Coming soon
Developer library · .NET · C# and VB.NET
Bastion SftpClient
SFTP that fits inside your application, not beside it.
Give your .NET program its own SSH-2 and SFTP client. One assembly, ten lines to a working transfer — no command-line tool to shell out to, no script to generate, no exit code to guess at.
1
file to deploy — Bouncy Castle is compiled in and internalised
7
target frameworks, .NET Framework 4.6.2 to .NET 10
937
automated tests, plus interoperability against three independent servers
18
cookbook recipes, and every sample in both C# and VB.NET
Ten lines to a working transfer
The library connects, performs the key exchange, authenticates and moves files, raising an event for every step. Most people buying an SFTP component for .NET write C#, so every sample ships complete in both languages — you never guess which parts are idiomatic.
VB.NET
Using client As New SftpClient()
client.Hostname = "sftp.example.com"
client.Login = "alice"
client.Password = "correct horse battery staple"
AddHandler client.FingerPrint, AddressOf OnFingerPrint
client.Connect()
For Each entry In client.ListDir("/")
Console.WriteLine("{0,-30} {1,12}", entry.Name, entry.Size)
Next
client.GetFile("/reports/january.csv", "C:\reports\january.csv")
End Using
C#
using var client = new SftpClient
{
Hostname = "sftp.example.com",
Login = "alice",
Password = "correct horse battery staple"
};
client.FingerPrint += (sender, e) =>
e.Action = e.Fingerprint == KnownFingerprint
? ClientActions.Allow
: ClientActions.Deny;
client.Connect();
foreach (var entry in client.ListDir("/"))
Console.WriteLine($"{entry.Name,-30} {entry.Size,12}");
client.GetFile("/reports/january.csv", @"C:\reports\january.csv");
Everything a real integration needs
Every kind of login
Password, public key, key-then-password and keyboard-interactive. Private keys are read from the files ssh-keygen writes: modern OpenSSH format and the older PEM forms, for Ed25519, ECDSA and RSA.
Post-quantum by default
Key exchange leads with ML-KEM-768 combined with X25519. On a client that matters most: the SSH specification gives the client the casting vote, so this list decides what protects the session.
Built for unattended work
Whole directories, recursively, with a per-item event, a per-failure event and a result object that counts what happened. Progress with a cancel flag. Keepalives that hold a connection open through a firewall.
Defended against the server
A remote name that tries to escape the download folder is skipped and reported. Symbolic links are never followed. Nesting is bounded. A server key below your stated size is refused before any credential is sent.
Everything it learns, it tells you
Events for the connection, the fingerprint, the algorithms agreed, each directory entry, each block transferred and each item that failed. The protocol conversation is rendered as readable lines.
A complete client, in source
Bastion.Client is a two-pane transfer application in ordinary Windows Forms: tabs per connection, a site manager, saved passwords protected by Windows, a known-hosts store and a protocol log. Open it and change it.
Algorithms your auditors can name
Enabled by default: Curve25519 and NIST-curve key exchange, the ML-KEM hybrid, Ed25519, ECDSA and RSA-SHA2 host keys, ChaCha20-Poly1305 and AES-GCM, and encrypt-then-MAC HMAC-SHA2. CBC ciphers, SHA-1 MACs and ssh-rsa are implemented and switched off until you ask. Every algorithm is an enumeration, not a string — a name cannot be misspelt, and the editor offers you every choice.
client.AlgorithmPolicy.Ciphers = {SshCipher.Aes256Gcm, SshCipher.Aes256Ctr}
client.AlgorithmPolicy.MinimumRsaKeyBits = 3072
The cryptography is a fixed table inside the assembly. Nothing is read from Windows, CNG or a machine-wide policy, so a transfer that works on your machine works on your customer’s.
Proved against servers written by other people
937 automated tests, and interoperability proved against three independently written servers: Bastion SftpServer, Python’s Paramiko and Go’s pkg/sftp.
A client tested only against a scripted peer agrees with whatever its own author believed. This one had three defects that survived 491 such tests and were found in a minute by one connection to a server somebody else wrote.
Pairs with Bastion SftpServer: the same ideas carry the same names in both — AlgorithmPolicy has the same five lists, and ClientActions is FtpActions with the same members. Learn one and you know the other.
It fits where your application already runs
| Frameworks | .NET Framework 4.6.2, 4.7.2 and 4.8 · .NET Standard 2.0 · .NET 8, 9 and 10 |
| Languages | C# and VB.NET, with complete samples in both |
| Visual Studio | 2017, 2019, 2022 and 2026 — a sample solution for each, all built by the release gate |
| In the box | The library and IntelliSense XML, QuickStart in C# and VB.NET, the Bastion.Client application in source, a command-line client, and web and CHM help |
| Dependencies | None to deploy. Bouncy Castle is compiled in; one file ships |
| Operating system | Windows |
How it compares
Capability and licensing matrix for commercial .NET SFTP client components, compiled September 2026 from each vendor’s published documentation. A ? means the capability was not stated either way — it is not a claim that the product lacks it.
OEM licensing
One licence type, priced for commercial software teams. Every Bastion SftpClient licence is an OEM licence: build it into your product and ship that product to as many customers as you like, on as many machines as they like.
- Royalty-free redistribution inside your own applications
- Desktop, server, cloud and SaaS deployment — no per-server or per-instance fees
- Perpetual licence with 12 months of updates; renewals at 35% of list
- Every build, .NET Framework to .NET 10, and every sample in C# and VB.NET
- Everything in Developer OEM
- $199 per developer
- Everything in Developer OEM
- No developer count to track as the team grows
- Source-code escrow available, priced on request
Launch prices in US dollars. Final pricing is confirmed at release.
Try it properly first
A thirty-day evaluation of the complete component. Nothing removed and no limits — you evaluate exactly what you would buy.
Because the trial is the whole product, sales are final, and accepting the terms and conditions of sale is part of completing a purchase. The one exception: report a serious defect and, if we cannot fix it and release an update within thirty days, we refund you in full.
Need more than the component? Custom development and integration work built on it is available, remotely or on site — talk to us.
Get notified when Bastion SftpClient is released
Tell us what you are building. We will let you know the moment the evaluation is available — and answer plainly whether it fits.