Use encrypted transfers, access controls, and audit logs as part of your organization's approach to SOC 2, with file storage under your control.
SFTPPlus MFT can support the file transfer controls in a system undergoing a SOC 2 assessment. Your team can configure encrypted connections, restrict access to files, and retain records of transfer activity as evidence of how the system operates.
SFTPPlus MFT is software you run on your own infrastructure or in your chosen cloud environment. ProAtria, the company behind SFTPPlus MFT, does not provide it as a hosted SaaS file transfer service and does not store or manage the files you transfer. Your organization chooses where files are stored, who can access them, and how long they are retained.
SOC 2 is an independent examination of controls at a service organization. It uses the American Institute of Certified Public Accountants (AICPA) Trust Services Criteria, which cover security, availability, processing integrity, confidentiality, and privacy. The categories included in an assessment depend on its scope and the organization's service commitments. The AICPA SOC 2 overview explains the purpose of the report and links to the criteria.
The assessment covers a defined system and the people, processes, and technology used to operate it. It is not a certification of an individual software product. If your organization needs a SOC 2 report, that report must cover your own system and controls; installing SFTPPlus MFT alone does not establish compliance or guarantee an audit outcome.
Use SFTP, FTPS, or HTTPS to encrypt files while they travel between systems. Configure the permitted protocols and algorithms, and validate remote server identities using trusted SSH host keys or TLS certificates. Encryption during transfer is one part of protecting data: your storage configuration, encryption at rest, and key management also need to follow your organization's policies.
Limit each account to the files and operations it needs through file and folder permissions. SFTPPlus MFT can use your existing identity provider and supports multi-factor authentication for user and administrator logins. Your team remains responsible for approving access, reviewing permissions, and removing access when it is no longer needed.
Keep an audit trail of connections, authentication attempts, file operations, and administrative changes. SFTPPlus MFT can write events to local log files or send them to external monitoring systems. Configure the events you retain, protect the logs from unauthorized changes, and set retention periods that support your audit needs. Assign someone to review alerts and investigate failures so that recording events leads to action.
Use transfer retries and failure notifications to handle temporary interruptions and alert operators when a transfer needs attention. Cluster deployments can support availability and disaster recovery plans. Your organization still needs to provide suitable storage and network infrastructure, maintain backups, and test recovery procedures.
Agree the system boundary and applicable criteria with your auditor, including the hosting, storage, identity services, and transfer partners on which your workflow depends. Document which controls SFTPPlus MFT implements and which are operated by your team or another provider. Running the software yourself does not remove the need to assess relevant suppliers and dependencies.
Keep configuration records, access review results, relevant audit logs, and evidence of update and recovery testing. These records help demonstrate how your controls are configured and used alongside policies for incident response, staff responsibilities, and data handling.
Our standards documentation describes the supported protocols, cryptographic standards, and guidance for other compliance obligations. If you need help relating a file transfer control to a SFTPPlus MFT feature or configuration option, contact the SFTPPlus team with your requirements.