All tools run in your browser — your files never leave your device.
All tools154

PDF

PDF security: what actually works, and what is theatre

Most PDF security features are requests that readers are free to ignore. Two are real. Knowing which is which saves a lot of wasted effort.

The short answer. Only two PDF protections are cryptographic and therefore real: an open password, which encrypts the content, and a digital signature, which makes any modification detectable. Everything else — permission flags, expiry dates, screenshot blocking, copy prevention — depends on the reader choosing to cooperate, and many do not.

The honest split

The honest split
FeatureReal?Why
Open password (encryption)YesContent is unreadable without the key
Digital signatureYesAny byte change is detectable
Permissions: no printingNoAdvisory; many readers ignore it
Permissions: no copyingNoAdvisory; and OCR bypasses it anyway
Expiry dateNoEnforced by the viewer, not the file
Screenshot preventionNoA camera exists
WatermarkingPartlyDeters and traces; prevents nothing
ZIP password around a PDFPartlyReal encryption, but only in transit

The pattern is simple: anything enforced by mathematics holds, and anything enforced by the viewer's goodwill does not. Vendors sell the second category hard because it demos well.

What encryption genuinely gives you

An open password encrypts the page content with AES. Without the password there is nothing to read — not slowly, not with effort, not at all. This is the one PDF protection that stands up.

It answers exactly one question: can someone who intercepts this file read it? No. It says nothing about what an authorised recipient does with it afterwards.

The weak point is never the cipher, it is the password and how you send it. Emailing an encrypted PDF and then emailing the password to the same address protects against nothing. The detail is in how to password protect a PDF.

Why expiry dates do not expire anything

A self-destructing PDF sounds useful and is not what is being sold.

A PDF is a file. Once it is on someone's disk, nothing in it can delete it, and nothing can stop them opening it in a reader that ignores the expiry. The feature works by having the document check a date — either an embedded one, which is trivially editable, or a server, which means the document is really a viewer stub and the content lives elsewhere.

That second architecture — a DRM platform where the "PDF" is a shell that streams content from a server — genuinely can revoke access. It is also not a PDF in any useful sense: recipients need the platform, it fails offline, and the content is only as available as the vendor. That may be a reasonable trade for high-value material. It is not a checkbox on a normal file.

Screenshot and copy prevention

These are sold together and neither survives contact with a determined person, or an undetermined one with a phone.

Copy prevention is the permission flag, which many readers ignore. Even where honoured, a screenshot plus OCR recovers the text in about a minute — Image to Text would do it. Screenshot blocking depends on the operating system cooperating, works on some platforms and not others, and is defeated entirely by pointing a camera at the screen.

The honest framing: these raise the effort from trivial to slightly annoying. If your threat model is a colleague casually forwarding a paragraph, they help a little. If it is anyone who actually wants the content, they do nothing, and believing otherwise is worse than knowing they are weak.

What digital signatures actually promise

A digital signature is the other genuinely cryptographic feature, and it is routinely misunderstood as protection.

It does not prevent modification. It makes modification detectable. The signature covers a hash of the file, so changing one byte invalidates it and any reader will say so.

That is a strong guarantee and a different one from what people expect. It answers "has this been altered since signing, and by whom was it signed" — not "can this be altered". For a contract or a filing, that is exactly the right question. The distinction between this and a drawn signature is in how to sign a PDF electronically.

A workable approach

Given all that, what actually protects a document is mostly not a PDF feature.

  1. Send less. The narrowest useful extract, not the whole file. Nothing protects a page you did not send.
  2. Encrypt in transit, with the password on a different channel — or better, use the recipient's own upload portal and skip email.
  3. Sign anything whose integrity matters, so alteration is detectable.
  4. Watermark for traceability, not prevention. A recipient name in a faint diagonal makes a leaked screenshot attributable.
  5. Use contracts for the rest. An NDA is the actual control over what someone does with a document they are allowed to read.

That last point is the one people resist and it is the truth of the subject. Every technical control ends at the moment an authorised person opens the file. After that it is a legal question, and no checkbox changes it.

Frequently asked questions

Can I stop someone printing or copying my PDF?

Not reliably. Those are permission flags the specification asks readers to honour, and many ignore them entirely. Even where honoured, a screenshot plus OCR recovers the text in about a minute. They raise the effort slightly; they do not prevent anything.

Can I set a PDF to expire?

Not in the file itself. A PDF cannot delete itself, and an embedded expiry date is trivially editable. Products that do this are DRM platforms where the "PDF" is a viewer stub streaming from a server — which works, but is not a normal file and fails offline.

Does password protection actually work?

An open password does — it encrypts the content with AES, so without it there is nothing to read. An owner password does not; it only sets advisory flags. The weak point is never the cipher, it is the password strength and how you transmit it.

Is a digital signature a form of protection?

It makes modification detectable rather than preventing it. The signature covers a hash of the file, so any change invalidates it and readers say so. That answers "has this been altered since signing" — a different and often more useful question.

Is zipping a PDF with a password secure?

ZIP AES encryption is genuine, so it protects the file in transit. But it only protects until someone extracts it — after that you have an unprotected PDF on their disk. It also saves almost no space, since a PDF is already compressed.

What actually protects a confidential document?

Sending less of it, encrypting in transit with the password on a separate channel, signing it so alteration is detectable, watermarking for traceability, and an NDA for everything after that. Every technical control ends when an authorised person opens the file.

Stop reading, start doing

Every tool in this guide is free.

154 browser-based utilities. No account, no upload, and no file size limit — your files are processed on your own device and never sent anywhere.

Browse all 154 tools