The implementation of SFTPPlus, a Managed File Transfer (MFT) solution, typically follows a structured, modular approach that can be completed within a few days to one week, depending on deployment complexity:
Installation Begin by deploying the SFTPPlus server on your chosen platform (Windows, Linux, macOS, Docker, or Kubernetes). Installation packages are available for each environment, and setup is straightforward—simply install, register the service/daemon, and launch.
Initial Configuration On first start, SFTPPlus uses a sample text-based configuration. Admins can modify this directly or via the embedded web-based configuration tool (HTML5 interface). This includes defining protocol services (SFTP, FTPS, HTTPS, etc.), user accounts, authentication methods, and SSL/TLS certificates.
User & Authentication Setup Configure accounts and access credentials. SFTPPlus supports local OS authentication, LDAP, Active Directory, Azure AD, and OpenID Connect. Admins can implement home-folder chroot, group-based permissions, and secure certificate-based authentication.
Automation & Event Handling Define automated workflows: schedules, event-driven transfers, pre/post-processing calls to external programs, and file monitoring. Use event handlers to integrate with antivirus tools, archive files, or forward data.
Security & Compliance Configuration Import or generate SSL/TLS and SSH certificates via the web interface. Configure encryption/decryption workflows and ensure compliance with standards like FIPS‑140‑2, HIPAA/HITECH, ISO 27001, and GPG 13.
Testing & QA Conduct functional and security testing, leveraging logging and audit capabilities. Logs can be outputted to syslog, Windows Event Log, SQLite, or forwarded to SIEM tools.
High-Availability & Clustering (Optional) For redundancy, configure active-active or active-passive clusters across VMs, containers, or Kubernetes. The sync cluster ensures automatic propagation of configuration changes.
Production Rollout Switch from trial to production license. Deploy non-production (staging) instances under the support contract. Begin live transfers, monitor, and tune performance.
Estimated Timeframe:
A basic, single-instance deployment with core protocols, user setup, and automation typically takes 1–3 days.
Advanced deployments involving clustering, external authentication, and complex workflows may require 1–2 weeks, depending on infrastructure and regulatory integration.
Customisation
SFTPPlus is highly customizable, enabling organizations to tailor the solution to specific business workflows and requirements:
Flexible Configuration: Administrators can configure everything via text files or through the web-based HTML5 console, supporting both scripted and interactive approaches.
Modular Architecture: Services—such as SFTP, FTPS, HTTPS, WebDAV, and SMTP—are enabled or disabled per port, allowing granular control of protocol exposure.
Authentication Options: Supports local OS accounts, LDAP, Active Directory, Azure AD, OpenID Connect, SSH keys, and X.509 certificates, giving flexibility in securing access.
Event Handlers & Workflows: Customize automation with pre/post-transfer script execution, directory monitoring, alerts, and integrations such as antivirus scanning or archival.
Matching Expressions: Use regular expressions and glob patterns to define file filters and routing logic tailored to business criteria.
API & SDK Access: A public HTTP(S) API and SDK allow deep integration with existing business applications, enabling custom dashboards, notification systems, or logging workflows.
Clustering and HA: Design custom high-availability schemes with active-active or active-passive modes, load-balancers, VM/container orchestration, and disaster-recovery planning.
Certificate Automation: Auto-manage SSL/TLS certs via Let’s Encrypt, reducing overhead for admins and ensuring secure operations.
Logging & Alerting Customization: Logs are formatted for syslog, Windows EventLog, SQLite, or HTTP POST, and rules can trigger alerts, enabling tailored auditing or SIEM integration.
Cloud Integration: Supports connections to Azure Blob/Files, SharePoint, Exchange Online, SMB, and more, and can be customized to work with cloud storage or email workflows.
Platform Agnostic Deployment: Run as a standalone service, in containers, or on-prem-cloud hybrids. You can tailor deployment to organizational policy or infrastructure preferences.
Additional Costs
SFTPPlus operates on a perpetual license basis, with the license including free upgrades and a non-production (pre-production) license for testing environments.
High-availability configurations (up to two active server or client instances in a cluster) cost 60% of a single license per extra replica.
Technical support and maintenance—covering updates, patches (both major and minor), phone/email assistance, and two annual out-of-hours support events—costs 20% of the current license price as a yearly subscription.
Optional consultancy services for design, implementation, documentation, monitoring, and deployment are offered in 20-hour blocks, priced at approximately £2,000 GBP / $2,400 USD / €2,300 EUR.
