SAS 70 / SSAE 16 Audited Data Center

FTP Today’s data center is one of the first to be Type II SOC 1 audited, assuring you rock solid protection.

The audit was performed under the Statement of Standards for Attestation Engagements Number 16 (SSAE 16) standard. SSAE 16 is the successor to the SAS 70 standard which will be ending in 2011.

SSAE16 Audited

In cases where data is regulated and/or sensitive (HIPAA, HITECH, PCI, SOX, GLBA, etc.) it is important for hosting organizations to have detailed and well documented controls in place to ensure the safety and privacy of the data being stored and transmitted. A SAS 70 / SSAE 16 examination signifies that a service organization has had its control objectives and activities examined by an independent auditing firm.
Read More

Hardware Firewalls

At FTP Today, every FTP server is behind a set of high availabilty firewalls. Should either device fail, uninterrupted traffic is automatically handled by the other firewall. Our firewalls provide accelerated security throughput at up to line speed on our network (1 gigabit per second) and can handle up to 400,000 concurrent sessions!

FTP Today’s expert technical staff maintains sets of firewall rules that deny all un-related traffic and only allow through data packets destined for TCP/IP ports necessary for the secure operation of your FTP site.

High Availability (HA)

FTP Today owns all its own hardware and software, and manages its own private cloud infrastructure. Each FTP server in the cloud is configured as a virtual machine (VM). Our FTP cloud uses High Availability (HA) clustering, which detects any physical server or operating system failures and automatically restarts any affected VM on a different physical server in our resource pool without human intervention. The use of HA therfore limits potential down time due to a hardware failure to just a few minutes while the VM reboots on new equipment.

Regular Backups

In the rare event of a system failure more serious than that which our purpose-built redundancies already cover, every FTP server is further protected by a Continuous Data Protection (CDP) backup system for efficient disaster recovery. We can also restore data files that you may have accidentally deleted.

All FTP Today sites are backed up daily, while our Enterprise FTP sites and Dedicated FTP Servers are continuously backed up every 2 hours.

To follow privacy regulations, our CDP Backup system uses a Storage Area Network (SAN) and no data is ever recorded on transportable media. This is a standard requirement of many of the compliance-regulated industries that we serve.

Toll-free Technical Support

FTP Today provides an up-to-date online knowledgebase, troubleshooter and ticket system. We also provide context sensitive help within our Site Admin system and our Web FTP Client.

Should you have to call for any reason, we are large enough to have dedicated specialists at all levels, but small enough to offer personal service. And not only do we support you free of charge, but also your end users!

Unlimited Tier-1 Bandwidth

No monthly limits. No unplanned fees — Flat rate pricing you can bank on! FTP Today simply allows you unlimited transfer (bandwidth usage). Thus you can transfer as much data as you want every month.

Our superior network infrastructure provides customers with reliable connectivity and fast performance and includes around-the-clock monitoring. Our data center facility utilizes multiple Tier-1 Internet carriers and deploys multiple carrier-agnostic OCx connections for maximum dependability.

Unlimited Simultaneous Connections

FTP Today has the most robust infrastructure in our industry. You can have an unlimited number of users logged in simultaneously without any degradation of performance and without running into any imposed limitation. In contrast, many of our competitors can’t handle so much potential traffic, so they limit your FTP site to as little as one user logged in at a time.

Unlimited Workspaces – Private or Shared

Users can be assigned access to one or more FTP Workspaces. Workspaces are folders in the FTP site root and can be Private Workspaces (with only one user assigned) or can be Shared (Group) Workspaces. An unlimited number of Workspaces can be created and assigned to users with FTP Today’s advanced FlexFTP Site Administrator, a secure web browser accessible application.

Unlimited File Sizes

You may have noticed other file transfer services or “FTP alternatives” that have a file size limit of 2 GB. This is because they are using a web-only HTTP system and it is the HTTP protocol itself that has this limitation.

FTP Today’s system has no file size limitation. We do provide you with a Web FTP Client that operates within any web browser, but only uses HTTP to load the interface into the user’s browser window. Once loaded, it uses the FTP protocol to communicate with the server.

Compatible File Transfer Protocols

Your FTP Today FTP site is flexible and compatible with respect to preferred file transfer protocols because we use RFC-compliant FTP server application software. Your users may connect to your FTP site via:

FTP

The standard File Transfer Protocol. FTP can be run in either active or passive mode, which determine how the data connection is established. Passive FTP is the most commmon, as this is firewall friendly to the client’s network.

 

FTPS & FTPeS with SSL encryption

Commonly referred to as FTP/SSL, FTPS is a name used to encompass a number of ways in which FTP client and server software can perform secure file transfers. Each way involves the use of an SSL/TLS layer below the standard FTP protocol to encrypt the control and/or data channels.

