For Organizations · PGP Encryption Built Into Diplomat MFT
Modern File Transfer for Modern Business Operations
Send Files to Anywhere From Anywhere
Our customers rely on us to integrate and work with their existing healthcare, accounting, HR, financial, and other business software solutions for their secure file transfer needs. Book a personalized demo or get a quote from one of our MFT experts today!
PGP Web
Interface
Threat Intelligence & IP Protection
SFTP Connections Reporting
PGP Enforcement Rules
Enhanced Integration & Automation
Managed File Transfer Software for Secure B2B and Hybrid Data Exchange
Diplomat MFT helps organizations eliminate manual processes, fragmented tools, and custom scripts by centralizing secure file transfers across cloud, on-premises, and trading partner environments. Automate SFTP, FTPS, HTTPS, AS2, and PGP-encrypted workflows from a single platform with complete visibility and control.
Eliminate File Transfer Complexity Across Hybrid Environments
FILE TRANSFER AUTOMATION
Multi-Step Automation Without Custom Scripting
Build powerful, event-driven workflows using Diplomat MFT’s no-code workflow builder. Chain file arrival, decryption, validation, transformation, and delivery into a single reliable automated pipeline.
Event-driven triggers: Start workflows on file arrival, schedule, or external API event
Multi-protocol delivery: Route files via SFTP, FTPS, HTTPS, AS2, S3, Azure Blob and more
Inline PGP handling: Decrypt, process, re-encrypt and forward in a single workflow
Retry & error handling: Automatic retries, failure alerts, and configurable fallback routing
Edge Gateway & SFTP Server
Secure Perimeter. Accept External Transfers Without Exposing Your Network.
Deploy Diplomat MFT’s Edge Gateway to accept incoming transfers in your DMZ. The built-in SFTP Server gives trading partners a single, secure connection point across all environments.
DMZ deployment: Accept external transfers without exposing internal systems
Built-in SFTP server: Host your own endpoint, no third-party server required
Hybrid-ready: Bridge on-premises, private cloud, and public cloud environments
Zero Trust architecture: Every connection authenticated and authorised before network traversal
Unified Security
Enterprise-grade security built into every transfer. Web Transfer Client, Threat Intelligence, and IP Access Controls work together to protect your entire data supply chain without heavyweight infrastructure.
Web Transfer PORTAL
Browser-Based Secure File Exchange (No Client Install Required)
Empower internal teams and external trading partners with a secure, browser-based file transfer portal. Because PGP enforcement and audit visibility are built in from the start, there is no software to install and no added complexity.
No agent install: Partners connect securely via browser using existing SFTP/FTPS credentials
Branded portal: Customisable interface for a professional B2B partner experience
PGP enforcement: Automatically apply encryption policy to all browser-based uploads and downloads
Full audit trail: Every session, file, and action logged and timestamped for compliance
How partners send you files securely, in five steps
No SFTP client. No VPN. No training. Just a browser, and automatic PGP encryption the moment a file lands.
Threat Intelligence
Proactive Threat Detection at the Transfer Layer
Diplomat MFT automatically blocks connections from known malicious IP ranges before any data exchange occurs. Live threat feeds update continuously ensuring your environment stays protected without manual intervention.
Real-time threat feeds: Live IP reputation data blocks risky connections at the transfer layer automatically
Partner security scoring: Assess and score SFTP partner posture across your ecosystem
Zero manual overhead: Threat database updates run silently in the background
Audit-ready logs: Every blocked attempt recorded with full timestamp and context
IP Access Rules
Granular Network Access Control. Zero Trust at the Transfer Layer.
Define precise allow/deny rules at the IP, CIDR range, or hostname level. Enforce Zero Trust principles at the transfer perimeter so only permitted sources can initiate or receive transfers.
Allow/deny lists: Whitelist partner IPs and block all other inbound connections
CIDR range support: Apply policies to full network ranges with a single rule entry
Per-user policies: Apply different access rules by user account or group
Full visibility: All allowed and blocked attempts logged in real time for audit
Automatic PGP Encryption, Built Into Every Workflow
Diplomat MFT enforces OpenPGP encryption automatically, in transit and at rest, with no manual key handling and no opportunity for user error. Watch how policy-enforced PGP works across workflows, browser uploads, and key management.
