Managed SFTP for S3, Azure, Google Cloud & S3-compatible storage
Turn any cloud bucket into an SFTP server.
Give the people and systems that need it secure SFTP access to cloud storage you already have, in minutes. Connect an existing Amazon S3, Azure Blob, Google Cloud Storage, or S3-compatible bucket, create users, and they connect with ordinary SFTP. No server to run, no migration, no second copy of your files.
Free forever plan · bring your own bucket · no data migration · live in minutes
Least-privilege access you can revoke anytime. How it stays your data →
Supported storage
Sound familiar?
Most people reach for Firepipe to get out of one of these.
Still running an SFTP server
Another Linux box to patch, users and keys to rotate, firewall rules, backups, HA, and storage that keeps filling up.
AWS Transfer Family bills add up
An always-on endpoint charged by the hour, plus per-GB in and out, for what is really just an SFTP front door to your S3.
Your vendors only speak SFTP
Customers and downstream systems still insist on SFTP, but your data already lives in S3, Azure, Google Cloud, or S3-compatible storage.
Migrating means giving up your storage
Most hosted SFTP services want you to move your files onto their storage. You would rather keep your data exactly where it is.
Firepipe replaces the gateway and leaves everything else exactly where it is.
How it works
Three steps from an existing bucket to a fast, ready-to-use SFTP endpoint.
Connect your bucket
Point Firepipe at an existing S3, Azure Blob, Google Cloud Storage, or S3-compatible bucket (such as Cloudflare R2). On S3 you grant a scoped cross-account role, no keys to copy or store; on Azure, Google Cloud, or R2 you paste a scoped key you can revoke anytime. Nothing to migrate.
Create SFTP users
Issue per-user credentials, password or SSH key, each jailed to a single path prefix, for the people and systems that need access. Hand out the hostname and they connect.
They connect, files land in your bucket
Users and systems connect with any standard SFTP client. Every transfer streams straight to your bucket, and listings stay fast no matter how many files pile up.
Why Firepipe
Stop handing your files to another company
Files stay in a bucket you own, on your own cloud account. Firepipe streams each transfer through to your storage and keeps no lasting copy, with least-privilege access you can revoke on your own terms.
Keep your storage exactly where it is
No migration, no lock-in. Connect an existing bucket and replace just the SFTP gateway, everything else stays put. Leave whenever you like and your data has not moved an inch.
Pricing that does not punish scale
No per-operation or per-listing fees, just simple metered throughput. Listings stay instant even at millions of files, so big directories never cost you a slow, expensive surprise.
Your storage stays yours
Your files live in a bucket on your own cloud account, and that's the only place they're kept, Firepipe streams each transfer through to your storage and holds no lasting copy of your data. Access is least-privilege and revocable on your own terms: a cross-account IAM role on S3 with no long-lived keys for us to hold, or a scoped key on Azure, Google Cloud, or an S3-compatible store that you can cut off anytime. Revoke it and we're locked out, and your data hasn't moved an inch, because it was never anywhere else.
See and control every transfer
Run it in production with the visibility and control an audit team expects.
A full audit trail
Every login, upload, download, and delete is logged with the user, path, and timestamp. Filter by user, action, or date, and export the whole trail to CSV whenever you need it.
Per-user access you control
Issue credentials per user or system, each jailed to a single path prefix with its own quota. See who is connected and when they were last active, and revoke any of them instantly.
Live connection status
Watch each bucket connection go from initializing to ready at a glance, with a clear reason surfaced if anything needs your attention. Activity totals show logins and transfer volume over time.
Coming soon: trigger your own simple actions when a file arrives, no cloud-function plumbing to wire up.
How it compares
| Firepipe | AWS Transfer Family | Traditional SFTP server | |
|---|---|---|---|
| Managed SFTP onto your own cloud bucket | ✓ | ✓ | — |
| No always-on per-endpoint hourly fee | ✓ | — | ✓ |
| Nothing to provision, patch, or wire up (no servers, no IAM/VPC) | ✓ | — | — |
| Per-user path jails + full audit trail in one UI | ✓ | DIY | — |
| Instant listings even at millions of files | ✓ | — | — |
Comparison reflects each option's standard offering for the bring-your-own-bucket use case. Product names are trademarks of their respective owners.
Pricing
Fair, transparent, metered throughput, no per-operation or per-listing fees from us.
Free
- 5 GB / month transfer
- 5 SFTP users
- Full audit trail + CSV export
- No per-op or per-listing fees
Starter
- 25 GB / month included
- then $0.50 / GB
- Unlimited SFTP users
- 30-day audit history
Growth
- 250 GB / month included
- then $0.40 / GB
- Everything in Starter
- Lower per-GB rate as you scale
Early-access pricing, these starting tiers may change as we learn. Your own cloud usage is billed by your provider, directly to you. Need more than 250 GB/mo or committed volume? Talk to us .
Questions, answered
- Where are my files stored?
- In your own bucket, on your own cloud account, exactly where they are today. Firepipe streams every transfer through to your storage and keeps no lasting copy of your file contents.
- Which storage does Firepipe work with?
- Amazon S3, Azure Blob, Google Cloud Storage, and any S3-compatible store such as Cloudflare R2, Wasabi, Backblaze B2, or MinIO. If you are on a different S3-compatible endpoint it will almost certainly work, get in touch if you would like it confirmed.
- Do you support SSH keys?
- Yes. Each SFTP user can authenticate with a password or an SSH public key, and is jailed to a single path prefix in your bucket.
- Does Firepipe store a copy of my data?
- No lasting copy. Transfers stream through to your bucket, and nothing of yours is retained on our servers once a transfer completes, your data lives only in your own bucket.
- Do I have to migrate any data?
- No. You connect an existing bucket and replace only the SFTP gateway. Nothing moves, and there is nothing to import.
- What happens if I cancel?
- Your data is already in your own bucket, so there is nothing to extract. Cancelling simply removes our access, a cross-account role you delete, or a scoped key you revoke.
SFTP for your cloud storage, no server to run.
Connect a bucket you already own and give anyone who needs it a clean SFTP endpoint in minutes, your files and your keys stay yours.
Get started free