Diplomat MFT: A Secure, Zero-CVE Alternative to Cleo MFT
Switch from Cleo to Diplomat MFT (no Clop ransomware exposure, no failed patches, no professional services required).
Security-First Architecture: Designed with enterprise security as the foundation
Guided Migration Process: Step-by-step migration framework with support to ensure a smooth transition from your current solution.
Proactive Security Model: Regular updates without emergency patching cycles
EASY INTEGRATION
Our customers rely on us to integrate and work with their existing healthcare, accounting, HR, financial, and other business software solutions for their secure file transfer needs. Book a personalized demo or get a quote from one of our MFT experts today!












Cleo MFT vs Diplomat MFT
Why replace Cleo MFT with Diplomat MFT?
Cleo MFT is a managed file transfer platform developed by Cleo, primarily positioned around B2B integration and supply chain data exchange. It supports a wide range of protocols and trading partner connectivity, and is used by mid-to-large enterprises across manufacturing, logistics, retail, and healthcare. However, Cleo’s headline feature set comes with a headline security problem that fundamentally changed how organizations assess MFT vendor risk at the end of 2024.
In October 2024, Cleo disclosed CVE-2024-50623, a critical CVSS 10 unrestricted file upload vulnerability affecting Cleo MFT, VLTrader, and LexiCom. A patch was issued, but it failed. In December 2024 the Clop ransomware group, the same group behind the MOVEit and GoAnywhere mass-breaches exploited the unpatched systems, leading to a second CVE (CVE-2024-55956, CVSS 9.8) being added to CISA’s Known Exploited Vulnerabilities catalogue. Over 4,200 Cleo customers were at risk, and organizations that had already patched believed they were protected. They were not.
Diplomat MFT offers a fundamentally different risk profile: 20+ years of operation with zero CVEs, transparent pricing from $1,149/year, and no professional services engagement required to get started. Rather than relying on a vendor whose patch cycle failed under active ransomware exploitation, organizations choose Diplomat MFT for its proven security track record, predictable costs, and direct access to the engineering team who built it.
Compare Diplomat MFT with Cleo MFT
Diplomat MFT offers these advantages over Cleo MFT *
| FILE TRANSFER SERVER | DIPLOMAT MFT ENTERPRISE | CLEO MFT |
|---|---|---|
| Users, Groups, Virtual File System | ✅ | ✅ |
| User IP Whitelisting | ✅ | ✅ |
| File Retention Policies | ✅ | ✅ |
| Folder Automation Events | ✅ | ✅ |
| Logging, Auditing & Reporting | ✅ | ✅ |
| 24/7 Severity 1 Support Availability | ✅ | ✅ (enterprise tier) |
| Edge Gateway (Included) | ✅ | ✅ (DMZ proxy, requires separate configuration) |
| OpenPGP File Encryption and Decryption | ✅ | ✅ |
| Auto-Rotating PGP Subkeys | ✅ | ❌ |
| High Watermark File Detection | ✅ | ❌ |
| Cloud Storage Integration | ✅ | ✅ |
| Job Monitor Visibility | ✅ | ✅ |
| Sync and Replication | ✅ | ✅ |
| Published Transparent Pricing | ✅ | ❌ (Contact for quote, professional services required) |
| Typical Implementation Time | Weeks | Months (professional services engagement required) |
| Zero CVEs (22-Year Track Record) | ✅ | ❌ (CVE-2024-50623 & CVE-2024-55956, both CVSS 10/9.8, exploited by Clop ransomware Dec 2024, added to CISA KEV catalog) |
*Research based on publicly available information as of January 2026. CVE-2024-50623 and CVE-2024-55956 affected Cleo MFT, VLTrader, and LexiCom. Both CVEs were added to CISA’s Known Exploited Vulnerabilities catalogue and exploited by the Clop ransomware group in December 2024 prior to a full patch being available.
