Skip to main content

Configuring Files.com For Maximum Security

For the highest level of security on your Files.com site, follow the recommendations below.

To prevent accidental transfers of files on your account using insecure FTP, do not enable Plain/unencrypted FTP support.

Do not allow connections with insecure ciphers via the HTTPS, FTPS, and SFTP ciphers setting.

Set strong password requirements for your users.

Do not add IP whitelisting or country restrictions as general hardening measures. Both block legitimate users far more often than attackers, and we do not recommend either one unless a compliance regime explicitly requires it.

Set the retention period with the Keep deleted files for setting as low as possible to minimize the amount of your data we retain as backups. For maximum security, set this value to no higher than 30 days. Many of our customers enter lower values such as 7 days or even 0 days.

Implement and enforce the use of two-factor authentication (2FA) for all user accounts.

Implement and enforce the use of SSH/SFTP Keys for SFTP instead of using a password.

Enable Malware Scanning on the folders that receive files from outside your organization, including the folder behind an Inbox or an upload-enabled Share Link. Nothing else on your site inspects those files.

Scanning covers new uploads into the folder you protect and every folder beneath it. It does not cover files already in the folder or files moved or copied in, so protect the folder where files are actually uploaded, not a folder an Automation or a move delivers them to afterward.

FedRAMP Security Mode

The recommendations above rely on administrators keeping each setting where it belongs. FedRAMP Security Mode enforces a subset of them instead. It sets the values FedRAMP requires and locks them, so no site administrator can relax them while the mode is enabled.

The mode covers insecure FTP, legacy SFTP ciphers, weak Diffie-Hellman parameters, per-user FTP SSL overrides, SMS two-factor authentication, and US-only data routing. All other settings stay under your control, so the recommendations above apply alongside the mode.

BAA and HIPAA

If you have a HIPAA BAA signed with us then, in order to meet compliance, your site will have these restrictions applied.

Your site will not have the option to enable the use of insecure FTP.

Your site will not have the option to enable the use of insecure ciphers for data transfer.

Storing data in a specific geographic region, such as the USA, is not a legal requirement of HIPAA. However, if storing data in a specific geographic region is important to your organization, configure your site to use only those regions.