Secure File Transfer Protocol moves files between computers using encryption so nobody in the middle can read them

Secure File Transfer Protocol, or SFTP, is a way to move files from one computer to another over the internet while keeping them encrypted the whole time. Think of it like sending a locked box through the mail instead of a postcard — the mail carrier can see the box is there, but cannot open it or read what is inside.

SFTP is different from the older, unencrypted FTP (File Transfer Protocol), which sends files in plain text. If someone intercepts an FTP transfer, they can read the files and see the password used to log in. SFTP scrambles both the files and the login information, so even if someone captures the data moving across the network, they cannot decode it without the encryption key.

Most people encounter SFTP when uploading files to a website, backing up data to a server, or moving large files between work computers. It is also common in business settings where sensitive documents need to move between offices or to cloud storage.

Key Takeaways

  • SFTP encrypts files and login credentials during transfer, so intercepted data cannot be read without the encryption key.
  • You access SFTP through a dedicated client program on your computer, not through a web browser like you would use for regular file downloads.
  • SFTP requires a username and password, and many services add an extra security layer by requiring a special key file in addition to the password.
  • The main risk with SFTP is weak passwords or reused passwords, which can let someone log in even though the transfer itself is encrypted.

How SFTP differs from other file transfer methods

Regular HTTP and HTTPS file downloads (the kind you do in a web browser) send files over an encrypted connection, but they are designed for one-way downloads, not for uploading or managing files on a server. SFTP, by contrast, lets you upload, download, delete, and rename files on a remote computer as if you were working with folders on your own machine.

Email attachments are encrypted in transit if you use a service like Gmail or Outlook, but they are not encrypted on the email server itself, and they create a copy of the file in your inbox and the recipient's inbox. SFTP keeps files on the server and does not create extra copies unless you explicitly download them.

Cloud storage services like Google Drive or Dropbox also encrypt files in transit and at rest, but they are designed for sharing and collaboration. SFTP is simpler and faster for moving large files between specific computers without the overhead of a full cloud service.

What you need to use SFTP

You cannot use SFTP through a regular web browser. Instead, you need an SFTP client — a program that runs on your computer and knows how to speak the SFTP language. Common SFTP clients include FileZilla (free and available for Windows, Mac, and Linux), WinSCP (Windows only), and Cyberduck (Mac and Windows). Many web hosting companies also provide their own SFTP client or a built-in tool in their control panel.

To connect, you will need the server address (usually something like sftp.example.com), a username, and a password. Some servers also require an SSH key — a special file that acts as a second form of identification. The server generates this key, and you save it on your computer. Even if someone steals your password, they cannot log in without the key file.

Once you have the client installed and the connection details, you open the client, enter the server address and login information, and you see the remote server's folders appear in a window on your screen. You can then drag files between your computer and the server, or right-click to upload, download, or delete files.

The encryption that protects your files

SFTP uses a combination of two types of encryption. The first, called asymmetric encryption, establishes a secure connection between your computer and the server using public and private keys. This is the same technology that protects your bank website. Once that secure tunnel is open, the second type, called symmetric encryption, scrambles the actual files and login information moving through the tunnel.

The result is that even if someone on your network or your internet provider captures the data, they see only random characters. Decoding it would require either the encryption key (which only your computer and the server have) or so much computing power that it would take longer than the files are useful.

This encryption happens automatically — you do not have to do anything special. As long as you are using SFTP (not the older FTP), the protection is there.

Real risks with SFTP

The encryption itself is strong, but the weakest point is usually the password. If you use a password that is easy to guess (like your name or "password123"), or if you reuse the same password across multiple services, someone who cracks it can log in to your account and access or delete your files. The encryption does not protect against someone who has the correct login credentials.

A second risk is man-in-the-middle attacks, where someone tricks your computer into connecting to a fake server that looks like the real one. This is rare but possible if you are on an unsecured public WiFi network. The protection here is to check the server's fingerprint — a unique identifier that your SFTP client can verify — before connecting for the first time.

A third risk is that SFTP only protects the transfer itself. Once files land on the server, they are only as secure as the server's own security. If the server is hacked or poorly maintained, your files could be exposed even though they arrived encrypted.

When to use SFTP instead of other methods

Use SFTP when you need to move files larger than email allows, when you need to manage files on a remote server (upload, delete, or organize them), or when the files contain sensitive information that should not sit in an email inbox or cloud service. It is common for web developers uploading code to a hosting server, for accountants moving financial documents between offices, and for researchers transferring large datasets.

Do not use SFTP if you just need to send a file to someone once — email or a file-sharing link is simpler. Do not use it if you need multiple people to collaborate on the same file at the same time — cloud storage is better for that. SFTP is best for point-to-point transfers where you control both ends of the connection.

Setting up SFTP securely

If you are setting up SFTP for the first time, start by creating a strong password — at least 12 characters, mixing uppercase and lowercase letters, numbers, and symbols. Do not reuse a password from another service. Write it down in a password manager like Bitwarden or 1Password, not in a text file on your desktop.

If the server offers SSH keys, use them. They are more secure than passwords alone because even if someone learns your password, they still cannot log in without the key file. Ask your server administrator or hosting company how to generate and install a key.

Before you connect for the first time, ask your server administrator for the server's SSH fingerprint — a string of characters that uniquely identifies the server. When your SFTP client first connects, it will show you the fingerprint and ask if you trust it. Verify that it matches what the administrator gave you. This prevents you from accidentally connecting to an imposter server.

Frequently Asked Questions

Is SFTP the same as SSH?

No. SSH (Secure Shell) is the underlying protocol that creates the secure tunnel. SFTP is a file transfer service that runs inside that tunnel. You could think of SSH as the secure road and SFTP as the delivery truck that uses that road. Most SFTP connections use SSH, so the terms are sometimes used together, but they are not the same thing.

Can I use SFTP on my phone?

Yes, but it is less common. Android has several SFTP apps like Termius and FTP Disc. iPhone has fewer options, but Yoink and a few others support SFTP. Phone apps work the same way as desktop clients — you enter the server address and login information, then browse and transfer files. However, most people use SFTP on a computer because the larger screen makes it easier to manage files.

What happens if I forget my SFTP password?

You will need to contact your server administrator or hosting company to reset it. They can issue a new password or help you set up SSH key authentication instead. This is why storing your password in a password manager is important — you can retrieve it without contacting anyone.

Does SFTP work if my internet connection drops?

No, the transfer will stop. Some SFTP clients have a resume feature that lets you pick up where you left off, but not all of them. For very large files or unreliable connections, consider splitting the file into smaller pieces or using a service designed for resumable transfers.

Can someone see my files if they are on the same WiFi network as me?

Not if you are using SFTP. The encryption protects the files from anyone on the network. However, they could still see that you are connecting to a server and roughly how much data you are transferring. If you want to hide even that information, you would need a VPN in addition to SFTP.