Managed SFTP / FTPS for Amazon S3 & S3-compatible storage

Fully managed SFTP for your own cloud storage.

Put a fully managed SFTP/FTPS endpoint in front of an existing Amazon S3 bucket — or any S3-compatible store like Cloudflare R2 — in minutes. The people and systems that need it get standard SFTP access; your files stay in your own bucket, on your own cloud account.

No migration, no lock-in. On S3 we connect through a cross-account role you control and store no keys at all; on R2 and other S3-compatible stores, access is a scoped key you can revoke anytime, encrypted at rest. Either way, your files stay yours.

Bring your own bucket · no data migration · live in minutes

Why Firepipe

Your bucket, your data

Files stay in your own bucket — Amazon S3 today, or any S3-compatible store like Cloudflare R2 — nothing to migrate, no lock-in. We connect with least-privilege access and never store your file contents, so your data never lands on our infrastructure. (Azure Blob and Google Cloud Storage are on the way.)

On S3, no keys to leak

Connect an Amazon S3 bucket through a cross-account role you grant and revoke at will — Firepipe stores no access keys at all, so there is nothing on our side to leak or lose. For Cloudflare R2 and other S3-compatible stores, access is a scoped key you can revoke anytime, encrypted at rest (AES-256-GCM).

No surprise fees

Fair, transparent pricing. Firepipe never charges per operation or per listing — you pay for simple metered throughput, and nothing else. (Your own cloud usage is billed by your provider, directly to you.)

Your data never touches our servers

Files stay in a bucket you own, on your own cloud account. Firepipe streams every transfer straight through to your storage — we never copy your files out and never store them. Your file contents never live on our infrastructure.

Access is least-privilege and revocable on your own terms. On S3 that's a cross-account role with no keys for us to hold at all; on R2 and other S3-compatible stores it's a scoped key, encrypted at rest, that you revoke whenever you like. Either way, cutting us off is a change on your side — and your data is already exactly where it has always been.

How it works

Three steps from an existing bucket to a fast, ready-to-use SFTP endpoint.

01

Connect your bucket

Point Firepipe at an existing S3 or S3-compatible bucket (such as Cloudflare R2). For S3, grant a scoped cross-account role — no keys to copy; for R2, paste a scoped access key. No data to migrate either way.

02

Create SFTP users

Issue per-user SFTP credentials (password or SSH key), each jailed to one path prefix — for people or automated systems. Hand out the hostname and a static IP.

03

Files flow, listings stay instant

Users and systems upload and download over SFTP/FTPS straight to your bucket. A synced index keeps every `ls` fast, no matter how many files pile up.

See and control every transfer

Run it in production with the visibility and control an audit team expects.

A full audit trail

Every login, upload, download, and delete is logged with the user, path, and timestamp. Filter by user, action, or date, and export the whole trail to CSV whenever you need it.

Per-user access you control

Issue credentials per user or system, each jailed to a single path prefix with its own quota. See who is connected and when they were last active — and revoke any of them instantly.

Live connection status

Watch each bucket connection go from initializing to ready at a glance, with a clear reason surfaced if anything needs your attention. Activity totals show logins and transfer volume over time.

Coming soon: trigger your own simple actions when a file arrives — no cloud-function plumbing to wire up.

How it compares

Firepipe Other SFTP gateways All-in-one platforms
Files stay in your own bucket
Instant listings at millions of files
No per-operation / per-listing fees from us

Comparison reflects each product's standard offering for the bring-your-own-bucket use case.

Pricing

Fair and transparent: simple metered throughput, with no per-operation or per-listing fees from us and a static IP for firewall allowlists included as standard. (Your own cloud usage is billed by your provider, directly to you.) Detailed plan tiers are landing soon; get in touch for early access and we'll size it to your volume.

Managed SFTP, without handing over your data.

Connect a bucket you already own and give anyone who needs it a clean SFTP endpoint in minutes — your files and your keys stay yours.

Get started