Managed SFTP · FTPS · HTTPS
Your files never
touch our servers.
Not by policy. By architecture.
Enterprise file transfer for the storage you already own:
Amazon S3 (and compatible, like MinIO, Backblaze, etc), Azure Blob, Google Cloud, or the Disk/SMB/NAS/SAN or SFTP server in your own data-center. We run the protocols, the users, and the audit trail. Your data stays under your control.
No credit card. No feature locks. Walk away by doing nothing.
Managed SFTP · FTPS · HTTPS
We never hold your
storage credentials.
Not by policy. By architecture.
Enterprise file transfer for the storage you already own:
Amazon S3 (and compatible, like MinIO, Backblaze, etc), Azure Blob, Google Cloud, or the Disk/SMB/NAS/SAN or SFTP server in your own data-center. We run the protocols, the users, and the audit trail. Your data stays under your control.
No credit card. No feature locks. Walk away by doing nothing.
Managed SFTP · FTPS · HTTPS
We cannot alter
your audit trails.
Not by policy. By architecture.
Enterprise file transfer for the storage you already own:
Amazon S3 (and compatible, like MinIO, Backblaze, etc), Azure Blob, Google Cloud, or the Disk/SMB/NAS/SAN or SFTP server in your own data-center. We run the protocols, the users, and the audit trail. Your data stays under your control.
No credit card. No feature locks. Walk away by doing nothing.
Managed SFTP · FTPS · HTTPS
Your firewall
stays closed.
Not by policy. By architecture.
Enterprise file transfer for the storage you already own:
Amazon S3 (and compatible, like MinIO, Backblaze, etc), Azure Blob, Google Cloud, or the Disk/SMB/NAS/SAN or SFTP server in your own data-center. We run the protocols, the users, and the audit trail. Your data stays under your control.
No credit card. No feature locks. Walk away by doing nothing.
The problem
Managed file transfer keeps
ending up in the news.
There is a structural reason.
A conventional file transfer platform has a specific shape. It sits on the public internet, because your partners have to reach it. It holds the credentials to your storage, because that is how it fetches your files. And it stages those files on its own disks while they are in flight, or simply stores them there outright.
That shape concentrates some of the most sensitive bulk data in an organization into one internet-facing system, and it does the same thing for hundreds of other organizations at once.
One flaw in one product becomes a breach at every company running it. It has happened at least four times in five years, to four different vendors, and the same malicious actors ran the same play each time.
So we built a different shape.
How it works
Your storage stays yours.
We handle everything in front of it.
Guarantees
Three things we cannot do,
even if we wanted to.
Files
We cannot read your files.
They are never written to our storage. Not encrypted at rest on our disks, not cached, not buffered to a temporary volume under load. They pass between your Connector and your user, and then they are gone.
Credentials
We cannot reach your storage.
There is no access key, no OAuth token, no service principal and no assumed role held on our side. The Connector authenticates to your storage from inside your network, using credentials that never leave it. There are no credentials to your storage in our infrastructure, so there are none to steal.
Audit trail
We cannot rewrite your record.
Every session writes two audit trails, one on our infrastructure and one on your Connector. Yours is generated inside your network and signed with a key we never hold. We cannot edit yours. You cannot edit ours. If they ever disagree, you can prove it without us.
Every system can be attacked, and you should be suspicious of anyone who tells you otherwise.
The better question is what can an attacker walk away with? With SFTP.cloud the answer is: neither your files nor the keys to them.
Architecture is why you would trust it. This is why you would use it.
Capability
And it does the actual job.
Architecture is why you would trust it. This is why you would use it.
-
Familiar protocols your partners already have.
SFTP, FTPS, FTPES, and a browser-based HTTPS client for the people who will not install anything.
-
The storage you already own.
Amazon S3 and S3-compatible, Azure Blob, Google Cloud Storage, MinIO, upstream SFTP servers, and on-premises file storage. Connect several at once.
-
Users, groups, and access rules.
Provision transfer accounts, scope them to paths, and manage all of it from a web console or the API.
-
A signed audit trail on both sides.
One on our infrastructure, one on yours, each signed with a key the other party never holds.
-
Encryption ready for what is coming.
Post-quantum cipher suites across SFTP, FTPS and HTTPS, and mutual TLS between every internal component.
-
Isolation when you need it.
A dedicated environment adds your own connection allow lists, short usernames without a site suffix, and several other service-level knobs for you to control and customize.
HTTPS access
The same storage,
through the browser.
Not every user has an SFTP client. The WebClient gives them the same virtual file systems, permissions and audit trail over HTTPS, with server-side transfers that finish even when the browser doesn't stay open.
The console
You can see everything,
the moment it happens.
Every session, every transfer, every rejection. All in real-time, all in one place. Watch the activity of each virtual file system, see which user is connected right now, and follow a file transfer’s lifespan from arrival to event-handlers without having to dig through complicated log files.
Pricing
Two plans. Both published.
Priced per account, not per gigabyte.
You pay for accounts. Not for storage (we store nothing) and not for transfer or bandwidth.
No unexpected surprises on your renewal invoice.
Shared
from $2,400 a year
(or $240 a month)
Dedicated
from $8,400 a year
(or $840 a month)
Both prices are on the page, in public, where you can compare them before you talk to anyone.
Verify it yourself.
Fourteen days on a shared environment, with your own storage connected. No credit card, and nothing to cancel if you decide it is not for you.
Fourteen days on a shared environment, with your own storage connected. No credit card, and nothing to cancel if you decide our service is not for you.
Still in diligence?
Read the security architecture or talk to an engineer The person who answers builds the product.
Still in diligence?
Read the security architecture
or talk to an engineer The person who answers builds the product.