Skip to content
Cybersecurity · Secure Data Exchange

Top 6 Managed File Transfer and Secure File Sharing Tools for 2026: Compared on Patch Record

GoAnywhere, MOVEit, Cleo, Kiteworks, Boomi MFT, and AWS Transfer Family, with the exploitation history every other comparison leaves out.

By ·Sep 18, 2026·15 min·6 tools compared
Managed File TransferSecure File SharingMFTData ProtectionVulnerability ManagementCybersecurity

The short answer

Managed file transfer is the only software category whose public profile was built by getting breached. Every serious comparison should therefore start with the patch record, and almost none of them do. This one does.

  • Fortra GoAnywhere MFT for large hybrid partner networks that need on-premises control, deployed with the admin console off the internet.
  • Progress MOVEit for regulated transfers needing deep audit evidence, and prefer MOVEit Cloud unless residency forces self-hosting.
  • Kiteworks for sensitive data with residency requirements and a small user population. The only vendor here with a published entry price: $25.50 per user per month.
  • Cleo when file transfer and EDI are genuinely the same workflow, and after you have asked about the December 2024 incomplete patch.
  • Boomi MFT if you already run Boomi. It is no longer sold standalone.
  • AWS Transfer Family if you control both ends and want fully published pricing: $0.30 per protocol hour, $0.04 per GB.
  • None of them if you are moving files between two systems you own. That is SFTP plus a scheduler, not a licence.

Last verified: September 2026.

Make patch and disclosure speed an explicit criterion

This is the information gain on this page. Nobody else scores it, and it is the variable that has actually decided outcomes in this category.

Ask every vendor these five questions and record the written answers next to the feature matrix:

  1. Is there a dated, numbered advisory feed for this product, covering at least two years? Fortra publishes numbered advisories (the GoAnywhere deserialization flaw is FI-2025-012). Progress publishes per-product security alert bulletins on its community site and runs a public trust center. Cleo publishes security update articles in its support knowledge base. A vendor that cannot point you at a feed has already answered the question.
  2. How many days elapsed between internal discovery and customer advisory for the last three critical issues? Ask for the number, not a policy statement.
  3. Does the advisory state whether exploitation was observed before the patch shipped? This one separates vendors who prioritize your incident response from vendors who prioritize their own reputation. Fortra's GoAnywhere advisory carried a discovery date of 11 September 2025 while public disclosure followed later that month, and independent researchers established exploitation in that window.
  4. How are affected customers contacted directly? Email to named security contacts, in-product notice, and account team outreach, or a web page you are expected to check.
  5. What happened the last time a fix turned out to be incomplete? Cleo is the case study, and it is the worst failure mode in the category, because it converts a diligent customer's correct action into false assurance.

The record, with dates

Every entry below is drawn from vendor advisories or government agency advisories, not from news summaries.

Accellion FTA, December 2020. Zero-day exploitation of the legacy File Transfer Appliance hit government and private organizations internationally. Accellion rebranded to Kiteworks in October 2021 and states the flaws were confirmed only in FTA, which ran a separate codebase from the Kiteworks platform. Accellion settled related healthcare litigation for $8.1 million.

GoAnywhere MFT, February 2023. CVE-2023-0669, remote code execution. CISA advisory AA23-158A records the Cl0p group claiming data exfiltrated from approximately 130 victims over ten days.

MOVEit Transfer, May 2023. CVE-2023-34362, SQL injection. The same CISA advisory states Cl0p began exploiting it on 27 May 2023, installing the LEMURLOOT web shell to steal data from MOVEit Transfer databases. This became the defining supply chain data-theft campaign of the period.

MOVEit Transfer, June 2024. CVE-2024-5806, an authentication bypass in the SFTP module, disclosed with a Progress security bulletin and flagged by CISA.

Cleo Harmony, VLTrader, and LexiCom, December 2024. CVE-2024-50623 was patched in version 5.8.0.21 in October 2024. In December, active exploitation bypassing that patch was identified, and a second flaw, CVE-2024-55956, was fixed in 5.8.0.24. Both entered CISA's Known Exploited Vulnerabilities catalog and Cl0p claimed the campaign.

GoAnywhere MFT, September 2025. CVE-2025-10035, a deserialization flaw in the License Servlet with a CVSS score of 10.0, covered by Fortra advisory FI-2025-012 with a stated discovery date of 11 September 2025. It was exploited as a zero-day before public disclosure, added to CISA's Known Exploited Vulnerabilities catalog, and linked to Medusa ransomware deployment. Fixed in 7.8.4 and the 7.6.3 sustain release.

MOVEit Automation, April 2026. Progress disclosed CVE-2026-4670, an authentication bypass scored CVSS 9.8, chained with CVE-2026-5174 for privilege escalation, on 30 April 2026. Fixed in 2025.1.5, 2025.0.9, and 2024.1.8. No workaround exists and remediation requires a full-installer upgrade, which means planned downtime.

What the pattern actually tells you

Read across those events and one thing is constant. In every case the exploited component was internet-reachable and customer-operated. The extortion groups are not finding exotic memory corruption bugs; they are finding authentication bypasses and deserialization flaws in admin consoles and service endpoints that were exposed to the whole internet because that was the easiest way to deploy.

