Coming soon

Developer library · .NET · C# and VB.NET

Bastion SftpClient

SFTP that fits inside your application, not beside it.

Give your .NET program its own SSH-2 and SFTP client. One assembly, ten lines to a working transfer — no command-line tool to shell out to, no script to generate, no exit code to guess at.

Bastion SftpClient transferring files from an SFTP server

1

file to deploy — Bouncy Castle is compiled in and internalised

7

target frameworks, .NET Framework 4.6.2 to .NET 10

937

automated tests, plus interoperability against three independent servers

18

cookbook recipes, and every sample in both C# and VB.NET

Ten lines to a working transfer

The library connects, performs the key exchange, authenticates and moves files, raising an event for every step. Most people buying an SFTP component for .NET write C#, so every sample ships complete in both languages — you never guess which parts are idiomatic.

VB.NET

Using client As New SftpClient()
    client.Hostname = "sftp.example.com"
    client.Login = "alice"
    client.Password = "correct horse battery staple"

    AddHandler client.FingerPrint, AddressOf OnFingerPrint
    client.Connect()

    For Each entry In client.ListDir("/")
        Console.WriteLine("{0,-30} {1,12}", entry.Name, entry.Size)
    Next

    client.GetFile("/reports/january.csv", "C:\reports\january.csv")
End Using

C#

using var client = new SftpClient
{
    Hostname = "sftp.example.com",
    Login    = "alice",
    Password = "correct horse battery staple"
};

client.FingerPrint += (sender, e) =>
    e.Action = e.Fingerprint == KnownFingerprint
        ? ClientActions.Allow
        : ClientActions.Deny;

client.Connect();

foreach (var entry in client.ListDir("/"))
    Console.WriteLine($"{entry.Name,-30} {entry.Size,12}");

client.GetFile("/reports/january.csv", @"C:\reports\january.csv");

Everything a real integration needs

Every kind of login

Password, public key, key-then-password and keyboard-interactive. Private keys are read from the files ssh-keygen writes: modern OpenSSH format and the older PEM forms, for Ed25519, ECDSA and RSA.

Post-quantum by default

Key exchange leads with ML-KEM-768 combined with X25519. On a client that matters most: the SSH specification gives the client the casting vote, so this list decides what protects the session.

Built for unattended work

Whole directories, recursively, with a per-item event, a per-failure event and a result object that counts what happened. Progress with a cancel flag. Keepalives that hold a connection open through a firewall.

Defended against the server

A remote name that tries to escape the download folder is skipped and reported. Symbolic links are never followed. Nesting is bounded. A server key below your stated size is refused before any credential is sent.

Everything it learns, it tells you

Events for the connection, the fingerprint, the algorithms agreed, each directory entry, each block transferred and each item that failed. The protocol conversation is rendered as readable lines.

A complete client, in source

Bastion.Client is a two-pane transfer application in ordinary Windows Forms: tabs per connection, a site manager, saved passwords protected by Windows, a known-hosts store and a protocol log. Open it and change it.

Algorithms your auditors can name

Enabled by default: Curve25519 and NIST-curve key exchange, the ML-KEM hybrid, Ed25519, ECDSA and RSA-SHA2 host keys, ChaCha20-Poly1305 and AES-GCM, and encrypt-then-MAC HMAC-SHA2. CBC ciphers, SHA-1 MACs and ssh-rsa are implemented and switched off until you ask. Every algorithm is an enumeration, not a string — a name cannot be misspelt, and the editor offers you every choice.

client.AlgorithmPolicy.Ciphers = {SshCipher.Aes256Gcm, SshCipher.Aes256Ctr}
client.AlgorithmPolicy.MinimumRsaKeyBits = 3072

The cryptography is a fixed table inside the assembly. Nothing is read from Windows, CNG or a machine-wide policy, so a transfer that works on your machine works on your customer’s.

Proved against servers written by other people

937 automated tests, and interoperability proved against three independently written servers: Bastion SftpServer, Python’s Paramiko and Go’s pkg/sftp.