Do I need FTPS?

This feature is for those users that need SSL-secure connections while using third-party FTP client software. Often these users also wish to automate transfers and that is where the third party software comes in.

Is FTP Today’s FTPS implementation compatible with all FTPS client software?

Our implementation is fully TLS/SSL compliant, so it is compatible with any software that is also compliant (designed and coded to RFC specifications). There are also different methods of FTPS configuration. The most common methodologies of applying FTP and SSL are:

  • AUTH TLS – Explicit FTPS or FTPES, named for the command issued to indicate that TLS (Transport Layer Security) should be used on port 21. This is the preferred method according to RFC 4217. The client connects to the server, but requests that TLS be used and performs the appropriate handshake before sending any sensitive data (username, password and data files).
  • AUTH – Implicit FTPS – uses port 990 as defined in RFC 2228.

SFTP with SSH encryption

The SFTP protocol is used by many Unix/Linux systems as a secure alternative to FTP and is also used by certain Windows software such as SecureFX or WinSCP.

Do I need SFTP?

Some of your Unix clients may simply require you to have SFTP support. One advantage of SFTP (using SSH2) over FTPS (using SSL) is that SFTP only requires port 22 open for login and transfer, whereas FTPS uses multiple open ports. This could be a better choice if the user is behind a firewall.

Does FTP Today’s SFTP server keep users jailed?

Most FTP hosts offer SFTP only for the site administrator account and use an open source SFTP server application that allows any user to see all folders in the entire file system.
FTP Today’s SFTP implementation allows you to maintain the same jailed, multi-user experience (secure file and folder access) regardless of which file transfer protocol is used. Not only does this apply to FTP and FTPS connections, but it also applys to SFTP connections — AN INDUSTRY EXCLUSIVE!

Another fault of most competitive SFTP implementation is that there are no activity logs for SFTP transfers (typical of OpenSSH deployments). FTP Today’s SFTP implementation provides the same detailed audit reports and server logs for FTP, FTPS and SFTP transfer sessions, including reports indicating which protocol was used at the time of each activity.

 

FTP-over-HTTPS (our Secure Web FTP Client with SSL encryption).

This version of our Web FTP Client replaces our Standard browser-based file transfer client with our Secure file transfer client. The Secure version creates a secure HTTPS tunnel with up to 2048-bit encryption between the browser and the server. This SSL-encrypted tunnel protects all data in transit and, due to using the standard port 443 for HTTPS, is also firewall-friendly.

Web FTP Client

With FTP Today your users have a choice of using their own FTP software or they can just use their web browser. Our full-featured Web FTP Client uses the actual FTP protocol, not just HTTP, so there are no file size limitations like you often find in other HTTP-based file transfer services.

Users love the drag-and-drop simplicity for uploading and downloading files, selecting multiple files with the familiar SHIFT or CTRL keys, and much more that this full-featured FTP client offers.

Click here for Demo

Secure Admin via Web Browser

Our proprietary FlexFTP Site Administrator is the world’s most advanced FTP control panel.

You can safely administer your FTP site from any computer in the world, including mobile devices like your iPhone or iPad. Once logged in, you can manage users, assign them workspaces, restrict the type of access, set up email alert notifications or view a multitude of reports and usage metrics.

Multiple Administrator Accounts

With FTP Today your FTP site managers won’t have to share a common master login. Any user you create on the system can be designated as a Site Administrator. Site administrators can not only manages all the users, features and settings of the FTP site; they also have full reign over the entire directory structure when they log in with an FTP connection.

Granular User Access Permissions

Each Workspace that a user has been given access to can be further limited by FTP Today’s granular user access permission system. There are four different permissions that can be assigned (by user by workspace):

UPLOAD – allows user to PUT files

DOWNLOAD – allows user to GET files

DELETE – allows user to REMOVE files

LIST – allows user to view DIRECTORY

Reports, Metrics and Logs

Going far beyond simple transfer logs, FTP Today provides both live and on demand reports detailing who is online, what they are doing now, what they have done in the past, and when they did it. This includes drill-down metrics and graphs for trend analysis on things like Disk Usage, Traffic, Head Counts, Logins, and much more.

Enforce Encryption

Even though most of our plans support both encrypted and un-encrypted access, you may have a strong business case to disallow un-encrypted access. Your FTP Today Site Settings screen will allow you complete control over which protocols are enabled. Simply turn off FTP and HTTP and your system will only accept encrypted connections.

This can be particularly useful to enforce Explicit FTPS on users of third party FTP software, who might otherwise establish an unsecure connection due to their software defaults.

User Control Panel

You can allow or disallow control panel access to end users. This would be required to be allowed if you want users to be able to change their Name, Email Address or Password. This feature works hand in hand with other password features of the control panel.