Three consequences for how you buy:

  • Network placement beats product choice. The admin console belongs on a private network segment. Partner-facing protocols belong in a DMZ proxy tier, not on the application server. That architecture would have blunted most of the events above regardless of vendor.
  • Patch capability is a purchase criterion about you, not the vendor. If your change process cannot ship an emergency patch to an internet-facing application within 48 hours, self-hosted MFT is the wrong choice. A vendor-managed cloud option is the honest one.
  • A clean record is not proof of safety. Boomi MFT and AWS Transfer Family have no public mass-exploitation event, which is genuinely worth something, and it partly reflects architecture (no customer-operated appliance) and partly reflects smaller installed bases. Do not read it as a guarantee.

Who is still an independent purchase

This market consolidated while nobody was watching, and a lot of comparison content has not caught up.

Thru no longer exists as a vendor. Boomi announced its acquisition on 15 May 2025, and the technology is now Boomi Managed File Transfer inside the Boomi Enterprise Platform. The thruinc.com domain redirects to Boomi. If a comparison still lists Thru as an independent option, it was written from stale data. For a buyer with no Boomi footprint, this means evaluating an entire enterprise integration platform to obtain file transfer, which is rarely the right trade.

Kiteworks is Accellion renamed, since October 2021. That is not a criticism, and the FTA codebase distinction the company draws is technically real. It still belongs in your evaluation, because the organizational question does not transfer to a new brand: how the vendor behaved during an incident, and what changed afterwards.

The rest (Fortra, Progress, Cleo, AWS) remain straightforwardly purchasable as of September 2026.

The cloud-native alternative, honestly

AWS Transfer Family is the option most buyers should price out before signing an MFT licence, and the option most of them will correctly reject.

What you get: managed SFTP, FTPS, FTP, and AS2 endpoints in front of Amazon S3 or EFS. Identity comes through IAM or your directory, and logging through CloudWatch. Published rates for US East (N. Virginia) are $0.30 per protocol hour and $0.04 per GB for SFTP, FTPS, and FTP. AS2 is $0.01 per message up to 50 MB for the first 100,000 monthly messages. Web app units cost $0.50 per hour for 250 concurrent sessions, and PGP decrypt workflows $0.10 per GB.

What you do not get: trading-partner onboarding, partner credential self-service, EDI translation, retry and escalation workflow, packaged non-repudiation reporting, or an operations console anyone outside engineering can use. Azure and Google Cloud have comparable gaps in their equivalents.

The decision rule is simple. If you control both ends, or your partners are few and technical, the cloud service is cheaper, more transparent, and has no appliance for you to misconfigure. If you onboard hundreds of external partners with varied protocol demands and somebody in operations needs a console, you are buying an MFT product whether you want to or not.

Where this sits in the rest of the stack

Managed file transfer is one control in a data protection story, not the whole of it.

Who should not buy this category

  • Internal-only file movement. Two systems you own, inside one network boundary: use SFTP with key-based authentication, a scheduler, and monitoring. MFT adds licence cost, administrative weight, and an internet-facing attack surface for governance features you will never invoke.
  • Occasional person-to-person document sharing. If the requirement came from legal or finance needing to send sensitive documents to outside counsel, that is secure file sharing. Your existing collaboration suite with data loss prevention, or a governed sharing product, is cheaper and less exposed.
  • Organizations that cannot patch an internet-facing application within days. Every event documented above punished exactly that. If the staffing is not there, do not buy a self-hosted appliance. Buy a vendor-managed service and make patching someone else's contractual obligation.

Quick Comparison

ProductBest forDeploymentPublished priceMass-exploitation history
Fortra GoAnywhere MFTLarge on-premises and hybrid partner networksOn premises, private cloud, hostedNo, quote only by module and instanceYes: CVE-2023-0669 (Feb 2023) and CVE-2025-10035 (Sep 2025)
Progress MOVEit TransferEnterprises needing broad protocol and compliance coverageOn premises or MOVEit CloudNo, quote onlyYes: CVE-2023-34362 (May 2023); further criticals in 2024 and 2026
KiteworksRegulated data with strict governance and residency needsHardened appliance, private or hosted cloudYes, Business edition $25.50 per user per monthPredecessor product: Accellion FTA zero-days (Dec 2020)
CleoEDI and supply chain integration alongside file transferOn premises or Cleo-hostedNo, quote onlyYes: CVE-2024-50623 and CVE-2024-55956 (Dec 2024)
Boomi MFT (formerly Thru)Teams already standardized on the Boomi platformCloud native, inside BoomiNo, quote onlyNo public mass-exploitation event
AWS Transfer FamilyProtocol endpoints in front of S3 with no vendor applianceAWS managed serviceYes, fully published per hour and per GBNo public mass-exploitation event

Fortra GoAnywhere MFT

Best for
Large on-premises and hybrid partner networks
Deployment
On premises, private cloud, hosted
Published price
No, quote only by module and instance
Mass-exploitation history
Yes: CVE-2023-0669 (Feb 2023) and CVE-2025-10035 (Sep 2025)