A client tested only against a scripted peer agrees with whatever its own author believed. This one had three defects that survived 491 such tests and were found in a minute by one connection to a server somebody else wrote.

Pairs with Bastion SftpServer: the same ideas carry the same names in both — AlgorithmPolicy has the same five lists, and ClientActions is FtpActions with the same members. Learn one and you know the other.

It fits where your application already runs

Frameworks.NET Framework 4.6.2, 4.7.2 and 4.8 · .NET Standard 2.0 · .NET 8, 9 and 10
LanguagesC# and VB.NET, with complete samples in both
Visual Studio2017, 2019, 2022 and 2026 — a sample solution for each, all built by the release gate
In the boxThe library and IntelliSense XML, QuickStart in C# and VB.NET, the Bastion.Client application in source, a command-line client, and web and CHM help
DependenciesNone to deploy. Bouncy Castle is compiled in; one file ships
Operating systemWindows

How it compares

Capability and licensing matrix for commercial .NET SFTP client components, compiled September 2026 from each vendor’s published documentation. A ? means the capability was not stated either way — it is not a claim that the product lacks it.

Rebex SFTPRebex CR, s.r.o.
Bastion SftpClientBastion Software Solutions
IPWorks SSH/n software · SFTPClient
Security
Post-quantum hybrid key exchangeML-KEM-768 with X25519
✔
✔on by default
✔from the 2026 releases
Strict key exchangeTerrapin countermeasure, CVE-2023-48795
✔
✔
✔
ChaCha20-Poly1305
✔
✔
✔
Ed25519 keys
✔
✔
?
OpenSSH-format private keys
✔
✔
✔
Keyboard-interactive login
✔
✔
✔
Transfer
Recursive directory transferwith per-item results
✔
✔
?
Path-escape defence on downloadhostile remote names skipped and reported
?
✔
?
Delivery
No external dependencies
✔post-quantum needs a PQC-enabled Windows
✔crypto compiled in
✔
Samples in C# and VB.NET
✔
✔
?
Server and SaaS deployment includedno per-server or per-instance fee
✔
✔
—separate Server and Cloud licences
LicensingPublished list price, 1 developer, perpetual with 12 months of updates, checked September 2026
$4991 developer · royalty-freerenewal $249 a year; volume discounts from 2 licences
$3991 developer · OEM$1,99910 developers · OEM$3,999Unlimited developers · site
$9991 developer · .NET Edition, client and serverroyalty-free only where the order form says so
✔ supported— not offered? not stated in public documentation

OEM licensing

One licence type, priced for commercial software teams. Every Bastion SftpClient licence is an OEM licence: build it into your product and ship that product to as many customers as you like, on as many machines as they like.

Developer OEM$3991 named developer
  • Royalty-free redistribution inside your own applications
  • Desktop, server, cloud and SaaS deployment — no per-server or per-instance fees
  • Perpetual licence with 12 months of updates; renewals at 35% of list
  • Every build, .NET Framework to .NET 10, and every sample in C# and VB.NET
Team OEM$1,999Up to 10 named developers
  • Everything in Developer OEM
  • $199 per developer
Site OEM$3,999Unlimited developers at one company
  • Everything in Developer OEM
  • No developer count to track as the team grows
  • Source-code escrow available, priced on request
Bastion SFTP Suite — Bastion SftpClient and Bastion SftpServer togetherSave $149 on buying both — written to talk to each other, with the same names for the same ideas.
$699 per developer, OEM
See all suites →

Launch prices in US dollars. Final pricing is confirmed at release.

Try it properly first

A thirty-day evaluation of the complete component. Nothing removed and no limits — you evaluate exactly what you would buy.

Because the trial is the whole product, sales are final, and accepting the terms and conditions of sale is part of completing a purchase. The one exception: report a serious defect and, if we cannot fix it and release an update within thirty days, we refund you in full.

Need more than the component? Custom development and integration work built on it is available, remotely or on site — talk to us.

Get notified when Bastion SftpClient is released

Tell us what you are building. We will let you know the moment the evaluation is available — and answer plainly whether it fits.

Scroll to Top