Skip to main content

A Tamper-Proof Record Of Everything On Your Site

Files.com, the File Orchestration Platform, writes down every login, every file moved, every permission change, every protocol session, and every setting change. It keeps that audit log for 7+ years, where no one can edit or delete it. Search it in the app, pull it through the API, stream it into your SIEM, or have it delivered as files to your own server. So when an auditor or an investigation asks what happened, you have the answer on hand. Moving to the cloud doesn’t mean losing access to your logs.

You Don’t Lose Your Logs When You Move To The Cloud

When you ran file transfer on-premise, you had hands-on access to every log, in the database and in files on disk. Most teams expect to give that up when they move to a cloud platform. Files.com is built the opposite way. You get all the same information, and more ways to reach it than you had before.

You reach the same record four ways, and turning any of them on is a setting, not a project.

app.files.com
The Files.com activity log: a searchable, time-stamped record of every file action, login, and change

Four Ways To Reach Your Logs

The same complete record, available however your team works: in the browser, in code, in your security stack, or as files on a server you control.

Search It In The App

A real search across your whole activity history, built into Files.com. It is not a raw dump you have to grep. Look up a user, a folder, an IP, or a date range and read exactly what happened, so you answer an auditor’s question in seconds instead of writing a log-parsing script.

Pull It With The API And CLI

Full programmatic access through the same API and CLI that drives the rest of the platform, so your own tooling and scripts read the log directly.

Stream It To Your SIEM

Send every event in real time to Splunk, Microsoft Sentinel, CrowdStrike, Datadog, Sumo Logic, or New Relic. Any other SIEM works too, over a generic JSON-over-HTTP connector. Files.com activity shows up alongside the rest of your infrastructure, so security watches one screen instead of two.

Get It Delivered As Files

Write timestamped JSON or CSV log files to a folder. Put them on Files.com, in your own cloud bucket, or onto your own on-premise server with the Files.com Agent. The file-based logging workflow you ran on-prem keeps working, so the scripts and tools already pointed at those files don’t change.

What Gets Logged

Every User Action

A per-user history of every login, upload, download, share-link creation, permission change, and key rotation. Each entry records who did it, when, and from which IP.

Every Folder Touched

A per-folder history of every file uploaded, downloaded, moved, copied, or deleted, with who did it, when, and from where. When a file goes missing, you can see exactly what happened to it.

Every Protocol Session

Separate session logs for SFTP, FTP, and WebDAV, each capturing the source IP, the client, the sign-in outcome, and the files touched in that session.

Every Setting Change

Every site-level setting change is logged, with who changed it, when, and what it changed from and to. This is the answer to "who turned off MFA enforcement two weeks ago."

Every Automation And Sync Run

Automation runs, sync runs, webhook deliveries, and API calls all land in the log, with the trigger, the outcome, and any retries recorded.

Every Share And Inbox Event

Every share-link creation, every recipient who opens one, and every inbox submission is captured as its own event, alongside public-hosting access logs.

Stream Every Event Into Your SIEM

Files.com delivers events in real time to the SIEM your security team already runs. There are native integrations for Splunk, Microsoft Sentinel, Datadog, CrowdStrike, Sumo Logic, and New Relic, plus a generic JSON-over-HTTP connector for any other SIEM. Files.com delivers the events; your SIEM does the correlation, alerting, and dashboards it already does for the rest of your infrastructure.

The audit log itself is on every plan. Real-time SIEM streaming is an Enterprise feature. The log is the trail auditors ask for under HIPAA’s audit-control requirement and SOC 2’s monitoring controls, with or without a SIEM attached. See what each plan includes on the pricing page.

Compare Plans

The Reports Auditors Ask For, Delivered On Schedule

Every access review starts with the same requests: who can reach what, who logged in, what got shared. Files.com builds those as standing reports, ready to run at any time: Permission Audit, Login History, Share Link Activity, Group Membership, and Site Usage by Folder.