Progress MOVEit Transfer

Best for
Enterprises needing broad protocol and compliance coverage
Deployment
On premises or MOVEit Cloud
Published price
No, quote only
Mass-exploitation history
Yes: CVE-2023-34362 (May 2023); further criticals in 2024 and 2026

Kiteworks

Best for
Regulated data with strict governance and residency needs
Deployment
Hardened appliance, private or hosted cloud
Published price
Yes, Business edition $25.50 per user per month
Mass-exploitation history
Predecessor product: Accellion FTA zero-days (Dec 2020)

Cleo

Best for
EDI and supply chain integration alongside file transfer
Deployment
On premises or Cleo-hosted
Published price
No, quote only
Mass-exploitation history
Yes: CVE-2024-50623 and CVE-2024-55956 (Dec 2024)

Boomi MFT (formerly Thru)

Best for
Teams already standardized on the Boomi platform
Deployment
Cloud native, inside Boomi
Published price
No, quote only
Mass-exploitation history
No public mass-exploitation event

AWS Transfer Family

Best for
Protocol endpoints in front of S3 with no vendor appliance
Deployment
AWS managed service
Published price
Yes, fully published per hour and per GB
Mass-exploitation history
No public mass-exploitation event
1

Fortra GoAnywhere MFT

Best for Enterprise

Best for: Large hybrid partner networks that need deep protocol coverage and on-premises control

GoAnywhere is the most capable general-purpose MFT product here for a complex partner network: broad protocol support, strong workflow automation, granular key and certificate handling, and deployment models that keep data on your infrastructure. It has also been mass-exploited twice, in February 2023 and again in September 2025, and any honest recommendation has to carry that. The security question with GoAnywhere is not whether it can be operated safely, it is whether your team will keep the admin console off the public internet and patch on the day an advisory lands.

Pros

  • Deep protocol and workflow coverage: SFTP, FTPS, AS2, AS4, HTTPS, PGP, plus scheduling and translation steps
  • Deployment flexibility across on premises, private cloud, and hosted, which suits data residency and air-gapped requirements
  • Modular licensing means you can start with core transfer and add Secure Mail or GoDrive later
  • Fortra publishes numbered product security advisories with dates, which makes its patch history auditable rather than anecdotal

Cons

  • Two separate mass-exploitation events in under three years, both against internet-exposed components
  • No published pricing, and module-plus-instance licensing makes quotes hard to compare against competitors
  • Feature depth carries administrative weight; this is not a product you run without an owner
Honest Weakness: GoAnywhere's record is the worst-case argument for the whole category. In February 2023, CVE-2023-0669 was exploited by the Cl0p group, and CISA's joint advisory records the group claiming data from roughly 130 victims over ten days. In September 2025 it happened again. CVE-2025-10035, a deserialization flaw in the License Servlet carrying a CVSS score of 10.0, was exploited as a zero-day before public disclosure. It was added to CISA's Known Exploited Vulnerabilities catalog and linked to Medusa ransomware deployment. Both events shared a root condition: an internet-exposed admin or service component. The mitigation Fortra itself stressed, keeping the admin console off the public internet, is exactly the control most breached deployments lacked. If you buy GoAnywhere, treat network exposure of every component as the primary design decision, not an afterthought.

Security track record

CVE-2023-0669, remote code execution, exploited by Cl0p from late January 2023; CISA advisory AA23-158A records the group claiming approximately 130 victims in ten days. CVE-2025-10035 was a CVSS 10.0 deserialization flaw in the License Servlet, covered by Fortra advisory FI-2025-012 with a stated discovery date of 11 September 2025. It was exploited as a zero-day before disclosure and subsequently added to CISA KEV. Fixed releases were 7.8.4 and the 7.6.3 sustain release.

What to ask the vendor

Ask for the mean time from internal discovery to customer advisory across the last three critical CVEs. Ask how customers are notified outside the advisory page. Ask what the supported upgrade path looks like when an advisory says patch today.

Deployment guidance

Put the admin console behind a VPN or a private network segment with no internet route. Terminate partner-facing protocols in a DMZ proxy tier rather than exposing the application server. Both mass-exploitation events would have been substantially blunted by that architecture.

No published price. Fortra licenses GoAnywhere MFT by module or server component per instance, with Secure Mail and GoDrive priced per user, quoted on request.

Visit Fortra GoAnywhere MFT
2

Progress MOVEit Transfer

Runner Up

Best for: Enterprises that need broad protocol coverage, compliance reporting, and a managed cloud option

MOVEit is the most widely recognized name in managed file transfer and a genuinely strong product: comprehensive audit trails, mature compliance reporting, a hosted MOVEit Cloud option, and an automation tier for scheduled workflows. It is also the product whose 2023 breach became the defining supply chain data-theft event of the decade, and it has shipped further critical vulnerabilities since. What matters for a 2026 buyer is not that MOVEit had a bad year, it is how the vendor has handled every disclosure cycle since, and that record is mixed.

