Theme
How the pieces fit together
Three pieces, and only one of them is yours to run.
The pieces
The Portal is where you manage your account. You sign in at the Portal to create sites, create users, pick a plan and see your invoices. The Portal never touches a file.
Your site is the transfer server. It answers SFTP on port 22, FTPS on 990, FTPES on 21, and the web client on 443, at an address such as acme.on.sftp.cloud. It checks who is signing in. It does not store files.
Your Storage Connector runs on a machine you own, next to your storage. It reaches the actual files, and it decides what each user may do to them.
Who connects to whom
Every arrow points the same way: from the less trusted side toward the more trusted side. Your Connector dials out to your site. Your site dials out to the Portal. Nothing ever dials in.
The division of labor follows the same line: your site (the cloud) holds the accounts, and the Connector (your machine) decides who may reach which storage. A grant made on the Connector is also what gives a user their home folder, unless you set an explicit layout per user in the Portal.
That is why the Connector needs no public IP address, no inbound firewall rule, and no DNS name. It needs to be able to make an outbound connection, and that is all.
What happens when somebody transfers a file
A user connects to
acme.on.sftp.cloudwith an SFTP client, an FTPS client or a browser.Your site checks who they are. It looks up the username, checks the password or the SSH key, and, in the browser only, asks for the second factor if one is enrolled. This happens entirely on your site. Your Connector is not involved yet.
Your site asks your Connector to open a session. It presents two signed documents: an identity record signed by the Portal, which says who this user is, and a session voucher signed by the site itself, which says this particular sign in just happened.
Your Connector checks both signatures. It verifies the Portal signature against a key built into the Connector software itself, which it obtained without your site's help when it enrolled. It then checks that the two documents agree about the user, and that the session voucher is fresh and has not been used before.
Your Connector decides what the user may do. It looks up its own local grant for that user: which folders they see, and what they may do inside each one. If the Connector holds no grant for that user, the session is refused. There is no default access.
Every file operation is checked again. Each open, read, write, rename and delete is checked against that user's permissions at the moment it happens, on the Connector, before the operation touches the disk.
Every operation is recorded, allowed or refused, into a signed log the Connector keeps locally. See Tamper evidence.
Why authentication and authorization are split
Your site proves who somebody is. Your Connector decides what they may do.
The practical consequence: control of your site is not control of your files. The permissions do not live there. They live on the machine you own, and the Connector will not act on an instruction that is not signed by a key it already trusts.
The other practical consequence, worth knowing before you start: the two halves are configured in two different places. You create users and choose which folders they see in the Portal. The Connector administrator decides what those users may do inside those folders, in the Connector's own admin console. See Users and Permissions.
Shared and dedicated
Your site runs either on a shared server or on a server of its own.
| Shared | Dedicated | |
|---|---|---|
| The server | Runs several customers' sites | Runs only yours |
| SSH host key | Shared with the other sites on that server | Yours alone |
Short usernames such as alice | Not available; the full alice@acme is required | Available when the name is unique on the server |
| Server wide security tuning | Platform baseline | Yours to tighten, on the Security page |
| FTPS goodbye message | Standard wording | Yours |
Sites of the same customer share nothing on the transfer path. Two sites of yours are two separate systems that happen to appear on one invoice.
Moving from shared to dedicated is a supported, guided operation. See Moving to a dedicated server.
What is stored where
| Thing | Lives on |
|---|---|
| Your files | Your storage, reached by your Connector |
| Your file permissions | Your Connector |
| Your at rest encryption keys, if you use them | Your Connector, never leaving your premises |
| Your usernames, passwords, SSH keys and second factors | Your site |
| Your account, plan, invoices and audit trail | The Portal |