Diplomat MFT Security & Migration ROI Calculator
Calculate your cybersecurity risk exposure using IBM breach cost research and configurable probability assumptions. Compare migration costs vs. breach impact with full transparency.Your ROI Analysis
Based on your inputs and industry dataANNUAL RISK EXPOSURE
YEAR 1 MIGRATION COST
3-YEAR NET BENEFIT
📐 How We Calculate This
Breach Cost: From IBM Cost of a Data Breach Report 2024 ($4.88M average; $9.77M healthcare). Breach Probability: Heuristic estimates based on common exposure patterns—these are not published research figures. Use "Advanced Options" to input your own rates if known. Net Benefit: 3-year risk reduction + labor savings − total 3-year cost (Year 1 + 2 renewal years).Current State vs. Post-Migration
| Metric | Current State | Post-Migration |
|---|---|---|
| Annual Breach Risk | - | - |
| Weekly Admin Hours | - | - |
| Compliance Automation | - | Automated |
| Vendor Support | - | Highly rated on G2 (as of Jan 2026) |
See What Diplomat MFT Can Do For Your Organization
You've seen the potential risk reduction and cost savings—now take the next step.
Diplomat MFT gives you enterprise-grade security, complete visibility, and powerful automation—without the complexity and vulnerabilities of legacy systems.
Ready to protect your data and reclaim your IT team's time?
MFT Migration Service:
Here’s an Overview of How It Works
Our MFT Migration Service provides a structured approach to help you seamlessly transition from your existing file transfer solution to Diplomat MFT. Many of the world’s largest organizations in industries like healthcare, financial services, retail, and more trust Coviant Software with their most sensitive file transfers. You can, too.
Step 1: Initial Discussion
In a 1–2-hour virtual session, our MFT experts meet with your team to understand your current file transfer setup. We identify which file transfer workflows should be migrated, and how you can do it easily and effectively.
Step 2: Deliver Tailored Migration Plan
We review what we’ve learned and prepare a clear, actionable Statement of Work (SOW)—outlining timeframes, required resources, and what you can expect.
Step 3: Review & Decide
You evaluate the SOW at your own pace. Need more clarity? We’re happy to consult further—at no cost.
Step 4: Fast, Professional Delivery
Once approved, we can quickly start assisting with your migration. We keep in close contact throughout the process, with regular updates and zero guesswork.
Step 5: Final Review & Sign-Off
We walk through the results with you to ensure everything meets expectations. Only when you’re satisfied do we consider the job done.
If you have questions, please reach out to schedule a discussion and quick demonstration of Diplomat MFT. Or you can take Diplomat MFT for a free 15-day test drive with no obligations.
Understanding the capabilities and considerations of Cleo MFT
Cleo MFT is a comprehensive file transfer and integration platform designed for organizations managing complex B2B and supply chain data exchange. It supports a wide range of protocols including SFTP, FTPS, AS2, HTTPS, and OFTP2, and is widely used across manufacturing, logistics, retail, and healthcare.
The platform is built to handle complex partner ecosystems, offering advanced routing, transformation, and trading partner management capabilities. This makes it a strong choice for organizations that need both managed file transfer and integration in a single solution.
However, the breadth of functionality introduces architectural complexity and increases the overall attack surface. Recent security incidents have led many organizations to reevaluate whether the combination of feature depth, exposure risk, and operational overhead aligns with their security posture and governance requirements.
As a result, Cleo is often evaluated not just on capability but on how securely and efficiently those capabilities can be operated at scale.
Employs SFTP and OpenPGP encryption for highest security
Calendar exclusions prevent transfers on bank holidays
Reducing risk of human error by automating transfers
Robust scheduler for easy configuration of transfer times
Full audit trails, file archiving, and notifications
Integrates with various protocols (SFTP, FTPS, AS2, HTTPS)
What does “Enterprise” file transfer really mean?
The term “enterprise” implies a product has the features, capacity, and job management capabilities to handle the demands of the largest organizations. With managed file transfer software, that means automating the largest file transfers to an extensive digital supply chain, doing it securely and reliably, and keeping pace no matter how your needs expand. It also means including enterprise-class features such as full auditing, alerting, data archiving and retention, directory management integration, PGP encryption management, and 24×7 support. We’ve helped a lot of organizations that found Cleo MFT fell short of those expectations. And so, if you’re looking for an alternative to Cleo MFT and need an MFT solution that has been proven in the most demanding enterprise environments—and is ready for more—take a look at Diplomat MFT. You’ll be glad you did.
What's new in Diplomat MFT?
Key Diplomat MFT enhancements include:
Secure, Browser-Based File Transfers: Allows your partners to simply use a standard web browser. Just send a URL and login credentials. No third-party tools, no software, no training needed.
Automated PGP Browser-Based File Transfers: Mandate PGP policy across your entire information supply chain, removing complexity and enhancing security.
