SFTP file transfer — security documentation
This page describes the security measures around Revizo’s SFTP integration for automatic file import. The document is intended for IT managers, security teams, and compliance staff who are considering connecting SAP, banking systems, or other file sources to Revizo via SFTP.
Overview
Revizo supports automatic file retrieval via SFTP (SSH File Transfer Protocol). The integration is used to retrieve bank files (CAMT.053) and trial-balance files (CSV/Excel) from external SFTP servers.
| Property | Description |
|---|---|
| Protocol | SFTP over SSH (port 22) |
| Direction | Revizo retrieves files (pull model) |
| Encryption in transit | SSH-encrypted channel (standard SSH encryption algorithms) |
| Encryption of credentials | AES-256-GCM (application level) |
| Encryption at rest | AES-256 at database level (Supabase/AWS) |
| Authentication | Username/password or SSH key pair |
| Access control | Only Revizo administrators can create/change connections |
Connection model
Revizo operates as an SFTP client — we connect to your server and retrieve files. We do not run a publicly available SFTP server.
┌──────────────────────┐ ┌──────────────────────┐
│ Your SFTP server │◄─SSH────│ Revizo │
│ (bank, SAP, ERP) │ port 22│ (SFTP client) │
│ │ │ │
│ /outgoing/ │ │ Polling (interval) │
│ ├── file1.xml │ │ Retry with backoff │
│ └── file2.csv │ │ Dedup via SHA-256 │
└──────────────────────┘ └──────────────────────┘
IP addresses
Revizo runs on Vercel (frontend/API) and Railway (background worker). Outbound SFTP connections are initiated from the Railway worker. If the firewall requires IP allowlisting, contact us for updated IP addresses.
Credential handling
Storage
All SFTP credentials (username, password, SSH keys) are encrypted before they are stored in the database:
| Field | Encryption method | Details |
|---|---|---|
| Username | AES-256-GCM | Application-level encryption |
| Password | AES-256-GCM | Application-level encryption |
| SSH keys | AES-256-GCM | Application-level encryption |
- The encryption key is a server-side environment variable that is never exposed to clients
- Encrypted values are stored as
iv:tag:ciphertext(initialisation vector, authentication tag, encrypted data) - Each field uses a unique initialisation vector (IV) per encryption operation
Access
- Credentials are never shown in API responses — GET requests never return passwords or keys
- Only administrators can create or change SFTP connections
- All changes are logged with user ID and timestamp
Rotation
We recommend rotating SFTP credentials periodically (at least annually). Updating is done in Revizo under Settings → File transfer → SFTP → edit connection.
Data processing
File handling
| Step | Description |
|---|---|
| Download | Files are downloaded to memory (buffer), never to disk |
| Deduplication | SHA-256 hash is calculated — identical files are never imported twice |
| Processing | The file is parsed in memory and the result is stored in the database |
| After import | Configurable: the file can remain, be moved, or be deleted from the SFTP server |
Revizo never stores raw files permanently. Only the parsed data (transactions or account balances) is stored in the database.
What is stored
| File type | Data stored |
|---|---|
| Bank files (CAMT) | Individual transactions: date, amount, reference, account number |
| Trial balance | Account balances: account number, balance, company code, import time |
Metadata about the import (filename, hash, timestamp, status) is stored for traceability and deduplication.
Tenant isolation
All data in Revizo is isolated per organisation (tenant_id):
- SFTP connections are scoped to the organisation that created them
- Imported data is only available to authorised users in the same organisation
- The database enforces Row Level Security (RLS) for additional isolation
- All API requests validate organisation membership via the Clerk session
Network security
Protocol
SFTP uses SSH (Secure Shell) to establish an encrypted channel. All communication — including authentication, file transfer, and commands — is encrypted.
Connection handling
| Property | Value |
|---|---|
| Timeout | 30 seconds per connection attempt |
| Retry | 3 attempts with exponential backoff |
| Concurrent connections | Max 1 per sync config (sequential polling) |
| Interval | Configurable (15 min – 24 hours) |
Firewall recommendations
If the SFTP server is behind a firewall, we recommend:
- Allow only port 22 (or the configured SFTP port) from Revizo’s IP addresses
- Block incoming connections — Revizo initiates all connections (pull model)
- Enable logging of all SFTP logins for tracing
Logging and tracing
What is logged
| Event | Data logged | Purpose |
|---|---|---|
| Connection attempt | Timestamp, connection ID, result | Troubleshooting |
| File retrieved | Filename, SHA-256 hash, size | Traceability |
| Import completed | Number of rows/transactions, duration | Audit |
| Import failed | Error message, filename, timestamp | Troubleshooting |
| Configuration changed | User ID, timestamp, change | Audit trail |
What is NOT logged
- Passwords and SSH keys
- File contents (metadata only)
- Personally identifying information beyond user ID
Compliance
GDPR
Trial-balance files typically contain only account numbers and amounts — no personal data. Bank files (CAMT.053) may contain payment references with personal names. This data:
- Is stored encrypted (AES-256) in Revizo’s database
- Is subject to tenant isolation and access control
- Can be exported and deleted in accordance with GDPR (Articles 15 and 17)
- Is processed in the EU (Frankfurt, Germany)
For complete GDPR documentation, see Privacy and GDPR.
SOC 2 and certifications
Revizo’s infrastructure providers:
| Component | Provider | Certification |
|---|---|---|
| Hosting | Vercel | SOC 2 Type II |
| Database | Supabase (AWS) | SOC 2, ISO 27001 |
| DNS/CDN | Cloudflare | ISO 27001 |
| Authentication | Clerk | SOC 2 Type II |
Recommendations for IT departments
Before setup
- Create a dedicated SFTP user for Revizo with read access to the file directory
- Restrict access — the user should only have access to the folder with export files
- Configure chroot — lock the SFTP user to a specific folder
- Enable logging — log all SFTP logins and file transfers
- Consider SSH key authentication rather than passwords for stronger security
After setup
- Verify that files transfer correctly by checking import status in Revizo
- Monitor SFTP logs for unexpected connection attempts
- Rotate credentials periodically (recommended: annually)
- Document the SFTP access internally (who administers it, which files are shared)
SAP-specific
For SAP customers setting up automatic export of trial balance:
- Configure an SAP job that exports the trial balance to the SFTP server (see SAP SFTP documentation)
- Set up file format: CSV with semicolon separator, 3 columns (company code, account number, balance)
- Configure export frequency — Revizo supports polling from every 15 minutes to daily
- Use a consistent filename or a naming pattern that file retrieval can match (e.g.
saldobalanse_*.csv)
Contact
For questions about security around the SFTP integration, contact:
- Email: karl@savesolutions.no
- Subject: SFTP security / IT Due Diligence
We normally reply within 1–2 business days.
Last updated: April 2026