SFTP for Google Cloud Storage

Google Cloud does not
have a manage SFTP
service.

This is the gap.

The architecture Active path
SFTP.cloud architecture Partners and staff reach you over standard SFTP, FTPS or HTTPS. SFTP.cloud terminates the protocol, authenticates the user and enforces your rules. The Storage Connector runs next to your storage and opens an outbound, mutually authenticated connection to SFTP.cloud. Data moves between your storage and your user across the Connector's own channel and is never written to a disk SFTP.cloud owns. SFTP · FTPS · HTTPS OUTBOUND, MUTUALLY AUTHENTICATED There is no disk here for it to be written to. Partners and staff the client they already use SFTP.cloud terminates the protocol · authenticates the user enforces your rules Storage Connector you install it · you hold its keys Your storage same region · unchanged

AWS has Transfer Family. Azure has native SFTP on Blob Storage. Google Cloud has Storage Transfer Service, which moves data between storage systems in batches and is a genuinely useful thing, but it is not an SFTP server and it will not give a trading partner a place to connect. 

So the usual answers are to run your own SFTP server on a Compute Engine instance, or to hand your bucket credentials to a third party. Neither is appealing.

No credit card. No feature locks. Walk away by doing nothing.

How it works

A third option

1

Deploy a Storage Connector in your Google Cloud project

Usually in the same region as your bucket. It authenticates to Cloud Storage using a service account you create and scope, and that service account key never leaves your project.

2

Partners connect to SFTP.cloud

Over SFTP, FTPS, FTPES or HTTPS with the clients they already have.

3

Files stream through the Connector's outbound channel

Between your bucket and your partner. They are never written to a disk we own.

No VM to patch. No sshd to configure. No public endpoint of your own to defend.

Security

We never hold your service account key

  • There is no key, no token and no delegated identity on our side. The Connector authenticates from inside your project, with credentials you created. Nothing in our infrastructure could be stolen and used against your bucket.

  • Optionally, encrypt the objects with a key that lives on your Connector and that we never receive.

Features

What you get

  • SFTP, FTPS, FTPES and a browser client

  • OIDC single sign-on, and MFA

  • Path scoping, geo-fencing and automatic blocking of attacking addresses

  • Dual signed audit trails you verify yourself

  • Automation running on your Connector

  • From $2,400 a year, with no per-gigabyte charge