SFTP for S3-compatible storage
Put SFTP in front of any S3-compatible store.
You run your own object storage because you wanted S3 semantics on infrastructure you control. Giving partners access over SFTP shouldn't mean putting that store on the internet.
SFTP.cloud works with RustFS, MinIO, Ceph, SeaweedFS and every other store that speaks the S3 API, self-hosted or hosted. No copy of your files on our side, no access keys in our hands, and no inbound rule on your firewall.
14 days. No credit card. No feature locks.
Inbound rules on your firewall0
01Supported stores
The store you run today, and the one you move to next.
The Storage Connector talks to your store through the S3 API. If it accepts S3 requests with an endpoint, an access key and a secret key, partners can reach it over SFTP.
Tested with SFTP.cloud
- RustFSSelf-hosted. Apache 2.0, built as a drop-in replacement for MinIO
- MinIOSelf-hosted. Community Edition and AIStor
- CephSelf-hosted, through the RADOS Gateway (RGW)
- SeaweedFSSelf-hosted, through its S3 gateway
- GarageSelf-hosted. Lightweight and geo-distributed
- Cloudflare R2Hosted
- Backblaze B2Hosted
- Linode Object StorageHosted, by Akamai
Running something else?
The Connector uses AWS’s official S3 client library for Go, the same library that already works with Wasabi, DigitalOcean Spaces, Dell ECS, NetApp StorageGRID, Cloudian HyperStore, IBM Cloud Object Storage, Oracle Cloud Object Storage, Hetzner, OVHcloud and Scaleway. If your store implements the S3 API, it connects the same way. Point a Connector at it during the free trial. On Amazon S3 itself, see SFTP for Amazon S3.
Running MinIO Community Edition?
MinIO put its Community Edition into maintenance mode in December 2025: no new features, and security fixes only case by case. Many teams are moving to RustFS, Ceph or SeaweedFS, and others are staying put for now.
SFTP.cloud works either way. With it in front of your store, a later move is invisible to your partners: you point the Connector at the new endpoint, and hostnames, accounts, keys and paths stay the same.
How switching works02How it works
Leave the store where it is. Add one small Connector next to it.
- 01
You deploy a Storage Connector.
As a container or a small VM on the same network as your store, often on the same host.
- 02
It reaches the store with an access key you create.
You scope it to the buckets and prefixes you choose, and it never leaves your network.
- 03
Your partners connect to SFTP.cloud.
Files stream through the Connector's own outbound channel, straight to and from the bucket. They are never written to a disk we own.
- Runs on
- Docker, Kubernetes, or a Linux or Windows service, on a VM or bare metal.
- Network
- Outbound connections only. The Connector reaches your store on the local network, so the store never needs a public address.
- Endpoint
- Any S3 endpoint URL, over HTTP or HTTPS, with path-style or virtual-hosted addressing.
- Throughput
- Each transfer runs over several parallel outbound streams, not one.
- Objects
- Stored as ordinary objects. Versioning, object locking, lifecycle rules and replication keep working.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": ["s3:ListBucket", "s3:GetBucketLocation"],
"Resource": "arn:aws:s3:::partner-exchange"
},
{
"Effect": "Allow",
"Action": [
"s3:GetObject",
"s3:PutObject",
"s3:DeleteObject",
"s3:AbortMultipartUpload"
],
"Resource": "arn:aws:s3:::partner-exchange/*"
}
]
}
03Security
Your keys stay with you. So does the choice of store.
The access key for your store lives on the Connector, inside your network. We never receive it, and nothing in our infrastructure can reach your store.
- 0Access keys or secret keys
- 0Inbound ports opened on your network
- 0Copies of your files
Moving from MinIO to RustFS, or to anything else.
Your partners connect to SFTP.cloud, never to the store itself. What sits behind the Connector is your decision, and you can change it on your own schedule.
- 01
Stand up the new store and copy your buckets.
With the tools you already use, such as
rclone syncormc mirror. The old store keeps serving partners while the copy runs. - 02
Point the Connector at the new endpoint.
Change the endpoint and the access key on the Connector. Nothing changes on our side, and there is nothing to tell us.
- 03
Your partners notice nothing.
Same hostname, same accounts, same SSH keys, same paths. Optional encryption with a key only your Connector holds moves with you. How we're built
04What you get
Everything in the product, on top of the store you already run.
- SFTP, FTPS, FTPES and a browser clientStandard protocols on standard ports, plus a WebClient for people without an SFTP client.Details
- Users, groups and path scopingGive each partner their own account, mapped to their own bucket or prefix.Details
- OIDC single sign-on and MFASign in to the WebClient with your identity provider, with MFA on top.Details
- Automatic blocking of attacking addressesBrute-force and scanning sources are blocked before they get a second try.Details
- Geo-fencingAllow or refuse connections by country.Details
- Dual signed audit trailsTwo independent chains, one signed with a key only your Connector holds. Verify them yourself.Details
- Automation next to your bucketSyncJS scripts run on your Connector before and after each operation, inside your network.Details
- Files on a NAS or file server too?The same Connector serves on-premises file storage alongside your buckets.On-premises storage
05FAQ
SFTP and S3-compatible storage, common questions.
Which S3-compatible stores does SFTP.cloud work with?
Any store that implements the S3 API. We have tested RustFS, MinIO, Ceph (through RGW), SeaweedFS and Garage, and the hosted services Cloudflare R2, Backblaze B2 and Linode Object Storage. Endpoints over HTTP or HTTPS, with path-style or virtual-hosted addressing, all work. The Connector uses AWS’s official S3 client library for Go, which also works with Wasabi, DigitalOcean Spaces, Dell ECS, NetApp StorageGRID, Cloudian HyperStore, IBM Cloud Object Storage, Oracle Cloud Object Storage, Hetzner, OVHcloud and Scaleway.
Does it work with RustFS?
Yes. RustFS speaks the S3 API, and the Connector treats it like any other store: an endpoint, an access key and a secret key.
Can I keep using MinIO now that Community Edition is in maintenance mode?
Yes. SFTP.cloud works with MinIO Community Edition and with AIStor. If you move to another store later, you point the Connector at the new endpoint and your partners keep the same hostname, accounts and keys.
Does my object store need to be reachable from the internet?
No. The Connector runs next to the store and only makes outbound connections. The store can stay on a private network with no inbound rule on your firewall.
Do you need my access key and secret key?
No. They are configured on the Connector inside your network and are never sent to us. You can rotate or revoke them without telling us.
Does SFTP.cloud store copies of my files?
No. Files stream through the Connector directly to and from your bucket. They are never written to a disk we own.
What does it cost?
From $2,400 a year on the Shared plan, with 15 transfer accounts and 3 Storage Connectors included, and no per-gigabyte or per-hour charge. Your store’s own costs, if any, are unchanged.
Point it at your store and try it today.
Deploy a Connector, give it an endpoint and an access key, and send your first file over SFTP in an afternoon. Fourteen days, no credit card, and nothing to cancel if it is not for you.
Want to see the moving parts first? See how it works or talk to an engineer. The person who answers builds the product.