SFTP for Amazon S3

Put SFTP in front of
your S3 bucket.

Leave the bucket where it is.

The architecture Active path
SFTP.cloud architecture Partners and staff reach you over standard SFTP, FTPS or HTTPS. SFTP.cloud terminates the protocol, authenticates the user and enforces your rules. The Storage Connector runs next to your storage and opens an outbound, mutually authenticated connection to SFTP.cloud. Data moves between your storage and your user across the Connector's own channel and is never written to a disk SFTP.cloud owns. SFTP · FTPS · HTTPS OUTBOUND, MUTUALLY AUTHENTICATED There is no disk here for it to be written to. Partners and staff the client they already use SFTP.cloud terminates the protocol · authenticates the user enforces your rules Storage Connector you install it · you hold its keys Your S3 bucket any region · unchanged

S3 is where your data already lives. It does not speak SFTP, and your trading partners do not speak S3. That gap is a well known nuisance, and the usual ways of closing it are more expensive and more invasive than they look.

No credit card. No feature locks. Walk away by doing nothing.

Pricing

What AWS charges for this

AWS Transfer Family is the obvious answer, and it is a competent product.

AWS Transfer Family

$0.30 per hour, per protocol
before a single byte moves
$2,628a year for SFTP alone
$217.20a month, AWS's own worked example
  • Add FTPS and it doubles
  • Data transfer $0.04 per GB in each direction, on top of your S3 costs
  • A single SFTP endpoint moving 1 GB a day

SFTP.cloud

$2,400 a year
with no per-gigabyte charge of any kind
15transfer accounts included
$0per GB, in each direction
  • SFTP, FTPS, FTPES and an HTTPS web client together
  • 15 transfer accounts included
  • No per-gigabyte charge of any kind
Start your 14-day free trial
No credit card required

How it works

How it works with S3

1

You deploy a Storage Connector.
.

Usually as a container or a small/free-tier instance in the same AWS account and region as your bucket.

2

It authenticates to S3 with your IAM identity

An identity you create and scope, and that identity never leaves your account.

3

Partners connect to SFTP.cloud with the client they already use.

Files stream through the Connector's own outbound channel. Your security group remains 100% closed inbound. They are never written to a disk we own.

Security

We never hold your AWS credentials

  • No access key. No secret key. No assumed role in our account. No cross-account trust policy for you to review. Nothing in our infrastructure could be stolen and used against your bucket, because there is nothing in our infrastructure that can reach it.

  • Rotate your IAM credentials whenever you like. You do not need to tell us, and we will not notice.

  • Optionally, encrypt the objects themselves with a key that lives on your Connector and that we never receive. Anyone who reaches the bucket by another route finds ciphertext.

What you get

  • SFTP, FTPS, FTPES and a browser client

  • Users, groups and path scoping

  • OIDC single sign-on, and MFA

  • Automatic blocking of attacking addresses

  • Geo- fencing

  • Dual signed audit trails you can verify yourself

  • Automation that runs on your Connector, next to your bucket

Works the same way with any S3-compatible store, including MinIO, Linode Object Storage, Ceph, Dell ECS, NetApp StorageGRID, Wasabi, Backblaze B2, Cloudflare R2 and DigitalOcean Spaces.