Theme
Site security
The Security page tunes the whole server your site runs on.
Dedicated plans only
These settings shape the server, not just your site, so they exist only where the server is yours alone. On a shared plan the hardened platform baseline protects every site on it, and this page explains that instead of offering controls.
To get these controls, see Moving to a dedicated server.
Tighten only
Every choice on this page makes your server stricter. Nothing here can make it weaker.
The platform baseline always applies underneath. If you set a value looser than the baseline, the baseline wins and your value is ignored. That is why there is no way to break your own server from this page.
Encryption
Post quantum key agreement is always on, on every plan. ML-KEM-768 combined with X25519 is offered on SFTP, FTPS and HTTPS whether or not you touch anything here.
Minimum TLS version
| Choice | Effect |
|---|---|
| TLS 1.2 | The platform baseline |
| TLS 1.3 only | Refuses TLS 1.2 |
Applies to FTPS and the web client. TLS 1.3 only may lock out very old FTPS clients. If you have automated partners on legacy FTPS libraries, test before you commit.
SFTP algorithm policy
| Choice | Effect |
|---|---|
| Safe | The platform baseline |
| Very safe | Post quantum or Curve25519 key agreement only, AEAD ciphers only, encrypt then MAC only, Ed25519 keys only |
Safe is not a weak setting. It already refuses every algorithm that is considered broken: SHA-1 key exchange and signatures, CBC and RC4 ciphers, SHA-1 message authentication. It also refuses the older finite field Diffie Hellman key agreement, which no current client needs and which is what a denial of service attack against an SFTP server spends your server's processor on. Your server signs its own identity with a single Ed25519 host key, and post quantum key agreement leads the list. Most SFTP clients written in the last decade connect under Safe without any configuration at all.
Very safe is the configuration Syncplify publishes as the ceiling for SSH-2. It is stricter in two ways that are worth knowing before you choose it.
Very safe accepts Ed25519 SSH keys only
Any transfer user whose registered public key is RSA is refused at sign in until they replace it with an Ed25519 key. Check your users before you switch, and give people time to generate a new key. Password sign in is unaffected.
Your server also presents its Ed25519 host key alone. A client that pinned a different host key needs the fingerprint from your site's settings page.
Some older SFTP clients cannot connect under Very safe at all. Test your automated partners first; it is a one click change back.
Session limits
Zero means the platform default applies.
| Setting | Effect |
|---|---|
| Max sessions, total | Across the whole server |
| Max sessions per address | Per client IP address |
| Idle timeout, minutes | Sessions with no activity are closed |
Transfer speed ceilings
Per session ceilings in KiB per second across the whole server. Zero means no ceiling.
Site and user caps can only be stricter than what you set here. The strictest applicable value always wins.
FTPS greeting
The first line your users see when they connect over FTPS, before signing in.
Clear the field to restore the standard greeting.
This is distinct from the per site FTPS messages on Site settings, which are shown after a sign in succeeds or fails.
Web client hardening
Block bots and unknown browsers
When on, requests from known bots and unrecognized clients are refused.
Download links keep working for scripts by design, so a scripted download of a share link is not affected.
Cross origin allowlist
Web pages on the origins you list may call your web client API from the browser.
Empty means no cross origin access, which is the safest setting. Only add an origin if you are embedding or driving the web client from your own web application.
Custom response headers
Extra headers added to every web client response.
The security baseline headers cannot be overridden. Anything you add is in addition to them.
Content Security Policy override
Replaces the default policy value. Leave empty for the platform policy, which fits the standard web client.
WARNING
An over length policy is refused, never trimmed and applied. A trimmed policy protects less than it looks like it does, so the page will not accept one. The counter beside the field shows how much room is left.
What is not on this page
| You want to | Go to |
|---|---|
| Decide which networks may connect at all | Site settings, Protection tab |
| Refuse countries | Site settings, Protection tab |
| Stop an address being banned, or lift a ban | Site settings, Protection tab |
| Set password rules for your users | Site settings, Policy tab |
| Refuse password sign in entirely | Site settings, Policy tab |
| Restrict one user to certain networks | Users |
| Control what a user may do to a file | Permissions |