Managed SFTP / FTPS for Amazon S3 & S3-compatible storage
Fully managed SFTP for your own cloud storage.
Put a fully managed SFTP/FTPS endpoint in front of an existing Amazon S3 bucket — or any S3-compatible store like Cloudflare R2 — in minutes. The people and systems that need it get standard SFTP access; your files stay in your own bucket, on your own cloud account.
No migration, no lock-in. On S3 we connect through a cross-account role you control and store no keys at all; on R2 and other S3-compatible stores, access is a scoped key you can revoke anytime, encrypted at rest. Either way, your files stay yours.
Bring your own bucket · no data migration · live in minutes
Why Firepipe
Your bucket, your data
Files stay in your own bucket — Amazon S3 today, or any S3-compatible store like Cloudflare R2 — nothing to migrate, no lock-in. We connect with least-privilege access and never store your file contents, so your data never lands on our infrastructure. (Azure Blob and Google Cloud Storage are on the way.)
On S3, no keys to leak
Connect an Amazon S3 bucket through a cross-account role you grant and revoke at will — Firepipe stores no access keys at all, so there is nothing on our side to leak or lose. For Cloudflare R2 and other S3-compatible stores, access is a scoped key you can revoke anytime, encrypted at rest (AES-256-GCM).
No surprise fees
Fair, transparent pricing. Firepipe never charges per operation or per listing — you pay for simple metered throughput, and nothing else. (Your own cloud usage is billed by your provider, directly to you.)
Your data never touches our servers
Files stay in a bucket you own, on your own cloud account. Firepipe streams every transfer straight through to your storage — we never copy your files out and never store them. Your file contents never live on our infrastructure.
Access is least-privilege and revocable on your own terms. On S3 that's a cross-account role with no keys for us to hold at all; on R2 and other S3-compatible stores it's a scoped key, encrypted at rest, that you revoke whenever you like. Either way, cutting us off is a change on your side — and your data is already exactly where it has always been.
How it works
Three steps from an existing bucket to a fast, ready-to-use SFTP endpoint.
Connect your bucket
Point Firepipe at an existing S3 or S3-compatible bucket (such as Cloudflare R2). For S3, grant a scoped cross-account role — no keys to copy; for R2, paste a scoped access key. No data to migrate either way.
Create SFTP users
Issue per-user SFTP credentials (password or SSH key), each jailed to one path prefix — for people or automated systems. Hand out the hostname and a static IP.
Files flow, listings stay instant
Users and systems upload and download over SFTP/FTPS straight to your bucket. A synced index keeps every `ls` fast, no matter how many files pile up.
See and control every transfer
Run it in production with the visibility and control an audit team expects.
A full audit trail
Every login, upload, download, and delete is logged with the user, path, and timestamp. Filter by user, action, or date, and export the whole trail to CSV whenever you need it.
Per-user access you control
Issue credentials per user or system, each jailed to a single path prefix with its own quota. See who is connected and when they were last active — and revoke any of them instantly.
Live connection status
Watch each bucket connection go from initializing to ready at a glance, with a clear reason surfaced if anything needs your attention. Activity totals show logins and transfer volume over time.
Coming soon: trigger your own simple actions when a file arrives — no cloud-function plumbing to wire up.
How it compares
| Firepipe | Other SFTP gateways | All-in-one platforms | |
|---|---|---|---|
| Files stay in your own bucket | ✓ | ✓ | — |
| Instant listings at millions of files | ✓ | — | — |
| No per-operation / per-listing fees from us | ✓ | — | ✓ |
Comparison reflects each product's standard offering for the bring-your-own-bucket use case.
Pricing
Fair and transparent: simple metered throughput, with no per-operation or per-listing fees from us and a static IP for firewall allowlists included as standard. (Your own cloud usage is billed by your provider, directly to you.) Detailed plan tiers are landing soon; get in touch for early access and we'll size it to your volume.
Managed SFTP, without handing over your data.
Connect a bucket you already own and give anyone who needs it a clean SFTP endpoint in minutes — your files and your keys stay yours.
Get started