Basic Password Options include whether you allow users to edit their passwords, or just to update their name and email address. Another is to allow forgotten password resets by email.

Enterprise customers can also take advantage of Enhanced Password Options, such as requiring strong passwords, expiring passwords or first-time user passwords. These would also require the users to have control panel access in order to update their passwords.

Forgotten Password Reset

If you want to allow users to reset a forgotten password, you can enable this feature. If they click the forgotten password link on the login screen for the control panel, it will email them a temporary link. They can then follow that link to choose a new password.

First-Time Passwords

If you choose, you can let the system generate a temporary password for every new user. It will then send the user an email with a link to log in for the first time. Once logged in, they will be forced to choose a new password.

Expiring Passwords

You will have the option of forcing password expiration and choosing the number of days since the lasst change that a password will expire. Highly regulated industries may even require that passwords be changed every 30 days. If you have a large user base, why would you want to have to manage this yourself.

Enabling password expiration will also auto-enable control panel access for users. Our system will also send all users a warning email before their password expires, and you control haw many days the warning email goes out prior to expiration.

Require Strong Passwords

Password strength is a primary key to good FTP site security. Whether you allow users to change their own passwords or not, you may wish to enable Require Strong Passwords. Once enabled, you can then choose your own settings for password length,  number of upper case, lower case, numerals and symbols. In addition, you can prohibit usernames within passwords and choose the number of days that must pass before a password can be re-used.

Suspending and Expiring Users

You can suspend a user’s FTP access at any time without having to delete their login account. You can also set a user to automatically be suspended on a calendar date in the future. Using Auto-Suspend effectively allows you to set up Expiring Logins.

Email Alerts & Notifications

Managable email alerts can be triggered based on events taking place on the FTP site, such as when an upload or a download occurs in a given workspace. You can also alert yourself or others when certain disk usage thresholds are reached.

Multiple email addresses can receive the same notices if you want. Our email alerts can be controlled to occur intantaneously, hourly or daily.

Our email alert system also allows you to change the From Address, Reply-to Address, Subject and Body of the email alerts that you configure. This way every email is branded with your own company information and, should anyone reply to an alert message, their reply will go straight to you and not to FTP Today.

Auto-Delete Files

Our service is used by most as a file delivery system. Often, once a file reaches the intended recipient(s), you may wish to clean up the system and delete older files. This need may even be driven by compliance with regulations for your industry.

Of course, you can always delete files manually, but FTP Today also provides you control over the auto-deletion of files. The auto-delete script runs daily and you can control, by Workspace, which files will be deleted based on how long ago they were uploaded.

You choose how many days old files must be for each Workspace that you wish to have processed by our auto-delete script. You also choose whether only files should be deleted or whether you also wish to include empty subfolders.

Restrict Access by IP Address

For the utmost in security, we give you the ability to disallow all global IP addresses on all incoming ports. You can then allow only specific IP addresses that belong to you and your important clients to connect. Of course, in order to enable this feature you and your clients must all have static IP addresses on your end.

Data at Rest (DaR) Encryption

We offer our Enterprise accounts the added option of an Enterprise Cryptographic Filesystem. Data at rest, i.e. when stored on our server hard drives, is automatically encrypted using a 256-bit AES cipher.

When FTP users download files from your DaR-protected FTP site, those files are automatically decrypted so that they arive on the user’s computer as a normal, readable file. This type of protection is designed to prevent anyone gaining command line access, including FTP Today’s support staff, from being able to read file contents.

Resume Broken Transfers

No matter how reliable we assume the Internet is, there is always a chance that your ISP connection may drop, a backbone may be temporarily severed, or some other issue may occur beyond your control that could cause you to lose your connection during a large file transfer. FTP Today’s servers will all accept resumed transfers from your third party FTP software and our Web FTP Client is configured to resume transfers by default.

Dedicated FTP Site IP Address

A dedicated IP address provides advantages over other FTP hosting companies that give you a shared IP address:

  • Your own Domain Name can be pointed to your FTP site, such as:
    • ftp.widgetco.com
    • secureftp.widgetco.com
    • myftpsite.widgetco.com
  • A Custom SSL Certificate matching your domain name can also be applied to your FTP site.

Logo Branding

We offer a brandable version of our Web FTP Client. This will take away the FTP Today banner and replace it with your own company logo and a link back to your website if the logo is clicked.

SSL Certificates

Any FTP Today plan that includes FTPS and HTTPS encryption will also include a valid, CA-signed SSL certificate for *.ftptoday.com. This assures that no SSL certificate warnings from anyone’s browser if they use the <yourcompany>.ftptoday.com URL.

Business and Enterprise plan customers can also opt for a custom SSL certificates to match up with your own domain name such as <secureftp.yourcompany.com>.