SFTP for S3-compatible storage

Put SFTP in front of any S3-compatible store.

You run your own object storage because you wanted S3 semantics on infrastructure you control. Giving partners access over SFTP shouldn't mean putting that store on the internet.

SFTP.cloud works with RustFS, MinIO, Ceph, SeaweedFS and every other store that speaks the S3 API, self-hosted or hosted. No copy of your files on our side, no access keys in our hands, and no inbound rule on your firewall.

14 days. No credit card. No feature locks.

Path of one uploadPartner to bucket
1Your partner's SFTP clientFileZilla, WinSCP, OpenSSH or a script. Nothing new to install.
2SFTP.cloudAuthenticates the user and applies policy. Stores nothing.
Your network
3Your Storage ConnectorNext to the store. Dials out, never accepts inbound.
4Your object storeRustFS, MinIO, Ceph or any S3 endpoint. Unchanged, and still off the internet.

Inbound rules on your firewall0

01Supported stores

The store you run today, and the one you move to next.

The Storage Connector talks to your store through the S3 API. If it accepts S3 requests with an endpoint, an access key and a secret key, partners can reach it over SFTP.

Tested with SFTP.cloud

  • RustFSSelf-hosted. Apache 2.0, built as a drop-in replacement for MinIO
  • MinIOSelf-hosted. Community Edition and AIStor
  • CephSelf-hosted, through the RADOS Gateway (RGW)
  • SeaweedFSSelf-hosted, through its S3 gateway
  • GarageSelf-hosted. Lightweight and geo-distributed
  • Cloudflare R2Hosted
  • Backblaze B2Hosted
  • Linode Object StorageHosted, by Akamai

Running something else?

The Connector uses AWS’s official S3 client library for Go, the same library that already works with Wasabi, DigitalOcean Spaces, Dell ECS, NetApp StorageGRID, Cloudian HyperStore, IBM Cloud Object Storage, Oracle Cloud Object Storage, Hetzner, OVHcloud and Scaleway. If your store implements the S3 API, it connects the same way. Point a Connector at it during the free trial. On Amazon S3 itself, see SFTP for Amazon S3.

Running MinIO Community Edition?

MinIO put its Community Edition into maintenance mode in December 2025: no new features, and security fixes only case by case. Many teams are moving to RustFS, Ceph or SeaweedFS, and others are staying put for now.

SFTP.cloud works either way. With it in front of your store, a later move is invisible to your partners: you point the Connector at the new endpoint, and hostnames, accounts, keys and paths stay the same.

How switching works

02How it works

Leave the store where it is. Add one small Connector next to it.

  1. 01

    You deploy a Storage Connector.

    As a container or a small VM on the same network as your store, often on the same host.

  2. 02

    It reaches the store with an access key you create.

    You scope it to the buckets and prefixes you choose, and it never leaves your network.

  3. 03

    Your partners connect to SFTP.cloud.

    Files stream through the Connector's own outbound channel, straight to and from the bucket. They are never written to a disk we own.

Runs on
Docker, Kubernetes, or a Linux or Windows service, on a VM or bare metal.
Network
Outbound connections only. The Connector reaches your store on the local network, so the store never needs a public address.
Endpoint
Any S3 endpoint URL, over HTTP or HTTPS, with path-style or virtual-hosted addressing.
Throughput
Each transfer runs over several parallel outbound streams, not one.
Objects
Stored as ordinary objects. Versioning, object locking, lifecycle rules and replication keep working.
Access policyScoped to one bucket
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": ["s3:ListBucket", "s3:GetBucketLocation"],
      "Resource": "arn:aws:s3:::partner-exchange"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:GetObject",
        "s3:PutObject",
        "s3:DeleteObject",
        "s3:AbortMultipartUpload"
      ],
      "Resource": "arn:aws:s3:::partner-exchange/*"
    }
  ]
}
Attach it to the Connector's user on RustFS or MinIO. Ceph, SeaweedFS and hosted stores have their own way to limit a key to one bucket, and any of them works.

03Security

Your keys stay with you. So does the choice of store.

The access key for your store lives on the Connector, inside your network. We never receive it, and nothing in our infrastructure can reach your store.

  • 0Access keys or secret keys
  • 0Inbound ports opened on your network
  • 0Copies of your files

Moving from MinIO to RustFS, or to anything else.

Your partners connect to SFTP.cloud, never to the store itself. What sits behind the Connector is your decision, and you can change it on your own schedule.

  • 01

    Stand up the new store and copy your buckets.

    With the tools you already use, such as rclone sync or mc mirror. The old store keeps serving partners while the copy runs.

  • 02

    Point the Connector at the new endpoint.

    Change the endpoint and the access key on the Connector. Nothing changes on our side, and there is nothing to tell us.

  • 03

    Your partners notice nothing.

    Same hostname, same accounts, same SSH keys, same paths. Optional encryption with a key only your Connector holds moves with you. How we're built

05FAQ

SFTP and S3-compatible storage, common questions.

Which S3-compatible stores does SFTP.cloud work with?

Any store that implements the S3 API. We have tested RustFS, MinIO, Ceph (through RGW), SeaweedFS and Garage, and the hosted services Cloudflare R2, Backblaze B2 and Linode Object Storage. Endpoints over HTTP or HTTPS, with path-style or virtual-hosted addressing, all work. The Connector uses AWS’s official S3 client library for Go, which also works with Wasabi, DigitalOcean Spaces, Dell ECS, NetApp StorageGRID, Cloudian HyperStore, IBM Cloud Object Storage, Oracle Cloud Object Storage, Hetzner, OVHcloud and Scaleway.

Does it work with RustFS?

Yes. RustFS speaks the S3 API, and the Connector treats it like any other store: an endpoint, an access key and a secret key.

Can I keep using MinIO now that Community Edition is in maintenance mode?

Yes. SFTP.cloud works with MinIO Community Edition and with AIStor. If you move to another store later, you point the Connector at the new endpoint and your partners keep the same hostname, accounts and keys.

Does my object store need to be reachable from the internet?

No. The Connector runs next to the store and only makes outbound connections. The store can stay on a private network with no inbound rule on your firewall.

Do you need my access key and secret key?

No. They are configured on the Connector inside your network and are never sent to us. You can rotate or revoke them without telling us.

Does SFTP.cloud store copies of my files?

No. Files stream through the Connector directly to and from your bucket. They are never written to a disk we own.

What does it cost?

From $2,400 a year on the Shared plan, with 15 transfer accounts and 3 Storage Connectors included, and no per-gigabyte or per-hour charge. Your store’s own costs, if any, are unchanged.

Point it at your store and try it today.

Deploy a Connector, give it an endpoint and an access key, and send your first file over SFTP in an afternoon. Fourteen days, no credit card, and nothing to cancel if it is not for you.

Want to see the moving parts first? See how it works or talk to an engineer. The person who answers builds the product.