Pros

  • Strongest audit and compliance reporting in the category, which shortens evidence gathering for regulated transfers
  • MOVEit Cloud removes appliance patching from your team, which directly addresses the failure mode that caused the 2023 losses
  • Broad protocol and integration coverage including cloud storage targets
  • Progress publishes dated security alert bulletins per product and runs a public trust center

Cons

  • Three separate critical disclosure cycles since 2023, the most recent in April 2026
  • Remediation for the 2026 Automation flaws required a full-installer upgrade with no workaround, meaning planned downtime
  • No published pricing; quote only, with a 30-day trial as the only self-serve entry
Honest Weakness: The pattern, not any single bug, is the concern. CVE-2023-34362 was exploited by Cl0p from 27 May 2023 using a SQL injection flaw to install the LEMURLOOT web shell and steal data from MOVEit Transfer databases, per CISA advisory AA23-158A. CVE-2024-5806 followed in June 2024 as an authentication bypass in the SFTP module. On 30 April 2026, Progress disclosed CVE-2026-4670, an authentication bypass in MOVEit Automation scored CVSS 9.8, chained with CVE-2026-5174 for privilege escalation. It is fixed only in 2025.1.5, 2025.0.9, and 2024.1.8, with no workaround, and remediation requires a full-installer upgrade. Three critical cycles in three years, in a product class attackers specifically hunt, is a risk you should price into the deployment plan rather than argue away. The mitigating factor is real: MOVEit Cloud shifts patching to Progress, and for many buyers that is the deciding argument.

Security track record

CVE-2023-34362, SQL injection in MOVEit Transfer, exploited by Cl0p from 27 May 2023, documented in CISA advisory AA23-158A alongside the LEMURLOOT web shell. CVE-2024-5806, SFTP authentication bypass, June 2024. CVE-2026-4670 (CVSS 9.8 authentication bypass) and CVE-2026-5174 (privilege escalation) in MOVEit Automation, disclosed 30 April 2026, fixed in 2025.1.5, 2025.0.9, and 2024.1.8, with no workaround available.

What to ask the vendor

Ask how MOVEit Cloud customers were protected during each of those cycles relative to self-hosted customers, with dates. That single answer is the clearest available evidence on whether the managed option is worth the premium.

Deployment guidance

If you self-host, budget a standing maintenance window you can invoke within 48 hours, because the 2026 fix required a full installer and a service outage. If you cannot commit to that, MOVEit Cloud is the more honest choice.

No published price. Progress quotes MOVEit on request through its sales team; a 30-day trial is available.

Visit Progress MOVEit Transfer
3

Kiteworks

Best Value

Best for: Regulated data exchange where governance, residency, and audit evidence outrank raw protocol breadth

Kiteworks is built around governance rather than transfer mechanics: a hardened appliance, consolidated policy across secure email, file sharing, and transfer, selectable hosting regions, and the audit evidence a privacy regulator asks for. It is also the only vendor in this comparison that publishes a real entry price, at $25.50 per user per month for the Business edition with a stated 40% discount for annual billing. The history you need to know is that Kiteworks is Accellion renamed, and the Accellion File Transfer Appliance was one of the original mass-exploitation events in this category.

Pros

  • Published, self-serve Business edition pricing at $25.50 per user per month, in a category that otherwise hides every number
  • Selectable hosting regions across the Americas, Europe, and Asia Pacific, which makes data residency commitments straightforward
  • Governance model spans secure email, file sharing, and transfer under one policy and one audit log
  • Hardened virtual appliance architecture narrows the exposed surface compared with a general application server

Cons

  • Business edition caps are restrictive: 5 to 100 users, 2 GB maximum file size, 1 TB storage, 50 GB per month bandwidth
  • Enterprise edition is call-for-pricing with no published figure
  • Lighter than GoAnywhere or Cleo on classic B2B protocol automation such as AS2 trading-partner workflows
Honest Weakness: The corporate history has to be on the table. Accellion's legacy File Transfer Appliance was compromised through zero-day exploitation beginning in December 2020, affecting government and private organizations worldwide, and the company settled related healthcare litigation for $8.1 million. Accellion rebranded to Kiteworks in October 2021. The company's position is that the vulnerabilities were confirmed only in FTA, which had a separate codebase from the Kiteworks platform, and FTA has since been retired. That distinction is technically meaningful and worth accepting, but it does not erase the organizational question, which is how the vendor behaved during the incident and what changed afterwards. Ask directly, and ask for the current disclosure policy in writing. Separately, the Business edition's 2 GB file cap and 50 GB monthly bandwidth ceiling will disqualify it for media, genomics, or engineering workloads before the security conversation starts.

Security track record

The predecessor product, Accellion FTA, was exploited through zero-day vulnerabilities from December 2020 in a campaign affecting government and private sector organizations internationally. Accellion rebranded as Kiteworks in October 2021 and states that the vulnerabilities were confirmed only in FTA, which ran a separate codebase from the Kiteworks platform.

Edition limits

Business: 5 to 500 users per the pricing page, with the online store selling 5 to 100 users, 2 GB maximum file size, 1 TB storage, 50 GB per month bandwidth, hosted cloud with a selectable region. Enterprise: unlimited users and a stated 16 TB maximum file size, call for pricing.

