Theme
Glossary
Every term SFTP.cloud uses, defined once. Terms are linked from the rest of the documentation, so you can arrive here from wherever the word confused you.
A
Activity
The record of what happened. There are two separate activity logs and they show different things. The Portal activity log records account events: sign ins, user creation, plan changes, support access. The Connector activity log records file operations: who opened what, and whether it was allowed. See Activity and Connector activity.
Address
Your site's name on the internet. Every site has a platform address made of your site name and a domain, for example acme.on.sftp.cloud. This address always works and is where SFTP and FTPS clients connect. You can add your own custom domain on top of it, but only for the web client. See Site settings.
Admin
One of the three Portal roles. An admin can do everything: sites, users, billing, the team and support access. Every account must keep at least one admin. See Your team and their roles.
Accounting
One of the three Portal roles. An accounting member handles the money: buying sites, plans, payment details and invoices. They cannot configure a site. See Your team and their roles.
Authenticator app
An app on your phone or computer that generates a six digit code that changes every thirty seconds, such as Google Authenticator, Microsoft Authenticator, 1Password or Bitwarden. SFTP.cloud requires one on every Portal account. Also called TOTP.
App password
A separate sign in credential for desktop clients and scripts, created by a user in the web client, shown once, protocol scoped, optionally expiring, and revocable on its own. Never opens the web client. See App passwords.
Automatic home folders
The default for a user's folder layout: whatever storage the Connector administrators grant becomes their home, the first granted storage as the starting folder and further ones as folders inside it. The alternative is an explicit custom map per user. See Users.
B
Ban
A temporary refusal of one IP address, applied after that address collects enough strikes against your site. Bans are listed on your site's Security settings. See Site security.
C
Be right back
A pause you switch on for one site: every sign in refused, an away page in your branding, Connectors still linked, scripted transfers still running, billing and service level unchanged. See Be right back.
CIDR
A way of writing a range of IP addresses, for example 198.51.100.0/24, which covers 198.51.100.0 through 198.51.100.255. Used wherever the product asks for networks rather than single addresses.
Commitment
A short signed summary of what your Connector's operation log contained at a moment in time, sent to the Portal and recorded there. Once a commitment is recorded, the log up to that point cannot be rewritten without the difference being provable. See Tamper evidence.
Connector
Short for Storage Connector. Software you install on a machine you own, next to your storage. It holds the connection to your storage, decides what each user may do, and performs the actual reads and writes. It dials out to your site and never accepts an inbound connection. See What the Connector is.
Custom domain
Your own domain name, such as files.yourcompany.com, pointed at your site. Custom domains serve the web client only. SFTP and FTPS always use the platform address. See Site settings.
D
Dedicated
A plan tier where the server running your site runs nothing else. A dedicated site gets its own SSH host key, its own server wide security settings, its own FTPS goodbye message, and short usernames. The opposite is shared. See Moving to a dedicated server.
Drop box
A share, or a permission level, where somebody can add files without being able to see what is already there. See Sharing files and Permissions.
E
Encryption at rest
Encrypting the files a virtual file system holds, so that reading the raw disk or the raw bucket yields ciphertext. The key is derived from a passphrase and never leaves your Connector. Syncplify never holds it and cannot recover it. The choice is permanent per virtual file system. See Encryption at rest.
Enrollment code
A single use code, minted in the Portal, that binds one Connector to one site. It is shown once, it expires, and it works one time. See Connect your storage.
Event handler
A rule on your Connector that runs a script when something happens, for example after a file is uploaded. See Event handlers.
Evidence
The signed, tamper evident record of what your machines did. See Tamper evidence.
F
Folder set
A named group of folders on your Connector, with a default permission level for each, that you grant to a user in one step. Useful when several users need the same access. See Folder sets.
Federated user
A user who signs in to the web client through their organization's identity provider rather than with a password held here. Matched by verified email on their first sign in, linked by the provider's stable subject from then on. See Sign in with your identity provider.
FTPS
FTP over TLS, on port 990. The TLS handshake happens first, before any FTP command. Sometimes called implicit FTPS.
FTPES
FTP over TLS, on port 21. The connection starts as plain FTP and is upgraded to TLS with the AUTH TLS command before credentials are sent. Sometimes called explicit FTPS. Plain, unencrypted FTP is never offered.
H
Head
The internal name for the server that runs your site: the thing that answers SFTP, FTPS and HTTPS and checks who is signing in. The Portal calls it your site or your server. The Connector's admin console uses the word Head when it reports what it is connected to.
Host key
See SSH host key.
I
Identity provider
Your organization's sign in system (Microsoft Entra ID, Google Workspace, Okta, or any OpenID Connect provider), which a site can be connected to so your people sign in with the account they already have. See Sign in with your identity provider.
Idle timeout
How long a session with no activity stays open before it is closed. Set per site, and never longer than the platform value. See Site settings.
