Initializing secure environment…
Initializing secure environment…
Put AES-256 encryption on a PDF and decide what the reader is allowed to do with it. Two passwords are possible and they do different jobs: an open password is required just to view the file, and a permissions password controls printing, copying, editing and form filling for someone who has already opened it. Your password is used inside this tab and never transmitted, which is the only way to make a claim like that true. No sign-up, no watermark.
To password protect a PDF free, add the file, set an open password and optionally a permissions password, then download. AES-256 encryption is applied in your browser, so your password never leaves your device. No sign-up, no watermark.
Set both passwords. The open password stops anyone without it from reading the file; the permissions password stops a reader from printing or copying once they are in. Two layers, and they are independent — which is the part most users get wrong by setting only one.
Almost always a reader with no support for AES-256, or one that requires a certificate to open an encrypted file. Test the encrypted output in the reader you actually use before sending it, rather than assuming the recipient's software matches yours.
Set one password and apply it to every file in the batch. Consistency matters more than it sounds: a set where one file is encrypted differently invites the question of which one is the odd one out. Send the password by a different channel from the files.
Compress first, encrypt last. Encryption is the final operation on the finished bytes, which means the file size you measured is the file size the recipient gets, and nothing downstream can change the encrypted content without invalidating the password check.
The open password is required to view the document at all. The permissions password is entered once by someone who can already open the file, and it controls what they may do — print, copy, edit, fill forms. Many people set only permissions, which is a weaker control than most users assume: the file opens for anyone.
No, and neither can anyone else. That is the property that makes the encryption worth having. There is no reset link, no recovery code and no back door, because a back door would be a way in for everyone else too.
No. The password is used as key material inside this browser tab, and nothing is transmitted. This is the claim the whole site is built around, and it is verifiable — open your network tools and watch.
By conforming readers, yes. The restrictions are recorded in the file and Acrobat, Preview, Chrome, Edge and Firefox all honour them. A determined user can screenshot or photograph what they can see, which is true of every DRM system ever shipped, and no PDF tool can prevent that.
AES-256, the same algorithm used for classified government material. Older PDFs using 40-bit or 128-bit RC4 are weak by comparison, which is one reason re-encrypting an old file is worth doing.
Yes, and it saves a great deal of friction when you are sending a set. Each file is encrypted independently, so a failure on one does not lose the batch.
Any conforming PDF reader can, given the password. What will not work is a tool that processes files in bulk without asking — which is the correct behaviour and worth knowing about before you rely on an automated pipeline.
Yes. Free, no account, no watermark, and no upload. Encrypting a document is the least sensible thing you could do by uploading it anywhere, which is why this is a local operation.
More security & privacy — all free, no upload.