FTP transmits passwords in cleartext, SFTP requires CLI knowledge, classic MFT tools are IT-only and expensive. Conbool SecureFiles is secure file transfer that every employee operates from Outlook, with Entra ID authentication, GDPR Art. 30 audit log and EU hosting.
Cleartext password over FTP, fails GDPR state-of-the-artEntra ID SSO, TLS plus optional client-side zero-knowledge
No central audit log, fragmented server logsCentral audit log, GDPR Art. 30, SIEM export
Own FTP server, patches, quotas, maintenanceEU SaaS, no maintenance burden
FTP no longer meets GDPR state-of-the-art for ad hoc employee transfer in 2026. Conbool replaces FTP with Outlook-native UX, Entra ID SSO and a central audit log.
Right for you if:FTP retirementGDPR Art. 32Microsoft 365
100 %
Hosted in the EU
30 days
Pilot phase
0
FTP servers to maintain
GDPR 30
Audit log per Art. 30
Employee
Recipient
Entra ID
TLS plus E2E
Audit log
SecureFiles · Hand-off
Files travel directly from employee to recipient.
Conbool SecureFiles replaces FTP with a direct line between two endpoints. Entra ID for authentication, encryption in transit and on demand client-side, audit log out of the box.
Outlook add-in for Classic, New and Web. Employees stay in their familiar workflow.
Entra ID SSO instead of FTP credentials. No more orphaned accounts.
Central audit log per GDPR Art. 30, SIEM export.
FTP, SFTP and Conbool, side by side.
Seven points from real ad hoc employee transfer.
Conbool SecureFiles
FTP / SFTP
Authentication
Entra ID, SSO
FTP: cleartext password, SFTP: key file
Transport
TLS plus optional E2E
FTP: none, SFTP: yes
Audit log
Central, GDPR Art. 30
Server logs only, fragmented
End-user client
Outlook add-in plus web
FileZilla, WinSCP, CLI
Scaling
SaaS, elastic
Own server, capacity bound
Audience
Every employee
IT and power users
Maintenance burden
Zero, SaaS
Patches, upgrades, certificate rotation
As of 2026. Statements about FTP and SFTP are based on RFC 959 and publicly available documentation of common server implementations.
GDPR Art. 32, state of the art
Why FTP no longer meets state of the art.
FTP transmits authentication in cleartext. In public WiFi and compromised segments a compliance risk. Conbool replaces it with Entra ID SSO, TLS and on demand client-side encryption.
FTP, RFC 959
Defined in 1985, no TLS, no audit. Cleartext authentication.
Conbool TLS and beyond
TLS 1.3 in transit, optional client-side zero-knowledge. Key derivation never server-side.
Entra ID SSO
Authentication via Microsoft Entra ID. No separate FTP credential lists, automatic deprovisioning when AD removes a user.
State-of-the-art conformance
GDPR Art. 32 demands appropriate state of the art. FTP no longer meets this in 2026, Conbool documents it in the GDPR Art. 30 record.
Migration
Retire FTP in 30 days.
Typical FTP retirement projects split into three steps: ad hoc employee transfers move to Conbool, automated B2B handover stays temporarily on SFTP or MFT, phase 2 replaces those later via API.
Use-case inventory
Ad hoc employee sending vs automated B2B handover are recorded separately.
Employee transfers first
Around 80 percent of FTP use cases are ad hoc employee sending. Those move first to the Outlook add-in.
B2B via SFTP plus roadmap
Automated handovers stay on SFTP initially. Conbool API in phase 2 replaces them gradually.
Switch off the FTP server
After 30 days of parallel operation the own FTP server is shut down. The TCO calculation often fully offsets the Conbool license.
Audit log
What GDPR Art. 30 actually demands.
GDPR Art. 30 demands a record of all processing activities including data transfers. FTP server logs are usually insufficient, fragmented and not exportable. Conbool delivers a central audit log out of the box.
Who, what, when, where to
Per transfer the sender, recipient, file size, encryption mode and expiry date are logged.
SIEM export
Logs export as JSON or CEF. Splunk, Sentinel, Elastic and Datadog compatible.
Configurable retention
Audit log retention is configurable per tenant, from 90 days to 10 years.
Instant lookup
On a GDPR access request, a recipient or sender can be filtered in seconds.
FAQ FTP alternative
Is Conbool GDPR compliant?
Yes. Conbool is a German company and runs SecureFiles exclusively in EU data centers on ISO-27001 certified infrastructure. GDPR Art. 30 is technically reflected in the central audit log. The data processing agreement is available for customers. In zero-knowledge mode the server technically sees no cleartext.
How do I switch from FTP to Conbool?
Typically in three steps. First, use-case inventory, ad hoc employee sending vs automated B2B handover are recorded separately. Second, ad hoc sending moves to the Conbool Outlook add-in, which covers around 80 percent of FTP use cases. Third, automated B2B handovers stay on SFTP or MFT temporarily and are later replaced via Conbool API. 30 days parallel operation, then the own FTP server is shut down.
What does Conbool cost compared to running an FTP server?
Conbool is licensed per user. Removing the own FTP server (hardware, patches, certificate rotation, storage) typically offsets the license fully in the TCO calculation. Concrete pricing on request.
Why is FTP no longer secure?
FTP transmits username and password in cleartext. Anyone listening on the network, for example on public WiFi or compromised segments, can grab the credentials. It also lacks modern features like audit log, retention policies and policy enforcement. GDPR Art. 32 state of the art no longer accepts FTP as an appropriate technical measure.
Isn't SFTP enough?
SFTP solves transport encryption but not the UX problem. End users need CLI knowledge or special clients like FileZilla or WinSCP, and central audit logs only exist via custom tooling. SFTP remains useful for IT-to-IT integrations, but for everyday employee use it is too high a barrier.
What is MFT and do I need it?
Managed File Transfer like GoAnywhere, IBM Sterling or Progress MOVEit combines protocol breadth with audit and policies. Useful for highly regulated B2B exchange but expensive and primarily operated by IT. Conbool addresses the broad employee day-to-day. MFT and Conbool can coexist, they serve different audiences.
How does this integrate into Active Directory?
Via Microsoft Entra ID, formerly Azure AD. SSO login, group mapping to Conbool roles, automatic deprovisioning when AD removes a user. For on-prem AD we recommend Entra Connect as a synchronization bridge, the standard in Microsoft 365 environments.
Is there an API for automation?
A REST API for phase 2 is announced for 2026. Today we offer custom webhook integrations and CLI-driven bulk uploads as a transitional path. For automated supplier handovers reach out, we have reference integrations.
Statements about FTP are based on RFC 959, statements about SFTP on RFC 4253. Statements about classic MFT tools are based on publicly available product descriptions 2024 to 2026. Statements about Conbool are based on its own product documentation and ISO-27001 infrastructure certification.
GoAnywhere, IBM Sterling, MOVEit and other named products are trademarks of their respective owners. Conbool is a trademark of Conbool GmbH. All statements without warranty of continued accuracy.
No maintenance, no server patches, no certificate rotation.