What to ask the vendor

Ask for the current coordinated disclosure policy, the notification channel and timeline customers can expect, and the most recent product security advisories with dates. A vendor with this history should be able to answer all three immediately.

Published for the Business edition: $25.50 per user per month, with a stated 40% discount for annual billing, sold for 5 to 100 users through the online store. Enterprise edition is call for pricing.

Visit Kiteworks
4

Cleo

Honorable Mention

Best for: Supply chain and EDI integration where file transfer and trading-partner workflow are one problem

Cleo is a different shape of product from the rest of this list. Harmony, VLTrader, and LexiCom sit where file transfer meets EDI and B2B integration, which is why Cleo is entrenched in logistics, manufacturing, and food distribution. If your file movement is inseparable from trading-partner onboarding and document translation, Cleo does something the general-purpose MFT products do not. Its December 2024 exploitation episode also produced the single worst disclosure data point in this comparison, and it deserves to be weighed heavily.

Pros

  • Combines managed file transfer with EDI and B2B integration, removing a whole category of middleware for supply chain operations
  • Deep trading-partner onboarding, document translation, and protocol handling for logistics and manufacturing workflows
  • Entrenched ecosystem knowledge in verticals where partner requirements are idiosyncratic
  • Publishes product security update articles in its public support knowledge base

Cons

  • The October 2024 patch for CVE-2024-50623 proved bypassable and the flaw was mass-exploited in December 2024
  • Two CVEs in the same component chain landed in CISA's Known Exploited Vulnerabilities catalog within days of each other
  • No published pricing; quote only
Honest Weakness: Cleo shipped an incomplete fix and customers who patched were breached anyway. CVE-2024-50623, an unrestricted file upload and download flaw enabling remote code execution, was addressed in version 5.8.0.21 in October 2024. In December 2024, researchers found active exploitation that bypassed that patch, and a second issue, CVE-2024-55956, was fixed in 5.8.0.24. Cl0p claimed the resulting data-theft campaign. Both CVEs entered CISA's Known Exploited Vulnerabilities catalog in December 2024. An incomplete patch is materially worse than a slow patch, because it converts a diligent customer's correct action into false assurance. If you are evaluating Cleo, that episode is the thing to interrogate: what changed in the security testing process afterwards, and what is the current commitment on verifying that a fix actually closes the attack path.

Security track record

CVE-2024-50623 disclosed and patched in 5.8.0.21 in October 2024; active exploitation bypassing that patch identified in December 2024. CVE-2024-55956, arbitrary command execution via Autorun directory defaults, fixed in 5.8.0.24. Both added to CISA's Known Exploited Vulnerabilities catalog in December 2024, with Cl0p claiming responsibility for the data theft campaign.

What to ask the vendor

Ask what changed in patch verification after the 5.8.0.21 bypass. Ask whether the vendor now publishes a statement of whether exploitation was observed at the time of each advisory. Ask how customers running an affected version are contacted directly rather than expected to read the knowledge base.

Deployment guidance

The Autorun directory default that enabled CVE-2024-55956 is a reminder to audit default configurations rather than trusting them. Review the hardening guide line by line at install, and re-review it after every major upgrade.

No published price. Cleo quotes Harmony, VLTrader, LexiCom, and its integration cloud on request.

Visit Cleo
5

Boomi MFT (formerly Thru)

Fastest

Best for: Organizations already standardized on the Boomi integration platform

Thru was a credible cloud-native MFT vendor with no public mass-exploitation history, which in this category is a genuine distinction. It is also no longer an independent purchase. Boomi announced the acquisition on 15 May 2025 and has folded the technology into its platform as Boomi Managed File Transfer; the thruinc.com domain now redirects to Boomi. That makes it an excellent option for existing Boomi customers and a poor shortlist entry for anyone else, because you would be buying an integration platform to get a file transfer product.

Pros

  • Cloud-native, multi-tenant architecture with no customer-managed appliance to patch, which removes the failure mode behind most incidents on this page
  • No public mass-exploitation event in its history
  • File movement sits alongside API and application integration in one platform, with one set of monitoring and credentials
  • Removes the DMZ proxy tier and certificate estate that on-premises MFT requires

Cons

  • No longer sold standalone; it is a capability of the Boomi Enterprise Platform since the May 2025 acquisition
  • No published pricing, and the commercial conversation is a platform conversation
  • Product roadmap now serves Boomi's integration strategy rather than MFT buyers specifically
Honest Weakness: The acquisition changes what you are buying, and that is easy to miss because much of the comparison content on the web still lists Thru as an independent vendor. Boomi announced the acquisition on 15 May 2025 and the Thru website now redirects into Boomi's platform pages. For an organization with no Boomi footprint, evaluating this means evaluating an enterprise integration platform, with its own licensing model, its own implementation effort, and its own lock-in, in order to obtain managed file transfer. That is rarely the right trade. There is also a quieter risk: when a specialist product becomes a feature of a larger platform, MFT-specific roadmap items compete for attention with everything else the platform sells. Ask for the post-acquisition release history before you commit.

