SSH File Transfer Protocol 101: What It Is and When to Use It

8 October 2026

Using SFTP to transfer files securely over an encrypted connection

If you've ever been told to "use SFTP" for a file transfer and quietly nodded while wondering what that actually meant, you're far from alone. It's one of those terms that gets thrown around in IT conversations, but rarely gets a plain-English explanation.
SSH File Transfer Protocol (SFTP) is a secure method for sending files between two systems over an encrypted connection. It runs on top of SSH (Secure Shell) and protects both your login credentials and the files themselves during transit. Unlike older protocols such as FTP, everything travels through a single encrypted channel on port 22, which means there's no window where your data is exposed.
For Irish businesses handling client work, contracts, or any kind of sensitive data, understanding SFTP matters. It's the standard protocol behind most secure server-to-server file transfers today, and it plays a direct part in keeping your files protected during delivery. Whether you're an agency sending design assets, a legal team sharing documents, or a finance professional moving reports between systems, SFTP is likely already part of your workflow.

How Does SFTP Work?

SFTP operates as a subsystem of the SSH protocol. When you connect to an SFTP server, your client first establishes an SSH session. That session handles authentication (usually through a username and password, or SSH key pairs) and sets up the encrypted tunnel.
Once that tunnel is live, all commands and data pass through it. Uploading a file, downloading one, renaming, deleting, changing permissions: it all happens over that same single connection. There are no separate channels for commands and data, which is a big departure from how FTP works.
Because SFTP uses SSH's encryption (typically AES), both the data in transit and the authentication credentials are protected. If someone intercepts the traffic, they'll see scrambled packets with no way to read the contents. That's a major step up from FTP, which sends everything, including passwords, in plain text.

SFTP vs FTP: What Changed and Why It Matters

FTP was built in the early 1970s. It worked well for decades, but security wasn't part of its design. Credentials travel unencrypted. Data travels unencrypted. And FTP relies on multiple ports, which creates headaches for firewalls and NAT configurations.
SFTP was designed from scratch by the IETF's SECSH working group as a replacement. It's not just FTP with encryption bolted on (that would be FTPS, a different protocol entirely). SFTP is a completely separate protocol that happens to handle file transfers.

Quick Comparison

  • FTP uses port 21 (and often port 20 for data). SFTP uses port 22 only.
  • FTP sends credentials and data in plain text. SFTP encrypts everything.
  • FTP requires multiple connections. SFTP runs over a single SSH channel.
  • SFTP can preserve file attributes like timestamps, while standard FTP cannot.
  • SFTP passes through firewalls more easily because it uses only one port.

If you're still running FTP in any production environment, it's worth making the switch. Most modern hosting providers and business file sharing platforms have moved to SFTP or equivalent encrypted transfer methods already.

When Should You Use SFTP?

SFTP isn't the right tool for every situation. It's built for server-to-server and client-to-server transfers, typically managed by someone with a bit of technical knowledge. Here's where it makes the most sense.
Automated file transfers between systems are probably the most common use case. If your business pulls reports from a partner's server every night, or pushes data files to a third-party processor, SFTP handles that reliably and securely.
Website management is another big one. If you've ever uploaded files to a web server using FileZilla or WinSCP, you've likely used SFTP (or should have been). It's the standard for pushing code, images, and assets to hosting environments.
For teams in regulated industries (legal, healthcare, financial services), SFTP provides the encrypted transit that compliance frameworks expect. It won't tick every box on its own, but it's a foundational layer for keeping files secure when sharing online.
Where SFTP doesn't fit so well is ad-hoc file sharing between people. Asking a client to install an SFTP client and connect to your server is rarely practical. For those situations, a purpose-built file delivery platform like CloudExpress makes far more sense, giving you encrypted delivery, download tracking, and a clean recipient experience without any technical setup on their end.

Does SFTP Help With GDPR Compliance?

SFTP alone won't make you GDPR compliant, but it's a meaningful part of the picture. The Data Protection Commission in Ireland expects organisations to implement appropriate technical safeguards when transferring personal data, and encryption in transit is one of those safeguards.
SFTP provides that encryption layer. It also supports strong authentication through SSH keys, which is more secure than basic password authentication. And because all commands and data travel over a single encrypted connection, there's less surface area for interception compared to older protocols.
But GDPR compliance goes beyond just the transfer itself. You also need to consider where your data is hosted, who has access, how long files are retained, and whether you can demonstrate an audit trail. That's where dedicated platforms with EU-hosted infrastructure and built-in access controls add real value on top of whatever protocol sits underneath.

Common SFTP Clients and How to Get Started

Getting started with SFTP doesn't require much. You need an SFTP client (the software on your end) and access credentials for the server you're connecting to.

Popular SFTP Clients

FileZilla is probably the most widely used free option. It runs on Windows, Mac, and Linux, and supports both SFTP and FTPS. WinSCP is another solid choice for Windows users, with a clean interface and good scripting support.
Mac, Linux and Windows 10/11 all come with SFTP built into the command line. Open Terminal (or Command Prompt or PowerShell on Windows), type sftp [email protected] and you're connected. No extra software needed.

Connecting for the First Time

Your hosting provider or IT team will give you the server address, your username, and either a password or an SSH key file. Enter those into your SFTP client, make sure port 22 is selected, and connect. The first time you connect to a new server, you'll see a prompt asking you to verify the server's host key. Check that it matches what your provider gave you, confirm it, and you're in.
From there, you'll see your local files on one side and the remote server's files on the other. Drag and drop to transfer. It really is that straightforward once you're set up.
SFTP is one of those tools that, once you understand it, becomes second nature. If you're handling any kind of sensitive file transfer for your business, it should be part of your toolkit. And for those everyday file deliveries to clients where SFTP is overkill, CloudExpress lets you send large files securely with EU-hosted transfers, GDPR-minded workflows, and zero friction for the people receiving them.

Frequently Asked Questions

What does SFTP stand for?

Is SFTP the same as FTP?

What port does SFTP use?

Do I need special software to use SFTP?

Does SFTP help with GDPR compliance in Ireland?

When should I use SFTP versus a file delivery platform?