PGP encryption is one of the most powerful ways to protect sensitive files, and it is at the core of how Diplomat MFT 9.5 secures your information supply chain. Instead of only encrypting the plumbing between two endpoints, PGP encryption protects the file itself. That way, even if a file is intercepted the contents remain unreadable to anyone who doesn’t have the correct decryption key.
If you take a close look at the exploitations that have plagued managed file transfer (MFT) solutions over the last few years, you’ll find a common factor: vulnerabilities in their web administration interfaces. The most striking example occurred in June of 2023 when CVE-2023-34362 was published. That item detailed a critical vulnerability in the MOVEit Transfer web application, which was exploited to devastating effect, resulting in what Tech Crunch described as the “biggest hack of the year.”
Things would get worse from there, with vulnerabilities found and exploited in popular MFT products like GoAnywhere, Aspera, Titan, ShareFile, WingFTP, CrushFTP, Cleo, SolarWinds Serv-U, and Accellion among others. All told the organizations affected by these vulnerabilities would total in the thousands, the privacy of tens of millions of individuals compromised, and billions of dollars lost.
Focused on the Secure in Secure Managed File Transfer
Coviant Software recognized that the security trade-offs that come with offering a web client for administrative access or browser-based file transfers were unacceptable. There’s too much at stake where the transfer of sensitive data is concerned. We’ve always taken the position that we will never sacrifice security on the altar of convenience, and we are steadfast on that commitment. But we aren’t ignorant of the fact that, despite the dismal track record of MFT solutions with browser-based functionality, a lot of organizations still want that familiar interface. Not necessarily for themselves, but because it makes it easy for their information trading partners.
You see, there are many organizations that maintain extensive information supply chains that include smaller entities lacking the resources and expertise to acquire and maintain a robust MFT solution that meets stringent security requirements. This is especially true in an industry like healthcare where a large hospital or healthcare services provider may need to transfer data to and from thousands of different medical practices, labs, service providers, vendors, and other small organizations. That large provider may set rigorous security standards for itself yet face the necessity of accepting the risk of sending and receiving data from partners that lack the resources or expertise to implement more sophisticated security measures.

What is PGP Encryption for File Transfer?
To address this security gap, organizations need a browser-based, PGP encrypted file transfer solution that is easy to use, consistent across partners, and enforced automatically—without placing the burden on those smaller information supply chain partners. That is why, after years of thoughtful design and testing, we have introduced our industry’s most secure browser-based file transfer solution: the Diplomat MFT 9.5 Web Transfer Portal (WTP). The Diplomat MFT 9.5 WTP provides a secure, browser-based experience with PGP encryption for file transfer built in, so every file is encrypted before it leaves the sender and can only be decrypted by the intended recipient.
PGP (Pretty Good Privacy) encryption is built on the OpenPGP encryption standard and uses a public key/private key model to protect data. For managed file transfer, that means you can confidently send highly sensitive data such as patient records, financial statements, or legal documents knowing that the file remains protected in transit and at rest, regardless of where it travels or where it is stored. In simple terms it works like this:
- The sender encrypts a file using the recipient’s public key
- Only the recipient’s private key can decrypt that file
- Optional PGP signatures verify who sent the file and provide non-repudiation
(For a deeper technical overview, visit our PGP Encryption Guide and Choosing PGP or GPG: A Guide to Secure Communication pages.)
Simple, Secure PGP Encryption Automation for Managed File Transfer
Diplomat MFT 9.5 by Coviant Software balances the simplicity of a familiar, drag-and-drop browser interface, but is purpose-built to avoid the security risks that have plagued other products. We did it by streamlining the architecture to include only the functionality required to support browser-based operations while retaining familiar navigation. Users won’t notice the difference, but your information security team will appreciate the improvement. And we didn’t stop there.

Industry-First Automated PGP Encryption for Browser-Based Managed File Transfer
Coviant Software is the first in our industry to figure out how to automate PGP file encryption for browser-based file transfers. We are the only MFT vendor who can make that claim, and the implications for information supply chain security are huge. By automating PGP file encryption in a browser-based format, and with zero effort required on the part of the user, healthcare, financial services, and other enterprises that must receive sensitive information from many smaller entities can standardize their file transfers on PGP encryption without placing a burden on their partners.
Our Diplomat MFT 9.5 Web Transfer Portal eliminates the security-simplicity trade-off that plagues other browser-based products thereby improving information supply chain security while reducing complexity. That makes an organization’s information supply chain security simpler and more efficient while lowering operational costs. It also means greater levels of cooperation and collaboration with both internal and external partners.