Acquisition status

Boomi announced the acquisition of Thru, Inc. on 15 May 2025, describing it as an expansion of file-based integration within the Boomi Enterprise Platform. The former thruinc.com URLs now redirect to Boomi's managed file transfer platform pages.

Why the architecture matters

Every mass-exploitation event on this page involved a customer-operated, internet-reachable component. A multi-tenant service where the vendor patches shifts that risk, though it concentrates it: a flaw in the service affects every tenant at once, and you have no ability to patch faster than the provider.

What to ask the vendor

Ask for the managed file transfer release notes since May 2025 and for the security advisory channel that covers this specific capability rather than the platform generally.

No published price. Sold as part of the Boomi Enterprise Platform, quoted on request, historically priced by data volume.

Visit Boomi MFT (formerly Thru)
6

AWS Transfer Family

Best Free Option

Best for: Teams that need SFTP, FTPS, FTP, or AS2 endpoints in front of their own storage without buying an MFT product

AWS Transfer Family is the honest cloud-native alternative, and the only product in this comparison with fully published pricing. In US East (N. Virginia) that is $0.30 per protocol hour per enabled endpoint, $0.04 per GB for SFTP, FTPS, and FTP transfer, and per-message AS2 rates. It is not an MFT product and does not pretend to be. It gives you managed protocol endpoints in front of Amazon S3 or EFS, with IAM and CloudWatch doing the identity and audit work, and you build the rest. For a large share of buyers, that is what they actually needed.

Pros

  • Fully published pricing with no sales cycle: $0.30 per protocol hour, $0.04 per GB for SFTP, FTPS, and FTP, AS2 at $0.01 per message up to 50 MB for the first 100,000 monthly messages
  • No appliance, no patching, and no internet-exposed admin console of your own to misconfigure
  • Identity, authorization, logging, and encryption inherit from IAM, CloudWatch, and S3 rather than a vendor's implementation
  • Managed workflows cover common needs such as PGP decryption, billed at $0.10 per GB

Cons

  • No trading-partner community management, no partner self-service onboarding, no EDI translation
  • Cost is usage-based and can exceed a licence for high-volume steady transfer, since endpoint hours accrue whether or not files move
  • You own the workflow, alerting, and non-repudiation design that a commercial MFT product ships out of the box
Honest Weakness: This is a protocol front end, not managed file transfer, and the gap shows up in operations rather than in a feature matrix. There is no partner onboarding portal, no partner-facing credential self-service, no document translation, no built-in retry and escalation workflow, and no packaged non-repudiation reporting that an auditor will recognize. Teams choose it for the transparent pricing and the absence of an appliance, then spend several engineering months rebuilding the partner management layer they did not know they were buying. It is the right answer when you control both ends, or when partners are few and technical. It is the wrong answer when you onboard hundreds of external partners with varied protocol demands and someone in operations needs a console to manage them.

What you get

Managed SFTP, FTPS, FTP, and AS2 endpoints that read and write directly to Amazon S3 or Amazon EFS, with authentication through AWS-managed users, a custom identity provider, or Active Directory, and logging through CloudWatch.

What you build

Partner onboarding and credential lifecycle, transfer success and failure alerting, retry and escalation logic, retention and legal hold policy, and any non-repudiation evidence your auditors expect. Budget engineering time for these explicitly.

Cost modelling

Endpoint hours accrue continuously per enabled protocol, so three protocols on one endpoint cost roughly $0.90 per hour before any bytes move. Model a full month of your real traffic profile, including idle hours, before comparing against a licence quote.

Published. $0.30 per protocol hour per enabled protocol. $0.04 per GB uploaded or downloaded for SFTP, FTPS, and FTP. AS2 is $0.01 per message up to 50 MB for the first 100,000 messages per month, then $0.005. SFTP connectors cost $0.001 per call plus $0.40 per GB. Web apps are $0.50 per hour per unit supporting up to 250 concurrent sessions, and PGP decrypt workflows $0.10 per GB. Rates shown for US East (N. Virginia); associated S3, EFS, Lambda, and CloudWatch charges are additional.

Visit AWS Transfer Family

Which One Should You Pick?

Use CaseOur Recommendation
Hundreds of external partners, mixed protocols, on-premises control requiredFortra GoAnywhere MFT, deployed with the admin console on a private network and partner protocols terminated in a DMZ proxy tier.
Regulated transfers where audit evidence and compliance reporting decide the purchaseProgress MOVEit, and strongly consider MOVEit Cloud so that patching the 2023 and 2026 class of flaws is the vendor's job rather than yours.
Sensitive data with residency requirements and a small user populationKiteworks. Business edition at $25.50 per user per month with a selectable hosting region is the only published entry price in the category.
Logistics or manufacturing where file transfer and EDI are the same workflowCleo, after interrogating what changed in patch verification following the December 2024 incomplete-fix episode.
Already running Boomi for application and API integrationBoomi MFT. Adding file transfer inside the platform you already operate avoids a second vendor, a second audit, and a second credential estate.
Engineering team that controls both ends and wants predictable published costsAWS Transfer Family. Protocol endpoints in front of S3 at published rates, with the partner management layer built yourself.
Moving files between two systems you own, inside one organizationNone of these. SFTP with key-based authentication plus a scheduler and monitoring does this. MFT earns its price on external partners, non-repudiation, and audit, none of which apply here.