No mandatory setup or installation fees are required, and initial consultancy is often provided free of charge, based on the vendor's specifics.
Training
Pro:Atria provides comprehensive support and training services for SFTPPlus users:
Email support is the primary channel, with responses archived for future reference.
Phone support is available weekdays (09:00–17:00 UK time) via their UK office, plus two annual out-of-hours support events.
They offer specialized consultancy and training, including both remote (conference calls, GoToMeeting, Zoom, Webex) and on-site sessions for configuration, implementation, or best-practices training, billed separately from standard support.
Pre-licensing consultancy is typically free, with formal consultancy costs agreed in advance.
Support includes maintenance, critical/security patches, and the ability to request new functionalities for inclusion in future releases.
An extensive security advisories newsletter is available, providing updates and best practices; older advisories are archived publicly after three months.
Security Measures
SFTPPlus incorporates robust security protocols and practices to safeguard data:
Supports multiple secure transfer protocols: SFTP, FTPS (explicit/implicit), HTTPS, SCP, AS2, and WebDAV over HTTPS.
Fully compliant with FIPS 140‑2, HIPAA/HITECH, ISO 27001, and GPG 13 standards.
Centralized SSL/TLS X.509 certificate management and AES encryption/decryption workflows protect data both in transit and at rest.
Supports strong authentication methods, including OS-level credentials, LDAP, Active Directory, Azure AD/Entra ID, OpenID Connect, SSH key pairing, and X.509 certificates.
Structured audit logging is available via syslog, Windows Event Log, or local SQLite databases, enabling secure and searchable logs for compliance.
DMZ-appropriate architecture with user locking controls ensures secure deployments in network-segregated environments.
The vendor provides a security advisories newsletter, timely patches, and long-term updates as part of standard maintenance.
All software versions undergo automated regression testing across supported platforms, with over 32,000 tests executed before release.
These detailed findings offer a clear view of SFTPPlus’s cost structure, support services, and robust security framework, with citations for each claim.
Updates
SFTPPlus follows a regular manual release schedule that includes both minor versions and patch releases. Minor feature updates—such as version 5.17.0—are typically released every 1–2 months, with the latest version (5.17.0) dated 11 September 2025 and a patch version (5.16.1) on 5 September 2025. New releases are documented through public release notes and product news postings. Administrators manage updates via downloads of installation packages suited to their OS or container environments. These updates are applied manually or scripted through automation tools. The software supports rollback by preserving previous configurations, and all update builds undergo rigorous automated regression testing to assure compatibility and stability.
Data Ownership and Portability
SFTPPlus is deployed as self-managed software, entirely hosted within customer environments, and the vendor does not claim ownership of any user data. Configuration resides in text files and optionally SQLite databases, which administrators can export, version, migrate, or replicate between environments freely. License terms support transferability—meaning one license can be moved across platforms (e.g., Windows to Linux) or deployments (on-premises to cloud) at no additional cost, and include a free non-production license to support staging and testing efforts. Consequently, organizations retain full control over all data, logs, and configurations.
Scaling Up / Down
SFTPPlus offers flexible scaling options to match organizational growth or contraction. For high-availability deployments, up to two active server or client instances can operate in a cluster behind a load balancer or within container orchestration platforms (e.g., Kubernetes, EKS, GKE, OpenShift). Each additional replica beyond the first is licensed at 60% of the single-instance cost. Configurations are automatically synchronized from a primary instance to secondary nodes. Advanced clustering in Kubernetes supports auto-scaling through replica sets, and comes with a free license for a dedicated cluster controller. Extra scaling—such as more than two instances or regional distribution—is available via custom engagement with the vendor. Licenses allow role changes or environment migration without extra fees, enabling seamless scaling up or down as business demands evolve.
Compliance
SFTPPlus is designed to meet rigorous industry and regulatory compliance standards, making it suitable for highly regulated sectors:
FIPS 140‑2, ensuring cryptographic module security.
HIPAA/HITECH, supporting HIPAA-compliant data handling with detailed audit logs and secure protocols.
ISO 27001, guarantees an information security management framework.
GPG 13, aligning with UK government's secure information practices.
Additionally, it supports secure transfer protocols such as SFTP, FTPS, HTTPS, SCP, AS2, and WebDAV over HTTPS—all providing encryption in transit and optional encryption at rest, fulfilling key compliance controls available through its administrative and logging features.
These certifications and technological safeguards enable organizations to implement SFTPPlus in environments requiring adherence to stringent security and privacy requirements.