Set a frequency and a recipient list once, and each report arrives by email on schedule. The quarterly permission review lands in the auditor’s inbox without anyone having to remember to run it, every quarter, indefinitely.

How Teams Answer Audits And Disputes With It

The four questions a file exchange gets asked over and over, and the record that answers each.

Prove Who Can Reach Which Client Folder

Export the permissions and user lists, with last login, and hand the auditor or the client’s security team a current access review instead of a screenshot tour of the admin console.

Settle A Delivery Dispute In Minutes

When a partner insists a file was never received, or a client asks who downloaded a report, the history for that path answers with the user, the protocol, the timestamp and the IP address. The argument ends with a record instead of a reconstruction.

Evidence That Streams To The Security Stack

Every login, transfer, permission change and sync run lands in Splunk, Sentinel, Datadog or any syslog target as it happens, so a compromised partner credential or a dormant account shows up in the same alerts as the rest of the estate.

Vendor Reviews That Close Themselves

A SOC 2 Type II report, a HIPAA BAA and a per-client audit trail answer the security questionnaire a client sends before it will send you its files.

Audit Log Questions

What teams ask about how Files.com records activity, how long it keeps it, and how to get it into their own systems.

Files.com audit log entries cannot be edited or deleted by anyone, including site administrators. Entries are stored in write-once-read-many (WORM) format and retained for 7+ years. That tamper-proof property is what makes the trail usable as evidence in a SOC 2 review, a HIPAA audit, or a forensic investigation, and it is the line between an audit trail and a log.

Files.com retains audit logs for 7+ years, which aligns with HIPAA’s six-year requirement and SOX’s seven-year financial-record requirement. The retention window scales by plan; lower tiers keep a shorter window. Check current details on the pricing page.

Files.com has direct, real-time integrations with Splunk, Microsoft Sentinel, CrowdStrike, Datadog, Sumo Logic, and New Relic, plus a generic “SIEM (Any Provider)” connector that delivers structured JSON over HTTP to any endpoint. Teams use that connector for Elastic, Chronicle, Securonix, Exabeam, and others. SIEM integration is an Enterprise feature; how Files.com integrates with your SIEM shows the routing.

Log File Streaming on Files.com writes timestamped JSON or CSV files to a folder you designate, on Files.com, in an external cloud bucket, or onto your own on-premise server through the Files.com Agent. Teams that ran on-prem and got logs as files on a box keep exactly that workflow.

Logging on Files.com is a setting an administrator switches on, not a build-it-yourself project. That covers the audit log, SIEM streaming, and file streaming. AWS Transfer Family makes you assemble equivalent logging from CloudWatch, a Lambda, and your own pipeline. On Files.com it is one button, and the logs help you troubleshoot faster from the first day.

Files.com Site Administrators can schedule recurring email delivery of the built-in reports: Share Link Activity, Login History, Permission Audit, Group Membership, and Site Usage by Folder. Set the frequency and recipients once, and the report arrives on schedule. It is how teams put quarterly access reviews and recurring compliance evidence on autopilot.

Filter Files.com history to the user, folder or action you need and export it as CSV from the web app, or pull the same records with the CLI or REST API for a scheduled report. Every download, upload, delete and login is a discrete event with user, protocol, timestamp and IP address.

Export the Files.com permissions report and user list, which show every user and group, the folders each can reach, the permission level and the last login. Paired with the SOC 2 Type II report and HIPAA BAA Files.com provides, that is the access-review evidence most audits ask for.

Search Files.com history for the partner’s account and folder over the disputed window. Every session and every upload attempt is recorded, so an empty result is itself the evidence. File-delivery monitoring can also flag the missed delivery on the day, so the dispute never reaches the audit stage.

See Everything That Happens On Your Site

Start a 7-day free trial, turn on logging with one setting, and watch every login, file event, and change land in a tamper-proof record you can search, export, or stream to your SIEM.

No credit card required • Free for 7 days • Live in minutes