How we evaluated

Last verified: September 2026.

Most managed file transfer comparisons score protocol checkboxes. Protocol support is table stakes across this shortlist, and it has never been the variable that decided an outcome. These are the dimensions used here:

  • Security track record, with dates. Documented mass-exploitation events, the CVE identifiers, the fixed versions, and whether exploitation preceded disclosure. Every claim carries a date so it can be checked and so it ages visibly.
  • Patch and disclosure behaviour. Whether the vendor publishes a dated advisory feed, whether advisories state observed exploitation, and what happened when a fix proved incomplete.
  • Deployment model and who patches. Customer-operated appliance, vendor-managed cloud, or a managed service with no appliance at all. This determines which of the documented failure modes you inherit.
  • Pricing transparency. Whether a real number exists on a vendor page, and what it covers.
  • Corporate status. Whether the product is still an independent purchase, since this market consolidated during 2025.

What we checked

Product and pricing claims come from vendor pages read in September 2026. Exploitation claims come from vendor security advisories or from government agency advisories, never from a news summary or another comparison site.

  • Kiteworks pricing page and its Business package store listing for the $25.50 per user per month figure, the stated 40% annual-billing discount, and the 5 to 100 user store range. The same pages give the 2 GB file size cap, 1 TB storage, 50 GB monthly bandwidth, and selectable hosting regions. They also state the Enterprise edition's call-for-pricing status, with unlimited users and a 16 TB file size ceiling.
  • AWS Transfer Family pricing for every published rate quoted on this page, taken at US East (N. Virginia).
  • Fortra's GoAnywhere pricing page for the licensing model (by module or server component per instance, with Secure Mail and GoDrive priced per user) and to confirm no figures are published.
  • Progress MOVEit for product structure and to confirm pricing is quote-only with a 30-day trial.
  • Boomi's managed file transfer platform page and the acquisition announcement dated 15 May 2025. We separately confirmed that thruinc.com now redirects into Boomi's platform pages, which is why Thru is listed here under its current name.

For the exploitation history:

  • CISA advisory AA23-158A for CVE-2023-34362 in MOVEit Transfer, the 27 May 2023 start of Cl0p exploitation, and the LEMURLOOT web shell. The same advisory states that this group claimed data from approximately 130 GoAnywhere victims over ten days following CVE-2023-0669.
  • Fortra advisory FI-2025-012 for CVE-2025-10035, its CVSS 10.0 rating, the 11 September 2025 discovery date, and the fixed releases 7.8.4 and 7.6.3.
  • Cleo's own product security update article for CVE-2024-55956 and the 5.8.0.24 fix, alongside the October 2024 5.8.0.21 patch for CVE-2024-50623 that was subsequently bypassed in December 2024.
  • Progress's MOVEit Automation critical security alert bulletin for April 2026 for CVE-2026-4670 and CVE-2026-5174, the 30 April 2026 disclosure, the fixed versions, and the absence of a workaround.

What we could not verify

Several vendor sites block automated retrieval. Fortra's pricing and advisory pages, Cleo's support knowledge base, and Progress's community advisory all return access errors to a crawler. Details from those sources were confirmed through their indexed content and cross-checked against the government advisories above, rather than read directly end to end. The CVE identifiers, CVSS scores, dates, and fixed version numbers are consistent across those sources. Confirm the current fixed versions on the vendor advisory itself before you plan an upgrade, because sustain-release version numbers change.

CISA Known Exploited Vulnerabilities catalog inclusion is stated here for CVE-2023-0669, CVE-2024-50623, CVE-2024-55956, and CVE-2025-10035 based on the corresponding agency and vendor advisories. Check the live catalog for current entries and due dates if you are using this for compliance purposes.

We found no published price for GoAnywhere, MOVEit, Cleo, or Boomi MFT, and we did not substitute an aggregator estimate for any of them. Specific dollar ranges circulate widely for these products and none of them is a vendor commitment.

What we did not do

We did not run these products, and this page makes no hands-on testing claims. Rankings reflect documented capability, published pricing, deployment model, corporate status, and the dated public security record.

We did not use the absence of a public exploitation event as evidence of superior engineering. Boomi MFT and AWS Transfer Family have no such event, which partly reflects architecture and partly reflects installed base and attacker attention. It is a real advantage and it is not a guarantee.

We did not rank vendors down for having disclosed vulnerabilities. Every product of this complexity has them. What is scored here is how fast the vendor moved, how clearly it told customers, and what it did when a fix was incomplete.

Note

Editorial independence: this is a vendor-neutral comparison with no paid placements, sponsorships, or affiliate links. Rankings reflect fit for the stated use cases, not commercial relationships. Verify current licensing, current patch levels, and current supported versions directly with each vendor before you buy or upgrade.