L
Log integrity
Whether your Connector's operation log is intact and whether anybody outside that machine is holding a copy of its position. Two separate questions, reported separately. See Log integrity.
M
Mount
One row in a user's What they see list: a path the user sees after signing in, such as / or /reports, mapped onto one virtual file system on one Connector. Exactly one mount must be at /. See Users.
P
Passkey
A credential stored on your device that signs you in with the device's own unlock: fingerprint, face, PIN or a hardware security key. It cannot be phished and needs no code. Available on Portal accounts and on web client accounts.
Permission level
A named bundle of abilities a user has inside one folder on a Connector: View and download, Upload only, Drop box, Full access, Everything, or Custom. See Permissions.
Plan
What a site runs on commercially: how many user accounts and storage connectors it includes, what it costs, and whether it is on the shared or the dedicated tier. See Plan and billing.
Platform address
See Address.
Portal
The management console at https://portal.sftp.cloud, where you sign in to run your account: sites, users, storage, plans, billing and your team. The Portal never touches a file.
R
Recovery code
A single use code that signs you in when you have lost your authenticator. A set is issued when you enroll an authenticator, shown once, and never shown again. Each code works once.
Region
Where your site's server physically runs. Chosen when the site is created and permanent afterwards.
Re-enrollment
Binding an existing Connector to your site again, with a fresh single use code, after something broke the original binding. See Enroll to your site.
S
Seat
One active user account on your site, counted against the number your plan includes. Disabling a user frees their seat immediately; disabled users cost nothing.
Service credit
Account credit applied automatically when a calendar month falls below the uptime we commit to. Credits come off your next invoice. They are not cash refunds, and there is nothing to claim. See Service level.
Share
A link one of your users creates so somebody without an account can download files, or upload them, or both. Shares can carry a password, an expiry date, an access limit and an address restriction. See Sharing files.
Shared
A plan tier where the server running your site also runs other customers' sites. Sites on a shared server are fully isolated from each other, but they share the server's SSH host key and its server wide settings. The opposite is dedicated.
Site
Your deployment: one address, one set of users, one set of connectors, one plan. Most customers have exactly one. Two sites of yours share nothing on the transfer path; they are two separate systems on one invoice.
Site name
The short name you choose when creating a site, which becomes the first part of its address and the part after the @ in every username on it. Lowercase letters, digits and dashes, 3 to 30 characters. Permanent once chosen. Also called the slug.
SSH host key
The key your site presents to prove it is itself, before any username is sent. Your SFTP client records it the first time and warns you if it ever changes. The fingerprint is on your site's Settings, under Advanced. On a shared server it is the server's key, shared with the other sites on it; on a dedicated server it is yours alone.
SSH key pair
A private key you keep and a public key you hand out. The public key goes on your account in the Portal; the private key stays with you. Signing in with a key is stronger than a password and is the recommended way to use SFTP. See Use an SSH key.
Storage Connector
See Connector.
Strike
A mark against one IP address for misbehaving, for example repeated failed sign ins. Enough strikes produce a ban.
Subscription
The live contract for one site: its plan, its billing period, how many accounts and connectors it carries, and what state it is in. One per site. See Plan and billing.
Support grant
Your explicit, time limited consent for Syncplify support to see your account. Without one, support sees only aggregate metadata. Everything they open while a grant is active is recorded in your activity log. See Getting help.
T
Tech
One of the three Portal roles. A tech member configures sites, users, connectors and settings, and can never spend money. See Your team and their roles.
TOTP
Time based one time password, the six digit code an authenticator app produces.
Transfer user
An account one of your people, or an automated system, signs in with to transfer files. Distinct from a team member, who signs in to the Portal to manage the account. Created in the Portal, on your site's Users page.
Team member
A person who signs into the Portal to manage your account, with the admin, accounting or tech role. Distinct from a transfer user, who signs into your site to move files. See Your team and their roles.
Trial
A free period on your first site, with everything enabled and nothing charged. A saved card is required to start it. See Plan and billing.
Trusted device
A browser you have told SFTP.cloud to trust, so it stops asking for the six digit code for a set number of days. Revoking trusted devices makes every one of them ask again.
U
Uptime commitment
The percentage of each calendar month your site's services are expected to be available. Measured every month, published every month, and credited automatically when missed. See Service level.
V
Virtual file system
A named piece of storage on your Connector: a disk path, an S3 bucket, an Azure container, a Google Cloud bucket or another SFTP server. Users are given access to virtual file systems by name, and mounted onto them in the Portal. Often shortened to VFS. See Virtual file systems.
W
Web client
The file transfer interface your users reach in a browser at your site's address. It carries your branding, not ours. See Sign in to the web client.
Z
Zone
Which domain your site's address lives in, when more than one is offered. Chosen when the site is created and permanent afterwards. The Portal calls it Domain in the site creation wizard.