On-premises storage

A cloud SFTP endpoint

for files that never leave your building.

The architecture Active path
SFTP.cloud architecture Partners and staff reach you over standard SFTP, FTPS or HTTPS. SFTP.cloud terminates the protocol, authenticates the user and enforces your rules. The Storage Connector runs next to your storage and opens an outbound, mutually authenticated connection to SFTP.cloud. Data moves between your storage and your user across the Connector's own channel and is never written to a disk SFTP.cloud owns. SFTP · FTPS · HTTPS OUTBOUND, MUTUALLY AUTHENTICATED There is no disk here for it to be written to. Partners and staff the client they already use SFTP.cloud terminates the protocol · authenticates the user enforces your rules Storage Connector you install it · you hold its keys Your file server or NAS SMB · CIFS · NFS · local paths

Your files are on a file server, a NAS, or an SMB share that has been there longer than most of the team. Moving them to somebody's cloud to make them reachable by SFTP is a large change to make, not to mention a new attack surface you previously didn’t have.

No credit card. No feature locks. Walk away by doing nothing.

How it works

Keep the files. Move the endpoint.

1

Deploy a Storage Connector on a server inside your network.
.

On a server in your datacenter, as a container in Kubernetes, or even on your NAS if it supports running your own containers. Deploy more than one for redundancy or to reach storage in different networks.

2

The Connector opens one outbound connection to SFTP.cloud and holds it open.

It needs to connect outbound-only to the SFTP.cloud Portal and to your SFTP.cloud Head on port 7600. Nothing else. These are the only firewall rules you'll need, and they’re outbound, no one can get in through them.

3

Your partners connect to a managed, highly available cloud endpoint.
.

Connect local storage, your NAS, SAN, DFS, or anything you can mount from a SBM/CIFS/NFS share. Hold the files in plain form, or encrypted with a key that stays on the Connector.

The trade

Why this is usually the point

Hosted file transfer, usually

The hosted option wants your data

  • An internet-facing SFTP server that is somebody else's to patch, monitor and keep available
  • In exchange, your files move to their cloud
  • A new attack surface you previously didn't have
The uncomfortable trade
SFTP.cloud

This one does not

  • We operate the endpoint, the protocols, the users and the availability
  • You keep the files, on premises, where your policy already says they belong
  • Nothing about your network perimeter changes
Keep the files. Move the endpoint.

Features

What you get

  • SFTP, FTPS, FTPES and a browser client for partners who will not install anything

  • OIDC single sign-on, MFA and path scoping

  • Automatic blocking of attacking addresses, geo-fencing and connection allow lists

  • Dual signed audit trails you verify yourself

  • Automation running on the Connector, inside your network

  • Optional encryption at rest with a key that never leaves it