Ian, Have you looked into some of the tools like 'scponly' which locks down user sftp/scp access to only their own files? Then on the Apache side, some form of webdav also limited to just the user's directory? John --