Skip to main content

Wealth Enhancement Group Brings Custodian SFTP, PGP-Encrypted Files, and Email Into Its Cloud Stack With Files.com

One in-house-managed exchange now routes multiple terabytes of regulated data between counterparties’ existing transfer methods and the firm’s modern cloud systems.
Wealth Enhancement Group (WEG)Files.com

Wealth Enhancement Group is an independent wealth management and financial advisory firm growing substantially through acquisition. The firm is regulated on both sides of its business: an SEC-registered advisory arm and a FINRA-member broker-dealer.

A wealth manager of this size does not hold client assets itself. Custodians and clearing firms do. That means the operating data of the business, from positions to transactions to reconciliation files, lives in a constant exchange with large outside institutions whose technology Wealth Enhancement Group does not control. The firm's own estate, meanwhile, is modern cloud: Amazon S3 and Lambda for processing, SharePoint and Teams for its people, Workday for HR. Every counterparty relationship was a file crossing between those two worlds. The problem was never any one feed. It was that every workaround was point-to-point. As the feeds multiplied, point-to-point stopped scaling.

The Custodians Weren't Going to Change Their Protocols

The counterparty side of that exchange speaks the protocols it has spoken for decades. Custodians, clearing firms, and vendors transact over SFTP and FTPS, some over plain FTP, and some require PGP encryption on top. Most do not deliver into a cloud bucket.

The majority of all of our vendors only support SFTP or FTPS. They don't actually allow you to move things into an Amazon S3 bucket.
Kevin Anema, Application Support Manager, Wealth Enhancement Group

The cost of that mismatch showed up as work and as blind spots. Data had to be ferried into the cloud estate through hand-built glue, including an AWS Lambda function whose only job was unzipping incoming archives. Some clearing companies and custodians do not send files at all: the data arrives in the body of an email to a staff member, with a person handling it from there. And when a custodian's file was late, the only way to find out was to go check S3 and other systems by hand to see what had not arrived.

None of this was fixable at the source. A wealth manager cannot make the institutions that custody its clients' assets change how they transmit data. Wealth Enhancement Group needed a repeatable exchange that could absorb each counterparty's existing methods without extending the point-to-point sprawl.

One Endpoint Where Both Worlds Meet

The fix had to satisfy both sides without changing either. It had to present SFTP, FTPS, and FTP outward, so a counterparty connects exactly as it always has. It had to connect natively inward to S3, SharePoint, Workday, and the rest of the estate. It had to handle PGP encryption, decryption, and key management for regulated data. It had to capture even the data that arrives as email. And it had to be buildable and runnable by a small in-house team. Wealth Enhancement Group selected Files.com to be that common endpoint.

That common endpoint now moves multiple terabytes of regulated data through workflows run day to day by a single application support manager.

On the counterparty side, custodians, clearing firms, and vendors land on Files.com over the protocols they already run, from plain FTP connections to PGP-encrypted drops. Files.com's GPG handling decrypts inbound files and encrypts outbound ones automatically, including the encrypted integration folders that feed Workday, with keys managed in the platform instead of in scripts.

On the cloud side, Files.com remote server integrations connect the same folders to S3, SharePoint, and third-party endpoints including Box, Dropbox, and MuleSoft. Roughly 20 service accounts and bots run Files.com Automations that move files among those systems on triggers, and webhook notifications post into Teams when files land, so people find out without watching folders. Syncs feed S3, where the developer team's own Lambda processing takes over. Files.com became the layer that shouldn't have been Lambda's job, while the firm's real processing stayed exactly where it was.

The whole layer was built and is maintained in-house, wired into the firm's own tooling through the Files.com CLI.

I've integrated that with a couple of my other scripts.
Kevin Anema, Application Support Manager, Wealth Enhancement Group

When the Data Arrives as an Email, Not a File

The least automatable feed in the estate got the same treatment. For the clearing companies and custodians that send operational data in email bodies, Wealth Enhancement Group pointed a Files.com Inbox at the problem. The inbox captures the inbound email, writes the body out as a text file, and filters it. From there it is pushed to a Files.com Agent running inside the firm's own environment, where the firm's software transforms the data and distributes it to the end users who need it.

A feed that used to terminate in a staff member's mailbox now runs through the same governed pipeline as an SFTP drop.

What the Broker Layer Replaced

With the Files.com layer in production, Wealth Enhancement Group replaced point-to-point glue and manual handling with one brokered exchange between the counterparty world and its cloud estate.

  • Vendors and custodians that support only SFTP or FTPS transact with the firm at scale, and not one of them was asked to add S3 capability or change anything on their side.
  • Custodian data that arrived as email and stopped in an inbox now flows through an automated pipeline to the people who need it, without stopping for manual handling.
  • The Lambda step that existed only to unpack archives was retired when Files.com shipped native auto-unzip, and several syncs and workflows got simpler with it.
  • Every counterparty delivery lands in one layer with one activity record, so the question of whether a custodian's file arrived has a single place to answer it, instead of a hunt through S3 and the systems downstream.

The compounding result sits underneath all of those: the pattern now exists. Onboarding the next SFTP-only vendor means pointing it at an endpoint that is already there, not standing up another one-off integration. Multiple terabytes of regulated data move through the layer, encrypted where counterparties require it and logged throughout, and the whole thing is run day to day by a single application support manager.

Neither Side Had to Change

Wealth Enhancement Group never got to choose its counterparties' technology, and it turned out not to need to. The custodians kept their SFTP, their PGP keys, and their emails. The firm kept its cloud. Files.com is the layer where both sides get to stay exactly as they are and still transact.