Compliance
Compliance Made Simple
The technical safeguards to satisfy HIPAA, PCI DSS, GDPR, GLBA, DORA and more. One-click reporting, automated audit trails, and visual data flow documentation remove the compliance burden from your team.
Real-time visual map of every connection and data flow across your MFT environment. Understand who is sending what, where, and when, without digging through log files.
- Visual topology of all active trading partner connections
- Drill into any node for full transfer history
- One-click export for audit evidence packages
Automatically generate detailed SFTP audit reports documenting every file transfer in your supply chain. Pre-formatted, timestamped evidence ready for auditors, in one click.
- Per-partner transfer history with full metadata
- Pre-formatted for HIPAA and PCI DSS audit packages
- Scheduled reports delivered automatically to stakeholders
Automatically apply PGP encryption policy to every file transfer. No manual key handling, no client software required, policy-enforced encryption from day one.
- Automatic PGP encryption on all browser-based uploads
- Enforce encryption rules without user intervention
- Full key management and audit trail built in
Validate every transfer job before it runs in production. Dry Run simulates the full execution path, catching misconfigurations and connection failures before data moves.
- Simulate transfer jobs without moving live files
- Identify connectivity and permission errors early
- Confidence-check automations before go-live



Standard
A complete secure file transfer platform. For IT teams that don’t need enterprise-scale automation.
Billed annually $3,999
Not available on Standard. Optional add-on with Professional, included in Enterprise. Encrypts every browser upload before it leaves the partner’s machine.
Not available on this plan- Edge Gateway Network-edge component that handles inbound transfers safely without exposing internal systems to the public internet.
- SFTP server
- Web Transfer Portal Browser-based upload/download interface for ad-hoc transfers by external users — useful for partners who don’t use SFTP. PGP encryption for Web Transfer is available as an add-on on Professional and included on Enterprise.
- Up to 25 automated workflows Called “transactions” in Diplomat MFT — defined transfer jobs such as nightly ERP exports, partner SFTP feeds or cloud sync workflows. Each is one transaction regardless of how many files it moves.
- Up to 5 File Transfer Server accounts Called “transfer server users” in Diplomat MFT — external accounts that authenticate to your SFTP or Web Transfer server. Typically the partners and customers sending files to you.
- Up to 5 keys per type Cryptographic keys for PGP, SSH and SSL — each type has its own slot count.
Professional
For growing teams that need automation, partner integration and admin controls.
Billed annually $8,499
Every browser upload encrypted at the partner’s browser, before it leaves their machine. No Kleopatra, no key management, no partner training. Just compliance enforced where it matters.
Add-on · $2,999/year- Everything in Standard, plus:
- 1 Remote Agent included Lightweight component installed at remote sites (offices, stores, customer environments) to securely move files back to the central Diplomat MFT instance.
- 1 Cloud Storage Connector included Connects Diplomat MFT directly to cloud storage such as S3, Azure Blob, SharePoint Online, Google Cloud Storage and others (without custom scripting).
- Up to 100 automated workflows Called “transactions” in Diplomat MFT — defined transfer jobs such as nightly ERP exports, partner SFTP feeds or cloud sync workflows. Each is one transaction regardless of how many files it moves.
- Up to 25 keys per type Cryptographic keys for PGP, SSH and SSL, with each type having its own slot count. Professional gives you up to 25 of each, a deciding factor for teams scaling beyond basic partner exchanges.
- Up to 25 File Transfer Server accounts Called “transfer server users” in Diplomat MFT — external accounts that authenticate to your SFTP or Web Transfer server. Typically the partners and customers sending files to you.
- Up to 3 admin accounts with concurrent access support Three administrator accounts on Professional, with all three able to be signed in to the web admin at the same time. Standard supports one admin only. Enterprise has unlimited admin accounts with concurrent access.
- Defined Partners Reusable partner profiles bundling endpoints, credentials and routing rules — set up once, reuse across many transactions.
- Synchronization
- Calendaring, file monitoring, advanced source options
Enterprise
For mission-critical operations that need everything, with no limits.
