Glossary

Ssecurity

Secure file transfer

A file transfer with named controls: encryption on the path, authentication, and usually encryption at rest.

How it works

The phrase alone is not a protocol. SFTP, FTPS, and HTTPS can each qualify. Plain FTP cannot. Ask which protocol, which key check, and where the file sits after.

A contract asks for secure transfer. The build uses SFTP with a pinned host key and a bucket that encrypts at rest. A second vendor enables FTP on port 21 and labels the folder secure. Only the first meets the ask.

How it differs

Secure is not managed. Managed adds schedule and audit. You can have a secure one-off with no ticket history.

A lock icon is TLS, not an access rule.

Write the protocol in the runbook.

On the ticket

  • The practical close is a log line: time, actor, byte count, result.
  • Without that line the transfer is a story.
  • With it, the next person can see whether this door did what the ticket claimed.
  • If the path is shared, say so in the partner profile so a later change does not silently pick a different limit, key, or region.
  • On a real ticket, write down the door, the byte count, and the clock.
  • For secure file transfer, that means naming the host or bucket, the expected size, and the time the other side must have a complete file.
  • A progress bar is not that record.
  • A 200 response that arrives before the complete call is not that record.
  • If a retry is allowed, say how many and whether it resumes.
  • If a person must approve the send, name the person.
  • Partners who receive secure file transfer files should match on hash or size before they import.
  • A same-length corrupt file passes a size check and fails a hash.
  • Keep the published hash off the only channel an attacker can edit, or treat it as a corruption check rather than a substitution check.
  • When the path changes, new key, new region, new cap, update the profile the same day so the next run does not use a stale limit.