Skip to main content

September 2026

In September 2026, we released Automations v2 as an early beta and added One-Way Partner Channels, the Partner Channel Home Page, Root Folder Settings that Site Administrators control across every Workspace, a dedicated S3-Compatible Endpoint permission, dedicated IPs and SFTP host keys for additional Custom Domains, AI Assistant access for selected groups, and isolation controls for Public Hosting. We also shipped security updates to the Agent, the Desktop App, the CLI App, and every official SDK, along with V2 webhook signatures that replace the older MD5-based ones. Minor updates cover Custom Form edits, separate Desktop App and Mobile App session lifetimes, Custom SMTP SSL Mode, Custom Message Only emails for Event Channels, and formatting in the custom email footer.

Security Updates

Two security changes this month affect software you run yourself.

Security Updates for the Agent, Desktop App, CLI App, and SDKs

We shipped security updates to the Files.com Agent, the Desktop App, the CLI App, and every official SDK in September.

If you use any of them, update to the latest version.

The Agent and the Desktop App update themselves by default, so they install these updates on their own. If your team turned off automatic updates to manage deployment itself, install the new versions now.

Learn more about Client Software and Security Updates.

V2 Webhook Signatures

Verify webhooks from Files.com with the X-Files-Signature-V2 header. The older folder webhook signatures use MD5, which is no longer considered secure.

V2 signs the complete request with HMAC-SHA256. It uses the Verification token or signing secret you already have, so moving to V2 doesn't require a new one. It covers folder webhooks, including the EV1 and EV2 legacy formats, and Event Channel webhook targets. The older signature headers are deprecated and stay available, so existing receivers keep working until you switch.

Update your receiver to verify V2, and reject any request without a valid V2 signature.

Learn more about Webhook Signatures.

Automations v2 (Early Beta)

Automations v2 connects actions and controls into a multi-step workflow. One run can receive a file, transform its contents, branch on what it finds, encrypt it, and deliver it to several destinations, with a recorded result for each node. Build the workflow in the visual Builder, or as a JSON definition through the Files.com API, starting from file activity, a schedule, an incoming email, an incoming webhook, or a manual run. Expressions can read a file's Custom Metadata, and files received over AS2 carry their AS2 headers as Custom Metadata, so one Automation can route each partner's files without opening them.

Automations v2 is an opt-in early beta and is not recommended for business-critical production workflows. Contact Support or your account manager to request beta access for your site. Once it is enabled, Site Administrators and Workspace Administrators configure v2 Automations, and your existing v1 Automations keep running unchanged.

Learn more about Automations v2.

Updates to Partner Channels

Partner Channels gained one-way exchanges and a simpler upload experience for Partners who mostly send you files.

One-Way Partner Channels

A Partner Channel's Direction can now be Files To Partner Only or Files From Partner Only, so a delivery-only or collection-only exchange gets a folder, permissions, and routing only for the direction you enable. A one-way Channel can also use the channel folder directly, with no outgoing or incoming subfolder, so a partner whose script already reads /DailyFlows/report.csv keeps that exact path after the exchange moves to Files.com. Partner Channel Templates support both, and a Template's route destination can be a fixed folder that every assigned Partner reads through its own Channel, without per-Partner copies. Choose the folder layout when creating a Channel or Template, because it can't change afterward.

Learn more about Partner Channel Folders and Directions.

Partner Channel Home Page

The Partner Channel Home Page gives a Partner's users a Home page with one upload destination for each folder they upload into, so they drop files without browsing the folder tree. It replaces the File Manager as the first page they see after signing into the web interface, and uploads land in the same From Partner Folders, with the same routing and Automations. Site Administrators and Workspace Administrators enable it per Partner. It is off by default, and users who connect through SFTP, FTP, or other protocols see no change.

Learn more about the Partner Channel Home Page.

Root Folder Settings

Two new site settings let Site Administrators govern the folder settings on the site's root folder. Restrict Root Folder Settings to Site Administrators keeps folder admins on the root from changing or removing settings a Site Administrator put there. Root Folder Settings Apply to All Workspaces extends File Expiration, file extension limits, filename limits, and Malware Scanning on the site root into every Workspace, including Workspaces created later. Enforcement starts as soon as you turn it on, so File Expiration on the root begins applying inside Workspace folders right away. Parent Site Administrators can apply both settings to Child Sites through a Child Site Management Policy.

Learn more about Root Folder Settings.

Dedicated S3-Compatible Endpoint Permission

Users and groups now have their own S3-Compatible Endpoint permission in Protocol Access, alongside FTP, SFTP, WebDAV, and Web, Desktop App, and API. It works independently of the others, so you can run an S3-only service account with every other protocol turned off, and you can cut off a user's S3 access without deleting their keys or disabling the account. New users have S3 allowed and new groups have it disallowed. Site Administrators manage the permission on the user or group details page, and Workspace Administrators manage it within their own Workspace.

