A Steel Producer Connects SAP Data Sphere to Its On-Premises Plant Without Building an SFTP Server
A North American steel producer runs a plant whose process systems stay on premises by design.
Steel production is continuous, and the process systems behind it have to be available every hour of every day, so the company keeps them in the building rather than staking them on cloud availability. That posture is deliberate, and it set up a collision. Clients and partners needed a place to exchange files with the company. SAP Data Sphere, running in the cloud, needed to deliver files into those same on-premises systems. Both required exactly the thing the posture forbids: an endpoint on the internet with a path into the plant.
On-Prem by Design, With Nowhere to Drop a File
The company had no SFTP capability at all. The business needed a location to put individual files for clients and partners to retrieve, and to pull files back down itself, and it needed SAP Data Sphere output to land in on-premises systems. Neither exchange had anywhere to happen.
The one in-house answer was to build the endpoint: stand up an SFTP server, put it on the internet, and own it. For the systems architecture team, owning it meant a host to keep alive, an operating system to patch on the schedule of whoever finds the next vulnerability, keys and accounts to manage, and the security posture of a permanently exposed machine to defend. All of it indefinitely, and none of it steelmaking. That server would also have been the one standing door into an environment the company keeps sealed on purpose.
An SFTP Layer in Front of the Plant, Not Inside It
The requirement, restated as a specification: a dedicated SFTP endpoint that clients, partners, and SAP could reach; a path from that endpoint into the plant that opened no inbound port; and no server for the company to run. The company selected Files.com to provide that managed SFTP layer.
On the outside, Files.com is the endpoint. Clients and partners connect to it, drop files, and retrieve what the company has left for them. The same endpoint receives files from SAP: The company created a dedicated service account for SAP Data Sphere, authenticated by SSH key rather than a password, and handed the public key to its SAP team for the inbound connection.
On the inside, on-premises Files.com Agents carry files the rest of the way. An Agent runs on a server inside the company's network and connects outward to Files.com, so nothing in the plant listens for the internet and no inbound firewall rule exists. When Data Sphere delivers a file, the Agent brings it in and lands it on the on-premises systems that need it. Files.com sits in that path as a second firewall layer in front of the plant environment: the only thing exposed to the internet is Files.com itself.
The company deployed the Agents across development and production, giving the SAP integration parallel paths under its existing change discipline. It governed access to the managed endpoint with country-based IP restrictions, single sign-on for internal users, file expiration, and granular permissions for external parties.
SFTP Became a Service Instead of a Server
With the workflow in production, the company replaced a server it would have had to build with a service it configures. SAP Data Sphere delivery and client and partner exchanges now run through the same managed endpoint, while the systems architecture team owns no internet-facing host to patch, maintain, or defend.
The compounding result is what happened next. New file workloads landed on it instead of spawning new infrastructure. Internal applications now stage files on Files.com and periodically pull them back down, and the platform holds the printing configuration for the company's XM Cloud environment. Each arrived on an already governed platform, with nothing new to build and nothing new to expose.
The Plant Stays Sealed
Today, when the business brings the next file exchange—whether from a partner, a cloud application, or an internal system—meeting it means configuring the platform rather than building and defending a server. The one internet-facing piece of the company's file exchange is Files.com's to run.
Related Customer Stories
An Automotive Distributor Puts Every External File Exchange on One Security-Owned Files.com Channel
Identity federated through the parent automaker, the brand’s own domain, Canadian data residency, and Inboxes that land partner documents in SharePoint, adopted across the business without an internal campaign.
Read The Story
A Semiconductor Company Uses Files.com for Modem-Log Collection Across Three Simultaneous Carrier Assessments
A shared collection layer let contractor teams upload multi-gigabyte handset logs without VPN access while the company kept its analysis systems on-prem.
Read The Story
A Computer Manufacturer Retired Its Warranty Repair FTP Server With Files.com—Without Changing the Address
A weekend cutover moved the repair channel to Files.com while preserving the endpoint and protocols its service providers already used.
Read The Story
Get The File Orchestration Platform Today
4,000+ organizations trust Files.com for mission-critical file operations. Start your free trial now and build your first flow in 60 seconds.
No credit card required • 7-day free trial • Live in minutes