Skip to main content

A Wealth Accounting Firm Replaced Kiteworks With a Files.com Portal That Isolates Dozens of Client Organizations

A carve-out from its former parent forced the firm to rebuild confidential document exchange around authenticated, isolated client spaces while preserving the controls its financial-institution clients audit.

A private wealth accounting firm runs the general ledger for the upper end of private wealth. Its accounting and reporting platform serves family offices, private banks, wealth advisors, and private funds.

Bringing a new client onto that ledger is not a signup flow. An implementation runs three to twelve months, and it runs on documents: account statements, spreadsheets, PDFs, files carrying account numbers and personal information, moving back and forth between the client and the firm's implementation team for the length of the engagement. That exchange is the front door of the business. Until recently, the front door ran on somebody else's infrastructure.

The Exchange Ran on a Former Parent's Kiteworks

For years, the firm operated as a unit of a larger parent. When the business was carved out, everything file-related lived inside the parent's environment, and separating meant losing all of it, including the Kiteworks instance that carried client onboarding exchange.

The workflow by which every new client arrives, months of confidential document exchange, ran on a Kiteworks instance the firm could not brand or keep.

And the bar for the replacement was set by the clients themselves. The firm serves some of the largest financial institutions in private wealth, and they audit it on every engagement. Whatever took over from Kiteworks had to hold up under that scrutiny while it was being stood up.

Links Were the Fast Answer and the Wrong One

The quickest replacement would have been share links: send a client a URL and let them upload. The firm rejected that on its clients' behalf. The people on the other end of this exchange are sending account statements with account numbers on them, and the firm wanted every one of them behind an authenticated account rather than a link anyone holding it could open.

So the replacement had to do specific things. It had to seal every client organization off from every other, and scope third parties tighter still, so a client's auditors could upload into one subfolder without seeing the rest of the tree. It had to carry the firm's own domain and branding on every page a client touches, and it had to work through authenticated accounts rather than links. And it had to be fully hosted, because the firm was standing up an IT estate from scratch and had no appetite for more servers to run.

The firm selected Files.com to carry the exchange and built it as a dedicated child site: a fully separate site with its own domain, branding, and security policy, under the same Files.com deployment that was absorbing the rest of the divestiture's file transfer.

One Walled Container Per Client, on the Firm's Own Domain

The design turned each client relationship into its own walled space on a portal the firm owns.

The child site runs on a custom domain of the firm's own, under the firm's branding, so everything a client sees reads as the firm's. And because Files.com child sites carry their own security policy, the portal's posture is set for exactly what it does. This is human-to-human exchange, so the firm deliberately disabled SFTP on the site: the only way in is an authenticated web login.

Inside, each client organization is a Files.com Partner in its own container, with a folder tree organized by document type. That boundary is enforced by the container itself. A user provisioned to one financial institution reaches that institution's folders and nothing else: not another bank's, not another family's. Where an engagement pulls in third parties, the scoping goes a level deeper, and a client's auditors can be given upload rights to a single subfolder with no visibility into anything around it.

Administration is delegated to the same boundary. Partner team leads and partner administrators create and manage their own downstream users inside their container, and every action on the site, by anyone, lands in one audit log.

The Users Carried Their Own Files Out of Kiteworks

The move out of Kiteworks was run by the people who owned the content. Internal users rebuilt their folder structures on the new site, exported their Kiteworks content as zips, and dragged it in.

The firm provisioned dozens of client organizations in bulk through a two-stage CSV import, creating each partner container with its permissions before mapping users into it. Invitations were timed so client team leads could tell their clients what was coming before the first email from the new portal went out.

The controls held under real scrutiny: the firm passed a major audit during the migration itself.

What Runs on the Portal Now

In production, the portal changed the operating model:

  • Client onboarding document exchange now runs on the firm's own domain, under its own branding, on infrastructure the firm governs and Files.com operates. There are no servers for the firm to patch.
  • Every client organization is isolated by construction. A user at one institution sees only that institution's tree, and auditors and other third parties work inside a single scoped subfolder.
  • Account administration moved out of IT. Partner team leads manage their own users inside their own container, work that previously routed through the firm's IT team.

The compounding result is what the next engagement costs. Onboarding another client organization now means creating a container, setting its permissions, and sending invitations; the folder pattern, the isolation, and the delegation come with it. It does not mean a new tool, a new access path, or a queue of account requests into IT.

The Front Door Belongs to the Firm

An implementation still runs three to twelve months, and it still runs on documents. What changed is whose infrastructure carries them. An engagement used to begin on a Kiteworks instance the firm could not brand or keep. It now begins with the client's team signing in to a Files.com portal under the firm's own name, into a folder tree that exists only for them.

The replacement did not trade rigor for ownership, either. The fast answer, links, would have loosened control at the exact moment clients hand over their most sensitive records. Authenticated partner containers on Files.com tightened it instead. For the firm that keeps the ledger for some of the wealthiest families in America, the exchange that starts every client relationship is now something the firm owns, brands, and can prove control of.

Get The File Orchestration Platform Today

4,000+ organizations trust Files.com for mission-critical file operations. Start your free trial now and build your first flow in 60 seconds.

No credit card required • 7-day free trial • Live in minutes