FilePort Pro — Security
Last updated: August 23, 2026
FilePort Pro is a web-based FTP and SFTP client. It connects to servers on your behalf and handles the credentials you enter to make those connections. This page explains, precisely and verifiably, how that works and what we do with your data. Nothing here is marketing — every statement describes what the product actually does.
How connections and credentials work
-
FilePort Pro relays your connection through our server. Your browser talks only to
/api/*endpoints on our service; the server opens the actual FTP or SFTP connection to the server you chose, using the credentials you submitted. - Traffic between your browser and FilePort Pro is encrypted (HTTPS), served through our hosting platform.
- Your credentials necessarily pass through our server in memory while an active session exists — the server needs them to open and, for FTP, transparently reconnect to your server. They are used for no other purpose.
Credentials are held in memory only
- Credentials are held only in memory for the duration of your session. They are never written to disk, never stored in a database, and never inserted into a database.
- Your session ends when you disconnect or after a period of inactivity (approximately 15 minutes).
- The free tier has no account system, so there is nothing for us to store or retain on your behalf.
Logging and retention
- Server logs record only event names and error codes (for example “connection failed”). They do not record hosts, usernames, passwords, or file contents.
- In-app logs have no retention mechanism beyond writing to the process output stream; we do not keep a separate log store.
Encryption in transit
- SFTP runs over SSH (port 22 by default) and encrypts traffic in transit.
- Plain FTP is unencrypted by protocol design. The app warns you before making a plain-FTP connection and recommends SFTP whenever possible.
SFTP host-key verification (trust on first use)
- When you connect to an SFTP server, the app records that server’s host-key fingerprint and shows you the SHA256 fingerprint of the key.
-
The fingerprint is stored in your browser, keyed by server address and
port. It is a non-secret identifier that anyone can read with
ssh-keyscan— it is not a credential. - If the server’s key ever changes since the fingerprint you saved, the app warns you and refuses to connect until you confirm the change or forget the previously saved key, because a changed key may indicate a man-in-the-middle.
Infrastructure
- FilePort Pro is hosted on the cto.new platform. Its database runs on Neon.
Report a vulnerability
We welcome responsible reports of security issues. Please send details of any vulnerability you find to our security contact:
fileport-pro-a0514327@ctomail.io
Please include the relevant page or behaviour, what you observed, and — where possible — a minimal reproduction. We aim to acknowledge reports and to act on confirmed issues.
Security review status
- FilePort Pro’s design has passed an internal, design-level security review (verdict: pass with changes, August 2026), and the fixes from that review have been adopted.
- A security re-review is planned as part of our process before launch.
- This is an internal review process. FilePort Pro has not undergone an independent, third-party, or paid security audit.