Threat Intelligence: Real-time blocking of malicious IP addresses with automated threat detection to prevent intrusions and advanced persistent threats.
IP Access Rules: Granular control to block high-risk IP addresses, ensuring only trusted users and networks have access.
PGP Enforcement Rules: Automatically removes files that aren't PGP encrypted, preventing exposure of sensitive information and ensuring data protection compliance.
SFTP Connections Report: Complete visibility into file access for compliance audits and security monitoring with full transparency.
Syslog Logging: Centralized monitoring of all system logins to identify suspicious activity across the entire network.
Zoho WorkDrive Transport Type: Easy integration and automated file transfers to Zoho WorkDrive, reducing manual work and errors.
Expanded RegEx: More flexibility in organizing file names and file types, reducing manual sorting and errors.
Connection Map Report: Visual documentation of data flow for compliance (HIPAA, etc.) showing connections between systems made by Diplomat MFT.
Granular Permissions and Custom Roles: Fine-tuned access control for improved security and regulatory compliance with role-based security.
Support for SSO (Single Sign-On) for Administrators: Simplifies administrator login, centralizes user management, and reduces administrative overhead.
If you have questions, please reach out to schedule a discussion and quick demonstration of Diplomat MFT. Or you can take Diplomat MFT for a free 15-day test drive with no obligations.
Years of experience
Individual transfers per day
Terabytes transferred per day
Concurrent jobs
Years of experience
Individual transfers per day
Terabytes transferred per day
Concurrent jobs
Choose from 3 Editions
We have three editions of Diplomat MFT to suit varying business requirements and budgets.
Standard
Billed annually $3,999
Not available on Standard. Optional add-on with Professional, included in Enterprise. Encrypts every browser upload before it leaves the partner’s machine.
Not available on this plan- Edge Gateway Network-edge component that handles inbound transfers safely without exposing internal systems to the public internet.
- SFTP server
- Web Transfer Portal Browser-based upload/download interface for ad-hoc transfers by external users — useful for partners who don’t use SFTP. PGP encryption for Web Transfer is available as an add-on on Professional and included on Enterprise.
- Up to 25 automated workflows Called “transactions” in Diplomat MFT — defined transfer jobs such as nightly ERP exports, partner SFTP feeds or cloud sync workflows. Each is one transaction regardless of how many files it moves.
- Up to 5 File Transfer Server accounts Called “transfer server users” in Diplomat MFT — external accounts that authenticate to your SFTP or Web Transfer server. Typically the partners and customers sending files to you.
- Up to 5 keys per type Cryptographic keys for PGP, SSH and SSL — each type has its own slot count.
Professional
Billed annually $8,499
Every browser upload encrypted at the partner’s browser, before it leaves their machine. No Kleopatra, no key management, no partner training. Just compliance enforced where it matters.
Add-on · $2,999/year- Everything in Standard, plus:
- 1 Remote Agent included Lightweight component installed at remote sites (offices, stores, customer environments) to securely move files back to the central Diplomat MFT instance.
- 1 Cloud Storage Connector included Connects Diplomat MFT directly to cloud storage such as S3, Azure Blob, SharePoint Online, Google Cloud Storage and others (without custom scripting).
- Up to 100 automated workflows Called “transactions” in Diplomat MFT — defined transfer jobs such as nightly ERP exports, partner SFTP feeds or cloud sync workflows. Each is one transaction regardless of how many files it moves.
- Up to 25 keys per type Cryptographic keys for PGP, SSH and SSL, with each type having its own slot count. Professional gives you up to 25 of each, a deciding factor for teams scaling beyond basic partner exchanges.
- Up to 25 File Transfer Server accounts Called “transfer server users” in Diplomat MFT — external accounts that authenticate to your SFTP or Web Transfer server. Typically the partners and customers sending files to you.
- Up to 3 admin accounts with concurrent access support Three administrator accounts on Professional, with all three able to be signed in to the web admin at the same time. Standard supports one admin only. Enterprise has unlimited admin accounts with concurrent access.
- Defined Partners Reusable partner profiles bundling endpoints, credentials and routing rules — set up once, reuse across many transactions.
- Synchronization
- Calendaring, file monitoring, advanced source options
Enterprise
Billed annually $12,999
Every browser upload encrypted at the partner’s browser, before it leaves their machine. No Kleopatra, no key management, no partner training. Just compliance enforced where it matters.