Billed annually $12,999
Every browser upload encrypted at the partner’s browser, before it leaves their machine. No Kleopatra, no key management, no partner training. Just compliance enforced where it matters.
IncludedWhat's included
Critical Outage (P1) response for all hours outside the Premium Support coverage. Coviant Software designates multiple senior team members highly qualified to provide in-depth technical support to serve as on-call contacts for these critical outage responses around the clock on every day of the year, with authority to draft in additional resources if required.
- Everything in Professional, plus:
- 5 Remote Agents included Lightweight components installed at remote sites (offices, stores, customer environments) to securely move files back to the central Diplomat MFT instance.
- 5 Cloud Storage Connectors included Connects Diplomat MFT directly to cloud storage such as S3, Azure Blob, SharePoint Online, Google Cloud Storage and others (without custom scripting).
- PGP for Web Transfer included Automatic PGP encryption applied to files uploaded through the Web Transfer Portal. Partners upload through the browser, and files are encrypted before they touch your storage. Available as an add-on on Professional, included on Enterprise.
- Proactive Threat Intelligence included Proactive Threat Intelligence blocks file transfer attempts from known-bad sources before they reach your environment, using continuously updated reputation feeds. Not an intrusion-detection or scanning product; the protection is at the connection layer.
- Advanced Authentication (SSO + LDAP + TOTP) included Single Sign-On (SSO) via SAML, LDAP authentication, and web admin TOTP two-factor authentication, bundled. Authenticate users through Okta, Azure AD, Google Workspace or directly against your LDAP directory. All are included on Enterprise.
- Unlimited workflows, users, keys Workflows are called “transactions” in Diplomat MFT. Defined transfer jobs such as nightly ERP exports, partner SFTP feeds or cloud sync workflows. Enterprise removes the cap entirely.
- RBAC, webhook invocation, multiple destinations Role-Based Access Control — granular permissions controlling what each administrator can see and do.
- Pre/Post-job processes
- 24×7 Critical Outage Response
- Paging notifications
Tools, Calculators & Resources
Validate your investment case, benchmark your current setup, and explore how Diplomat MFT compares, before you pick up the phone.
Diplomat MFT FAQs
Gradually. The most successful migrations replace one workflow at a time rather than everything at once.
Legacy transfer setups are a little like dozens of handwritten instructions taped around a factory: the Windows Scheduled Tasks, PowerShell and batch scripts, and FTP jobs may have worked for years, but nobody remembers who wrote them, whether they are still correct, or what breaks if one disappears. They also share structural weaknesses: passwords stored inside scripts, unencrypted FTP connections, failed transfers nobody notices, and no audit trail when someone asks what happened.
Common migration mistakes worth avoiding: migrating everything simultaneously, leaving the old FTP server running indefinitely "just in case", forgetting scheduled jobs that only run monthly or quarterly, not rotating the credentials that lived in scripts, and not documenting trading partner connections before switching them.
Because Diplomat MFT runs modernized and legacy workflows side by side during transition, partners never notice the cutover, and each migrated workflow immediately gains encryption, retries, alerting, and logging. The outcome is transfers that stop depending on whoever wrote the original scripts.
Yes. Organizations move between MFT platforms regularly, usually because of licensing changes, vendor consolidation, cloud adoption, support quality, or a platform that has grown more complex and expensive than the job requires.
A successful migration preserves business processes, not just software. Teams moving from MOVEit or GoAnywhere typically review their automated workflows, trading partner connections, PGP keys and certificates, scheduling rules, and audit requirements, then map each across. In practice most environments translate cleanly, and the project becomes an opportunity to retire workflows nobody uses and simplify the ones everybody depends on.
How much help you want is your call. Coviant's engineers can run the migration for you, train your team to run it themselves, or stay on hand while you do it your own way. Whichever route you take you are working with the same engineers, because the riskiest part of any migration is the part of the old system nobody documented.
The best MFT platform is not the one with the longest feature list; it is the one that fits your security, operational, and compliance requirements at a cost you can predict. If you are evaluating MOVEit, GoAnywhere, Cerberus FTP, Globalscape EFT, or another enterprise file transfer solution, a structured comparison looks at five areas.