Frequently Asked Questions

Why does managed file transfer software keep getting mass-exploited?
Because it combines three properties attackers select for. It is internet-reachable by design, since external partners must connect to it. It holds the organization's highest-value data in bulk, already collected and often unencrypted at rest inside the application. And a single vulnerability yields hundreds of victims at once, because the same product is deployed at thousands of companies with similar configurations. That is why one extortion group has returned to this category repeatedly: Accellion FTA in December 2020, GoAnywhere in February 2023, MOVEit in May 2023, and Cleo in December 2024. The category is not unusually badly written software. It is unusually well targeted, and it should be bought and deployed with that assumption rather than despite it.
How should I evaluate a vendor's patch and disclosure speed?
Make it a scored criterion with written answers, not a conversation. Ask five questions. First, does the vendor publish a dated, numbered advisory feed for this product, and can you read the last two years of it. Second, what is the measured interval from internal discovery to customer advisory for the last three critical issues, stated in days. Third, does the advisory state whether exploitation was observed before the patch shipped, since a vendor that hides this is choosing its reputation over your incident response. Fourth, how are affected customers contacted directly rather than expected to check a web page. Fifth, what happened the last time a fix turned out to be incomplete. Fortra publishes numbered advisories with dates, Progress publishes per-product security alert bulletins and runs a public trust center, and Cleo publishes support knowledge base security articles, so all three can answer the first question. The rest should be in your evaluation record in writing.
Which managed file transfer vendors publish a price?
Two of the six. Kiteworks publishes $25.50 per user per month for its Business edition, with a stated 40% discount for annual billing, sold through its online store for 5 to 100 users. That edition caps file size at 2 GB, storage at 1 TB, and bandwidth at 50 GB per month. The Enterprise edition is call for pricing. AWS Transfer Family publishes everything: $0.30 per protocol hour, $0.04 per GB for SFTP, FTPS, and FTP, and per-message AS2 rates. Fortra, Progress, Cleo, and Boomi publish nothing. Fortra's own pricing page describes the licensing model, by module or server component per instance with Secure Mail and GoDrive priced per user, but gives no figures. Any specific dollar range you see quoted for those four elsewhere is an aggregator estimate rather than a vendor commitment.
Is MOVEit safe to buy after the 2023 breach?
It is defensible, with conditions, and the conditions are the whole answer. MOVEit remains capable, and Progress has continued to publish dated security bulletins, including the April 2026 disclosure of CVE-2026-4670 and CVE-2026-5174 in MOVEit Automation. The pattern of three critical disclosure cycles in three years is the risk you are accepting. Two conditions make it reasonable. First, prefer MOVEit Cloud unless a residency or contractual requirement forces self-hosting, because the 2023 losses concentrated among self-hosted customers who could not patch fast enough. Second, if you do self-host, commit in writing to a maintenance window you can invoke within 48 hours, since the April 2026 remediation required a full-installer upgrade with no workaround and no way to mitigate in place.
What is the difference between managed file transfer and secure file sharing?
Managed file transfer is machine-to-machine and governed: scheduled or event-driven transfers between systems and external partners, with protocol breadth (SFTP, FTPS, AS2, AS4), workflow automation, non-repudiation evidence, and an audit trail built for regulators. Secure file sharing is human-to-human: a person sends a large or sensitive file to another person, with access control, expiry, and tracking. Kiteworks deliberately spans both under one governance policy, which is its main architectural argument. GoAnywhere and Cleo are MFT-first with sharing modules attached. AWS Transfer Family is MFT protocol plumbing with no sharing story at all. Buying the wrong one is common: teams purchase heavy MFT because a legal department needs to send documents securely, when the requirement was sharing.
Who should not buy managed file transfer software at all?
Three groups. First, anyone moving files between systems they own inside one organization: SFTP with key-based authentication, a scheduler, and monitoring does this, and MFT adds licence cost and an internet-facing attack surface for governance features you will not use. Second, teams whose actual requirement is person-to-person sharing of occasional sensitive documents, where a governed sharing product or your existing collaboration suite with data loss prevention is both cheaper and less exposed. Third, and this is the hard one, any organization that cannot commit to patching an internet-facing application within days of an advisory. Every mass-exploitation event in this category punished slow patching of an exposed component. If you cannot staff that, buy a vendor-managed cloud option and make patching someone else's obligation.
Does moving to a cloud-hosted MFT service remove the risk?
It changes the shape of the risk rather than removing it. A vendor-operated service takes patching off your team, which addresses the specific failure that caused most of the documented losses in this category, and that is a real improvement for most buyers. What it introduces is concentration and loss of control: a flaw in the service affects every tenant simultaneously, and you cannot patch faster than your provider no matter how good your team is. The reasonable position: vendor-managed hosting is the better default for organizations without a dedicated platform team. It also obliges you to evaluate the provider's disclosure behaviour even more carefully, because during an incident their notification timeline is the only information you will have.

About the author

is the founder and creator of LoginRadius, a customer identity platform he built and scaled to over a billion users. He is now the founder of GrackerAI, a GEO platform for B2B SaaS and cybersecurity teams, and has spent more than 15 years building identity and security products.

Related Comparisons