Key Features That Support End to End Encrypted File Transfer
When you automate essential security processes, the effect on security is magnified because it ensures security policies are enforced while reducing the risk of human error. Existing users can easily upgrade to Diplomat MFT 9.5 via their customer portal, or with the help of our award-winning technical support team. And remember, when you invest in Diplomat MFT, you not only get the industry’s most secure browser-based file transfer capability and the only one with automated PGP encryption for browser-based file transfers, but you’ll also enjoy a host of other leading security features, including:
- Advanced Threat Intelligence: Support zero trust security initiatives by evaluating requests to connect based on real-time threat intelligence and user-defined rules of engagement.
- Built-In Compliance Tools: Simplified documentation for HIPAA updates and other regulations with SFTP Audit Report and digital supply chain Connection Map.
- Workflow Testing: Validate workflow function and security using Dry Run mode before launch to avoid errors.
- No-Code OneDrive Transfers: Automate file transfer workflows to OneDrive with a simple click.
- Flexible Roles & LDAP: Establish custom permissions and directory integration based on organizational needs.
- Dry-Run Mode: Ensure your MFT workflows operate as intended in a safe test environment before implementation.
- ROI Calculator: See exactly how much your organization saves in time and money when using Diplomat MFT for file transfer workflow automation.
Coviant Software’s Diplomat MFT meets customer expectations for functionality, ease of use, and enterprise-grade scalability without sacrificing security for convenience by offering automated PGP encryption management, authorized recipient/destination confirmation, a robust scheduler with virtually unlimited concurrent job capacity, file transfer process data capture for compliance audit reporting and troubleshooting, and notifications to communication channels of choice (email, text, Slack, Teams, etc.).
Secure Browser-Based MFT Without Compromise
We’re proud that in over twenty years of breach-free performance, Coviant Software’s customers trust us to help maintain compliance with security and privacy regulations like HIPAA/HITECH, PCI-DSS, and GDPR. They also rely on us to securely send, receive, host, and retrieve critical business files with unlimited B2B partners across a wide variety of endpoints, including traditional FTP servers, remote agents, and even email.
Diplomat MFT integrates seamlessly with the business services and applications you already use, including ERP and CRM platforms, and cloud storage services like S3, Azure, SharePoint, Box, Dropbox, and more. And we do it all at an ethical price that is the best value in the industry. Try our secure MFT ROI calculator and compare your existing file transfer solution with Diplomat MFT, then contact us for a free demonstration.
# # #
FAQs on PGP Encryption and End-to-End Encrypted File Transfer
Q: What is end-to-end encrypted file transfer in an MFT solution?
A: End to end encrypted file transfer means files are encrypted before leaving the sender, remain encrypted everywhere they travel or are stored, and are only able to be decrypted by the intended recipient. In an MFT solution like Diplomat MFT 9.5, this is achieved by combining secure file transfer protocols with automated PGP encryption management for file transfer, so sensitive data stays protected at rest and in motion.
Q: Do I still need PGP encryption if I use SFTP or FTPS?
A: Yes. Protocols like SFTP and FTPS encrypt the communication channel, but they do not necessarily protect files once they land on a server or are copied elsewhere. PGP encryption for file transfer adds a second layer of protection by encrypting the file itself, providing defense in depth and helping you satisfy strict security and compliance requirements.
Q: How does Diplomat MFT 9.5 WTP automate PGP encrypted file transfer in the browser?
A: Diplomat MFT 9.5 automates PGP encryption behind a secure, browser-based interface. Users simply upload or download files, while the platform enforces PGP file transfer encryption policies automatically—handling key management, encryption, decryption, and logging without requiring users to run separate tools or scripts.
Q: How is browser-based PGP encryption in Diplomat MFT different from manual PGP workflows?
A: In manual workflows, users must run separate encryption tools, manage keys themselves, and remember the correct steps before every transfer. With Diplomat MFT 9.5, PGP encryption is integrated directly into the MFT environment and the browser experience, so encryption is enforced consistently and automatically every time a file is sent or received.
Q: How does Diplomat MFT 9.5 help with compliance and audit readiness?
A: Diplomat MFT 9.5 combines end-to-end encrypted file transfer with detailed logging, audit reports, and specialized compliance tools such as SFTP audit reports and MFT endpoint connection mapping. This makes it easy to prove that PGP your files were encrypted as required by law, and that encrypted file transfer and secure file transfer processes and protocols are used consistently, in keeping with requirements for HIPAA, DORA, SOX, GLBA, GDPR, and other regulatory framework audits.
