
So the fix could not be a policy memo. It had to be a place both sides could authenticate into: scoped to the individuals in one exchange, reachable by a named outsider without an onboarding project, protected by multi-factor authentication, and able to clean up after itself when the work ended. Anything harder to use than a reply-all would lose to the reply-all.
SCCU's application support team put Files.com in that role.
A Files.com Folder Per Exchange, Scoped to the People in It
Each certificate or SAML exchange runs in its own Files.com folder, isolated from everything else on the site. External counterparties connect through Files.com Partners, with upload and download permissions granted per relationship, so a vendor contact sees the one folder for the one exchange they are part of and nothing beyond it. MFA is enforced globally, so an outside contact authenticates under the same requirement as SCCU staff.
Then there is the lifecycle email never had. A site-wide retention policy expires any file not modified in 45 days, and it applies retroactively to files already uploaded. Certificate material moves through Files.com; it does not live there, and it never outlives the exchange it belonged to.
The Audience Is One or Two People, and the Material Expires
With these exchanges running through Files.com, SCCU replaced a broadcast channel with a scoped one.
- Sensitive certificate and SAML material reaches the one or two people involved in an exchange, not the 12 to 15 recipients an encrypted email was copied to.
- Secrets stop accumulating. Under the 45-day expiration, material nobody touches is removed automatically; in email, every copy sat in every mailbox on the thread indefinitely.
- Scoping the next exchange is a folder and its permissions. The first workflow, a certificate update with an external partner, was configured and cleared UAT the same day.
Least Privilege, Applied to File Distribution
What changed at SCCU is where least privilege stops. It used to stop at the mail client: access to systems was granted person by person, and then the secrets that configure those systems went out to every inbox on a thread. Now the distribution itself is granted. Least privilege applies to file distribution the same way it applies to everything else: the audience for a secret is the people who need it, not the people on the thread.
Related Customer Stories
Banking & Finance
Nasdaq Data Link Brings Small Data Vendors Into Its Marketplace With Files.com—Without Running Its Own SFTP
A branded intake for suppliers without delivery infrastructure stayed in place through the Quandl acquisition and now supports roughly three million API transactions a day.
Read story →
Banking & Finance
SumUp Scales EU-Resident Merchant Data Exchange Beyond 500 Accounts With Files.com
The exchange has run for nine years, while a site-level setting has kept every file in EU storage since 2018.
Read story →
Banking & Finance
Bambora North America Gives Thousands of Merchants Permanent, Account-Free FINTRAC Intake Through Files.com
A dedicated folder and non-expiring Share Link for each merchant turned manual compliance collection into repeatable infrastructure.
Read story →