Coming soon
Developer library · .NET · C# and VB.NET
Bastion SftpServer
Put a real SFTP server inside your own application.
One .NET assembly. No service to install, no configuration file to deploy, no second process to keep alive. Add a reference, set a port, answer one event — and your application is an SSH-2 and SFTP server.
26
events — your code decides who connects and what they may touch
1,393
automated tests, proved against four independent SSH client stacks
7
target frameworks, .NET Framework 4.6.2 to .NET 10
0
dependencies to deploy — copy the DLL
A working server in a dozen lines
This is the complete program, in the language your team writes. The user is confined to the home directory you assign, and any SFTP client can connect.
VB.NET
Imports Bastion.SftpServer.Api
Public Class MinimalServer
Private WithEvents _server As New SftpServer()
Public Sub Run()
_server.Port = 2222
_server.DefaultHomeDir = "C:\SftpRoot"
_server.GenerateHostKeys()
_server.Start()
End Sub
Private Sub OnLoginPassword(sender As Object, e As LoginPasswordEventArgs) _
Handles _server.LoginPassword
If e.Login = "alice" AndAlso e.Password = "correct horse battery staple" Then
e.User.HomeDir = "C:\SftpRoot\alice"
e.Action = FtpActions.Allow
Else
e.Action = FtpActions.Deny
End If
End Sub
End Class
C#
using Bastion.SftpServer.Api;
public class MinimalServer
{
private readonly SftpServer _server = new SftpServer();
public void Run()
{
_server.LoginPassword += OnLoginPassword;
_server.Port = 2222;
_server.DefaultHomeDir = @"C:\SftpRoot";
_server.GenerateHostKeys();
_server.Start();
}
private void OnLoginPassword(object sender, LoginPasswordEventArgs e)
{
if (e.Login == "alice" && e.Password == "correct horse battery staple")
{
e.User.HomeDir = @"C:\SftpRoot\alice";
e.Action = FtpActions.Allow;
}
else
{
e.Action = FtpActions.Deny;
}
}
}
Written for the deployments that are hard
A fixed set of machines that may connect and nothing else. Users who must never see each other’s files. Auditors who name algorithms.
Policy is yours
Twenty-six events cover connection, authentication, every directory and file operation, transfer progress and the raw protocol conversation. A server with no handlers still works.
A jail, not a setting
A session cannot reach outside its home directory by any path it can build: dot-dot traversal, absolute paths, device names, alternate data streams, symbolic links or junctions.
Two-factor login, built in
Password and public key, alone or both required together. Time-based one-time passwords from any authenticator app. Windows account validation against local or domain accounts.
Brute-force defender
Failed logins are counted per address across connections, and an address over the threshold is refused at the accept loop. Bans survive a restart.
Nothing saved in the clear
Authorised keys and ban lists are written under AES-256-GCM with a key derived from your passphrase, and authenticated. There is no plain-text option.
Connections that survive a firewall
A NAT device drops an idle mapping and tells neither end. Set KeepAliveSeconds and it does not happen — and a client whose machine was switched off is noticed in a known number of seconds.
Virtual folders. Show a user a directory that is not under their home directory at all — a shared drop box, a read-only archive — without moving a single file. Kerberos. The SSH half of GSSAPI authentication (RFC 4462) is complete and tested; you supply the Kerberos mechanism through an interface, and until you do the method is never advertised.
Post-quantum by default
The key exchange leads with ML-KEM-768 combined with X25519. The session is safe if either half holds — and traffic recorded today cannot be decrypted later. Alongside it: ChaCha20-Poly1305 and AES-GCM, Ed25519, ECDSA and RSA-SHA2 host keys, encrypt-then-MAC, strict key exchange against Terrapin, and a FIPS-approved-only mode with one call. Legacy algorithms are implemented, and off until you ask.
Tested against the clients your users run
Interoperability is proved against four independently written SSH stacks — OpenSSH, the PuTTY-derived clients, SSH.NET and Go’s x/crypto/ssh. Not four skins of the same one.
Every release runs the same gate: tests on two frameworks, a release merge across all seven target frameworks, a public API check, four sample solutions and the help build. The documentation is tested too — a property added without being documented fails the build.
Pairs with Bastion SftpClient — FtpActions is ClientActions with the same members, and AlgorithmPolicy has the same five lists in both.
It fits where your application already runs
| Frameworks | .NET Framework 4.6.2, 4.7.2 and 4.8 · .NET Standard 2.0 · .NET 8, 9 and 10 |
| Languages | C# and VB.NET, with complete samples in both |
| Visual Studio | 2017, 2019, 2022 and 2026 — a sample solution for each, all built by the release gate |
| In the box | QuickStart and a full Windows Forms server in C# and VB.NET, the Workbench (every setting in a property grid, every event logged live), and web and CHM help |
| Dependencies | None. Bouncy Castle is compiled in; one file ships |
| Operating system | Windows |
How it compares
Capability and licensing matrix for commercial embeddable .NET SFTP servers, compiled September 2026 from each vendor’s published documentation. A ? means the capability was not stated either way — it is not a claim that the product lacks it.
Rebex File Server also offers SSH shell, exec and SCP. Bastion SftpServer concentrates on SFTP and the controls around it.
OEM licensing
One licence type, priced for commercial software teams. Every Bastion SftpServer licence is an OEM licence: build it into your product and ship that product to as many customers as you like, on as many machines as they like.
- Royalty-free redistribution inside your own applications
- Desktop, server, cloud and SaaS deployment — no per-server or per-instance fees
- Perpetual licence with 12 months of updates; renewals at 35% of list
- Every build, .NET Framework to .NET 10, and every sample in C# and VB.NET
- Everything in Developer OEM
- $225 per developer
- Everything in Developer OEM
- No developer count to track as the team grows
- Source-code escrow available, priced on request
Launch prices in US dollars. Final pricing is confirmed at release.
Try it properly first
A thirty-day evaluation of the complete component. Nothing removed and no limits — you evaluate exactly what you would buy.
Because the trial is the whole product, sales are final, and accepting the terms and conditions of sale is part of completing a purchase. The one exception: report a serious defect and, if we cannot fix it and release an update within thirty days, we refund you in full.
Need more than the component? Custom development and integration work built on it is available, remotely or on site — talk to us.
Get notified when Bastion SftpServer is released
Tell us what you are building. We will let you know the moment the evaluation is available — and answer plainly whether it fits.