IncludedWhat's included
Critical Outage (P1) response for all hours outside the Premium Support coverage. Coviant Software designates multiple senior team members highly qualified to provide in-depth technical support to serve as on-call contacts for these critical outage responses around the clock on every day of the year, with authority to draft in additional resources if required.
- Everything in Professional, plus:
- 5 Remote Agents included Lightweight components installed at remote sites (offices, stores, customer environments) to securely move files back to the central Diplomat MFT instance.
- 5 Cloud Storage Connectors included Connects Diplomat MFT directly to cloud storage such as S3, Azure Blob, SharePoint Online, Google Cloud Storage and others (without custom scripting).
- PGP for Web Transfer included Automatic PGP encryption applied to files uploaded through the Web Transfer Portal. Partners upload through the browser, and files are encrypted before they touch your storage. Available as an add-on on Professional, included on Enterprise.
- Proactive Threat Intelligence included Proactive Threat Intelligence blocks file transfer attempts from known-bad sources before they reach your environment, using continuously updated reputation feeds. Not an intrusion-detection or scanning product; the protection is at the connection layer.
- Advanced Authentication (SSO + LDAP + TOTP) included Single Sign-On (SSO) via SAML, LDAP authentication, and web admin TOTP two-factor authentication, bundled. Authenticate users through Okta, Azure AD, Google Workspace or directly against your LDAP directory. All are included on Enterprise.
- Unlimited workflows, users, keys Workflows are called “transactions” in Diplomat MFT. Defined transfer jobs such as nightly ERP exports, partner SFTP feeds or cloud sync workflows. Enterprise removes the cap entirely.
- RBAC, webhook invocation, multiple destinations Role-Based Access Control — granular permissions controlling what each administrator can see and do.
- Pre/Post-job processes
- 24×7 Critical Outage Response
- Paging notifications
Try Diplomat MFT for yourself
Every evaluation is different. That's why we build yours around your requirements — not a one-size-fits-all process.
Share your requirements with us
Every organization has unique file transfer challenges. In a short call, our team will learn about your specific protocols, endpoints, compliance needs and integrations — so we can shape your entire evaluation around what matters most to you.Watch a tailored demonstration
No generic walkthroughs. We'll demonstrate Diplomat MFT configured to your environment and workflows, so you can see exactly how it addresses your requirements before you invest any time in setup.Start your trial and evaluate with expert guidance
We cut the learning curve. Our team helps you install and configure a full-featured trial tailored to your requirements — so you spend your time validating, not troubleshooting. Your trial is time-limited, not function-limited.Decide with confidence
Once your evaluation is complete, we'll review the results together against your original requirements. You'll have everything you need to make an informed decision — with no obligation to purchase.FREQUENTLY ASKED QUESTIONS
What is the best alternative to Cleo MFT?
The best alternative to Cleo MFT is a security-first managed file transfer platform like Diplomat MFT, designed to reduce attack surface, simplify automation, and provide full operational visibility without additional modules.
Cleo MFT is often used for EDI and integration-heavy environments, but many organisations look for alternatives when file transfer becomes business-critical and security or operational complexity becomes a concern.
Key reasons buyers switch from Cleo include:
- Security concerns following recent vulnerabilities and exploits
- Additional licensing for core components like gateways
- Complexity across multiple products (MFT, VLTrader, LexiCom)
- Limited native automation compared to modern MFT platforms
An alternative MFT platform should consolidate these into a single, secure system with built-in automation, auditing, and deployment flexibility.
What are the key differences between Cleo MFT and modern MFT platforms?
The main differences between Cleo MFT and modern MFT platforms come down to architecture, security model, and operational complexity.
Cleo MFT:
- Often deployed as part of a broader integration stack
- Requires additional components (e.g. gateway, separate products)
- Historically exposed to critical vulnerabilities requiring urgent patching
- Designed for flexibility, but often at the cost of complexity
Modern MFT platforms:
- Built as file transfer infrastructure, not an add-on
- Include secure gateway/DMZ architecture by default
- Provide native workflow automation without scripting
- Centralise logging, auditing, and alerting
For organisations prioritising security and simplicity, this difference becomes material — especially in regulated environments.
What security issues have affected Cleo MFT, and why do they matter?
In October 2024, Cleo disclosed a critical vulnerability (CVE-2024-50623, CVSS 10) involving unrestricted file upload. Although a patch was released, it failed to fully mitigate the issue.
