YOUR VPC. YOUR DATA. SAME CONSOLE.

SFTP and FTP/S in your VPC

Connected directly to your own S3, GCS and Azure blob backends.
You can also connect to S3 compatible services like Cloudflare R2, IBM COS, Backblaze B2, NetApp StorageGRID, Ceph, Cloudian HyperStore, Wasabi, MinIO and more.
On AWS? You can also deploy the server straight from the AWS Marketplace — billed hourly through AWS, with no license to manage.
Golang

A single binary

Get started in minutes with a single binary installation, available on Mac, Windows and Linux
User interface

Manage your instances

Manage your instances through our UI. View our administrator guide to learn more about running in production.
Free trial

Get started!

Generate your trial license key immediately, and start your instance on your local computer. View the getting started guide.

Highly available

Run as few or as many instances that you require. Automatically manage your cluster from our hybrid cloud. No database required.

Your SSL certificates

Encrypt all traffic sent and received using your own SSL certificate for FTPS, and your own RSA key for SSH SFTP encryption.

Hybrid cloud

We manage the user interface, you manage the instance. Move your workload from your VPC to the Cloud and back again anytime.
SFTP FOR HEALTHCARE

HIPAA-ready file transfer, inside your own network

Hospitals, labs, payers and health-tech vendors exchange claims, HL7 and imaging files over SFTP every day. The self-hosted server meets the requirements of the HIPAA Security Rule for transferring protected health information - and because it runs in your VPC and writes to your bucket, the PHI is never ours to protect.
PHI never leaves your VPC
Files move from the client straight into your own S3, Azure or GCS bucket. The DocEvent console holds configuration only - it never receives, stores or processes a single byte of patient data, so there is no PHI in our hands for a Business Associate Agreement to cover.
Encrypted in transit and at rest
SFTP and FTPS on every connection, with plaintext FTP switched off per service. At rest, files sit in your bucket under your provider's server-side encryption and your own KMS keys.
Least-privilege access
Per-user home directories, read-only users, quotas, SSH-key-only login and an IP allow / deny firewall on every service. Disable a user and their access ends on the next connection.
An audit trail you own
Every login, upload, download and delete is written as a JSON transaction entry on your host - user, source IP, path, bytes, session. Ship it to CloudWatch, Splunk or your SIEM and retain it for the six years the Security Rule asks for.
You remain the covered entity or business associate. DocEvent provides the technical safeguards; your policies, training and risk analysis complete the programme.
SFTP FOR REGULATORY COMPLIANCE

Built for audited environments

Encryption on every connection, least-privilege users, a complete activity log and a footprint that stays in your cloud account. Whichever framework your auditor holds you to, the controls are already there.

PCI DSS

Cardholder data in transit and at rest, under your controls.
  • Req. 4 - strong cryptography on open networks: SFTP and FTPS only, plaintext FTP refused
  • Req. 1 - runs inside your VPC behind your own security groups, plus a per-service IP allow / deny list
  • Req. 7 & 8 - unique user IDs, per-user directories, read-only users, SSH key authentication
  • Req. 10 - every access and file operation logged with user, source IP, path and timestamp

HIPAA

Meets the technical safeguards of the Security Rule for file transfer.
  • Transmission security - encrypted SFTP / FTPS on every connection
  • Access control - unique users, least-privilege directories, key-based login
  • Audit controls - a complete activity log kept on your infrastructure
  • Files and logs stay in your VPC - DocEvent never handles PHI

FIPS 140

Modern cryptography, with validated modules where they matter.
  • FTPS negotiates TLS 1.2 or newer; SFTP uses current SSH key exchange and ciphers, with no legacy algorithms
  • Bring your own TLS certificate and SSH host key
  • Encryption at rest is performed by your cloud provider's FIPS 140-validated storage and KMS services
  • Need a build on the FIPS 140-3 validated Go Cryptographic Module for a government workload? Talk to us

GDPR

Data residency and minimisation by design.
  • Personal data stays in the region and bucket you choose - files never transit DocEvent infrastructure
  • Retention and erasure are enforced by your bucket's lifecycle rules, not by us
  • The console stores only account and configuration metadata, covered by our Data Processing Agreement
  • Access logs identify who touched which file and when, supporting subject-access and breach-notification duties
Software is one control in a compliance programme, not a certificate. Read our security information for the platform-wide picture.

Self-Hosted pricing

Choose an annual plan or one-time perpetual license.
Free 7 day trial

Business

$1,980
per year
40 simultaneous connections
  • Complete control of your environment
  • Active-active clustering
  • Annual license
  • Included maintenance
  • SFTP + FTP + FTPS
  • Any backend (S3/Azure/GCS)
  • Security whitelist / blacklist
  • SSH key authentication
  • Unlimited data transfer
  • Unlimited operations
  • High availability cluster (per node license)
  • Ongoing support and maintenance
Best value

Data Center

$4,940
per year
Unlimited simultaneous connections
  • Complete control of your environment
  • Active-active clustering
  • Annual license
  • Included maintenance
  • SFTP + FTP + FTPS
  • Any backend (S3/Azure/GCS)
  • Security whitelist / blacklist
  • SSH key authentication
  • Unlimited data transfer
  • Unlimited operations
  • Unlimited high availability cluster
  • Ongoing support and maintenance

You focus on integration,
we'll focus on delivery.

Get started for free