SFTP
In short: SSH File Transfer Protocol — file transfer as with FTP, but tunnelled completely over an encrypted SSH connection.
In more detail: Despite the similar name, SFTP technically has nothing to do with classic FTP or FTPS — it’s a protocol of its own that sits on top of the SSH transport protocol and shares its encryption and authentication. Runs over the same port as SSH (22); no second data connection needed.
In Depth
The name “SFTP” is historically somewhat misleading: classic FTP uses two separate connections (one for commands, one for the actual data) and transmits unencrypted by default. SFTP technically has nothing to do with that — it’s a complete new development as an extension of the SSH protocol and uses its existing, already encrypted connection for everything: commands AND data run over the same channel, which makes firewall configuration much simpler than with classic FTP (which often needs additional port openings for the data connection).
Functionally, SFTP offers considerably more than SCP: listing directories, renaming/deleting files, changing permissions, resuming interrupted transfers at the right point (resume) — SCP can basically only “copy”. That’s why SFTP is today considered the standard for secure file transfer, while SCP is only used for very simple, quick ad-hoc copies.