In December 2024, the Clop ransomware group exploited the vulnerability across both patched and unpatched systems, leading to:
- A second vulnerability (CVE-2024-55956, CVSS 9.8)
- Inclusion in CISA’s Known Exploited Vulnerabilities (KEV) catalogue
- Over 4,000 organisations potentially affected
This matters because MFT systems sit at a high-risk intersection: external access + sensitive data + internal systems.
The takeaway for buyers is not just that a vulnerability existed — but that:
- It was actively exploited
- Patching did not fully protect systems
- The attack surface was large enough to scale
Security evaluation should focus on architecture (exposure, isolation), not just patching responsiveness.
Is Cleo MFT secure enough for enterprise use today?
Cleo MFT can be secured, but doing so often depends on configuration, patch management, and additional architectural controls rather than secure-by-default design.
Enterprise-grade MFT security typically requires:
- DMZ isolation between internet-facing and internal systems
- Minimal exposure of management services
- Strong validation of session and file handling
- Continuous monitoring and auditability
Where organisations become concerned is when:
- Security depends heavily on correct configuration
- Core protections require additional components or licensing
- Recent vulnerabilities demonstrate real-world exploitability
Many organisations evaluating alternatives are not just asking “can it be secured?” but “is it secure by design?”
That distinction is what drives switching decisions.
How difficult is it to migrate from Cleo MFT to another platform?
Migrating from Cleo MFT is typically manageable, especially for organisations already running structured file transfer workflows, endpoints, and schedules.
A standard migration includes:
- Mapping trading partners, endpoints, and protocols
- Rebuilding workflows using native automation tools
- Reconfiguring authentication, encryption, and routing rules
- Consolidating multiple Cleo components into a single platform
In many cases, migration reduces complexity because:
- Multiple products (e.g. VLTrader, LexiCom) are consolidated
- External scripts or workarounds are eliminated
- Monitoring and alerting become centralized
For organisations concerned about disruption, most migrations are phased — running Cleo and the new platform in parallel until validation is complete.
We've invested in Cleo MFT automation workflows. How difficult is migration?
Cleo MFT’s automation capabilities are more limited than enterprise MFT platforms — Gartner’s MFT Market Snapshot 2021 didn’t include Cleo MFT, and analysts have noted it lacks the workflow automation that defines true managed file transfer. Many Cleo MFT users end up creating Windows scheduled tasks with external scripts because the built-in event system is too constrained.
Migration to Diplomat MFT typically involves mapping your source and destination endpoints, schedules, file patterns, encryption settings, and notifications. If you’re already using external scripts for automation, those same scripts can integrate with Diplomat MFT’s trigger system or be replaced by native functionality. Organizations often discover during migration audits that they have redundant or unused transfer processes — the City of Los Angeles found this when migrating from GoAnywhere, turning migration into an opportunity to clean house. Diplomat MFT’s interface was designed for IT professionals; the learning curve is minimal for anyone familiar with enterprise administration.
WHAT OUR CUSTOMERS SAY
G2 is the largest and most trusted software marketplace. More than 90 million people annually—including employees at all Fortune 500 companies—use G2 to make smarter software decisions based on authentic peer reviews.

Scott J.
Diplomat MFT has been a powerful workhorse for all of our enterprise file exchange for many years. No other enterprise application we use comes with the same level of support we receive from Coviant.

Eric D.
Director of Information Technology
The support is fantastic. I had to contact them on a few occasions – as it turns out, not for issues with Diplomat MFT but issues with one of the FTP partners. Coviant support stuck with me and went above and beyond to troubleshoot and figure out the issue.

Dave L.
Manager of Information & Technology
Diplomat MFT is a solid data transfer product, its easy to set up, and easy to use. I like the way the transaction builder is laid out. It’s so easy to understand what values it wants.

Adah B.
Extremely robust platform for managing our enterprise file transactions. Every upgrade provides us with additional useful tools to streamline our business processes.

Stephen H.
IT BI Analyst SE
I find the sftp file transfers to be the most helpful tool of Diplomat MFT. No need for programming, the interface is customized already and users only need to fill in the boxes.

Jeff M.
The interface and GUI are very straightforward. The options are simple and labeled so anyone can understand how to set up and configure. The ability to test something without actually sending something is also beneficial.