Learn more about S3 Protocol Access.

Dedicated IPs and SFTP Host Keys for Custom Domains

One Files.com site can now take over several existing SFTP services and keep each one's hostname, IP addresses, and host keys, in both directions. Custom Domains and dedicated IP addresses are available on the Power and Enterprise plans.

Multiple Custom SFTP Host Keys

Site Administrators can select several custom SFTP host keys for the site, one per algorithm, so clients added over the years that support different algorithms each keep the host key they already trust. Custom host keys require dedicated IP addresses, which your site receives with its Primary Custom Domain.

Learn more about Site-Wide Keys.

Dedicated IPs and SFTP Host Keys for Additional Custom Domains

A Site Administrator can give an additional Custom Domain its own one or two dedicated IP addresses with Add Dedicated IPs, and assign custom SFTP host keys to that domain instead of the whole site. Each domain then presents its own FTPS certificate and SFTP host keys, so several SFTP services can move onto one site and keep their distinct hostnames and server identities. The domains still lead to the same site, with the same users and permissions.

Learn more about Dedicated IP Addresses and FTPS.

Choose Which Custom Domain's Dedicated IPs a Remote Server Uses

A Remote Server can now be tied to one Custom Domain, so every connection to that server originates from that domain's dedicated outbound IP addresses. When your site carries several sets of dedicated addresses, each counterparty sees connections only from the addresses it allowlisted. Site Administrators and Workspace Administrators pick the domain under Connection Routing when adding or editing a Remote Server, and the server's details page shows the exact addresses to give the remote operator. If the selected domain later becomes unavailable, connections fail instead of switching to a different set of addresses.

Learn more about Dedicated IP Routing.

AI Assistant Access for Selected Groups

Site Administrators can now offer the AI Assistant to members of selected groups without making it available to every user. Turn All Users off, enable Selected Group Members, and choose groups from the default Workspace or any custom Workspace. Availability options are additive, so administrator access stays independent of group membership, and the Assistant still works within each user's existing permissions. Partner Users can't belong to groups, so they don't receive access this way.

Learn more about Enabling and Disabling the AI Assistant.

Public Hosting Isolation Controls

Hosted folders on the same hosting domain share a browser origin, and new folder settings let you separate them. An allowed-origins list limits which websites can read a folder through CORS. HTML sandboxing displays published HTML but blocks its scripts, form submissions, and popups, and a folder bound to its own Custom Domain can be served only on that domain. Turn on sandboxing for any hosted folder that someone other than an administrator can write to.

Learn more about Setting Up Public Hosting.

Other Minor Updates

This month's smaller updates cover Custom Forms, app sessions, and email.

Custom Form Edits Preserve Earlier Answers

You can edit a Custom Form while it is assigned to an Inbox or Share Link and after it has collected registrations, without changing the meaning of answers already collected. Edits apply to future registrations, and earlier answers keep the original question label, field type, and choices, even when you remove a field.

Learn more about Editing a Custom Form.

Separate Desktop App and Mobile App Session Lifetimes

Security settings now show Desktop App Session Lifetime and Mobile App Session Lifetime separately, so you can set how long Mobile App sign-ins last from the web interface. Desktop App sessions default to 180 days and Mobile App sessions to 30 days. A change applies to new sessions only and doesn't affect the other app.

Learn more about Session Lifetime and Device Removal.

Custom SMTP SSL Mode

Custom SMTP has an SSL Mode setting with four options: Use If Available (the default), Require SSL (Explicit), Require SSL (Implicit), and Never Use. With Use If Available, the first certificate-verified STARTTLS connection to your server switches the saved mode to Require SSL (Explicit), and Files.com never lowers the requirement on its own. Parent Site Administrators can enforce the mode on Child Sites through a Child Site Management Policy.

Learn more about SMTP Encryption.

Custom Message Only Emails for Event Channel Subscriptions

Turn on Custom Message Only and a subscription's notification emails contain only your Custom Message, your site's branding, and the standard footer, without the event details or the Review notifications button. Use it to notify people who don't have access to your site. The setting requires a Custom Message and is off by default.

Learn more about Subscription Email Content.

On Power plans and above, Custom email footer text uses the rich text editor and supports Markdown, so you can format the footer and link to resources like a privacy policy or contact page. The formatting appears in the system-generated emails your site sends. On other plans, the footer stays plain text.

Learn more about Setting Custom Email Footer Text.

Get The File Orchestration Platform Today

4,000+ organizations trust Files.com for mission-critical file operations. Start your free trial now and build your first flow in 60 seconds.

No credit card required • 7-day free trial • Live in minutes