Security: encryption in transit and at rest, PGP key management, modern authentication, and the protocols your partners actually require. Automation: scheduling, event triggers, automatic retries, and alerts that tell you something failed before your partner does. Visibility: audit trails and reporting that answer an auditor's questions in minutes rather than days. Scalability: cloud storage support, hybrid deployment, and room for a growing partner network. Total cost of ownership: look past the license price to add-on modules, per-connector fees, implementation effort, and support quality, because the sticker price is rarely the real price.
Then do what experienced buyers do: check independent review platforms such as G2 and SoftwareReviews, where verified users score vendors on the things demos hide, and validate your shortlist against real workflows in a free trial. The MFT Business Case Builder turns the comparison into numbers your leadership team can review.
Diplomat MFT comes in three editions: Standard, Professional, and Enterprise. All three run the same core platform; what changes is capacity and capability, including how many File Transfer Server accounts and encryption keys you can manage and how many Cloud Storage Connectors are included.
Standard suits teams automating their first secure workflows, Professional adds the capacity most mid-sized environments need, and Enterprise removes the ceilings for large partner networks. Because pricing is published openly, you can map your requirements to an edition before ever talking to sales. See what each edition includes on the pricing page.
The Web Transfer Portal is a browser-based interface for exchanging files with people who do not have SFTP software. Partners visit your branded portal URL, sign in with their existing credentials, and upload or download directly in the browser, with nothing to install and no VPN to configure.
Permissions mirror your SFTP server exactly, so partners see only the folders you have granted, and files are PGP encrypted automatically as they are uploaded, if the feature is enabled. Every exchange is logged in the same audit trail as the rest of your transfers, so browser convenience never means a visibility gap. Explore the Web Transfer Portal in detail.
Diplomat MFT includes its own enterprise SFTP server, so there is no third-party server to license, patch, or maintain. It gives trading partners a single, secure connection point across your environments.
For organizations that need to accept external transfers without exposing internal systems, the Edge Gateway deploys in your DMZ and brokers inbound connections, supporting a Zero Trust posture where every connection is authenticated and authorized before it traverses your network. See the SFTP server page for details.
Diplomat MFT triggers transfers two ways: on a schedule, from simple intervals to precise calendar rules, and on events, such as a file arriving in a monitored location. Event-driven workflows start the moment work exists rather than waiting for the next polling window.
Each workflow chains the steps around the transfer itself, such as encryption or decryption and delivery to multiple destinations, so the whole pipeline runs unattended. The practical outcome is that files move when they should without anyone remembering to run anything.
Failed transfers retry automatically according to rules you set, and alerting notifies your team the moment something needs attention, so you find out before your trading partner does.
Every attempt, success or failure, is recorded in the audit trail with what moved, when, and where it was going. That combination, automatic retries plus proactive alerts plus a complete record, is the difference between managed file transfer and a script that failed silently overnight.
Yes. Diplomat MFT has a 15-day free trial with no credit card required, and the most reliable way to evaluate MFT software is to run your real workflows on it rather than watching a demo.
During the trial you can configure actual partner connections, PGP keys, and schedules, and if you want help along the way you talk to an MFT engineer, not a sales script. Start the free trial.
Start by reviewing how each partner actually connects, because partner connections age quietly. Configurations set up years ago persist unchanged: older protocols still enabled, encryption keys past their intended lifetime, weak cipher settings, and active accounts for partners you stopped trading with.
These weaknesses are nearly impossible to spot while transfer activity is spread across scripts, servers, and individual inboxes, and they matter because auditors and attackers both look for exactly these gaps, and one of them will find yours first. Centralizing transfers on a managed file transfer platform puts every partner connection, security setting, and transfer record in one place, so IT and security teams can strengthen encryption partner by partner, retire outdated protocols, and remove dormant accounts on evidence rather than guesswork. Diplomat MFT provides this visibility as standard, turning partner security reviews from an annual scramble into routine housekeeping.
What is your next step?
No forms, no gatekeeping. Pick the path that matches where you are.















