Main guide · PDF passwords
How to password protect a PDF properly
Short answer
In this guide
| Property | Value |
|---|---|
| Encryption | AES-256 |
| Revision | 6 (PDF 2.0) |
| Opens without the password | No |
| Password stored in the job record | No |
To password protect a PDF, upload it, enter the same strong password twice, download the encrypted copy, and test that it refuses to open without the password. The tool uses AES-256 encryption. The password is sent to the encryption worker for the job, but it is excluded from the application job record and logs. The protection is only as strong as the password you choose, and it cannot stop an authorized reader from copying, photographing, or sharing what they can already see.
Add the password
-
Open Protect PDF and add one PDF no larger than 50 MB. The original file on your device is not changed.
-
Type the password twice. The matching field catches typing mistakes before the file is encrypted. Use a long passphrase rather than a short PIN or a familiar word.
-
Download the protected copy, open it, and confirm that it asks for the password. Test the password before sending the file or deleting your unprotected original.
Protect PDF
Add a password with real AES-256 encryption
Free · no signup · files deleted in 60 minutes
What the tool writes into the PDF
The protected copy uses AES-256 encryption with revision 6, as confirmed by inspecting a file produced by the tool. A compatible PDF viewer needs the password before it can decrypt and display the pages. Current versions of Acrobat, Preview, and major browser viewers support this protection.
Encryption changes the downloaded copy, not the original PDF on your device. Keep the original somewhere safe until you have tested the protected version. If the download is damaged, the password is mistyped, or the recipient uses unusually old software, that original is your clean way back.
The two protections people confuse
The PDF specification defines two separate things, and they look identical from the outside until you try to use the file.
An open password (sometimes called a user password) means the file cannot be opened at all without it. The content is genuinely encrypted, and this is what you get from the tool above.
Owner restrictions mean the file opens for anyone, but printing, copying, or editing are marked as not allowed. Viewers decide whether to honour those permissions, so restrictions are not a reliable confidentiality control. A restriction-only PDF can often be processed with Unlock PDF without an open password.
If your goal is that a stranger cannot read the document, only the first one counts.
Choose a password that deserves the encryption
AES-256 protects the key. The key comes from your password. A four-digit PIN or a common dictionary word can be tested by offline guessing even though the file uses strong encryption. The cipher cannot rescue a weak password.
A practical choice is a long, unique passphrase that is not reused for an account or another document. Several unrelated words are usually easier to type correctly than a short string of predictable substitutions. A password manager can generate and store a random alternative if both you and the recipient use one.
The delivery method matters too. Sending the PDF and its password in the same email puts both pieces in one place. When the document genuinely needs protection, send the password through a separate trusted channel and confirm the recipient before sharing it.
What PDF encryption cannot do
Password protection controls who can open the file. It does not provide per-person accounts, an expiry date, or a way to revoke access after the password has been shared. Everyone who knows the password has the same access.
It also cannot control what happens after a legitimate reader opens the document. They may be able to copy text, take screenshots, photograph the screen, print the pages, or save an unprotected copy. Owner restrictions can discourage some actions in cooperative viewers, but they are not a substitute for access control or a confidentiality agreement.
For changing teams, expiring links, or individual audit records, use a document platform designed for managed access. A PDF password is best for a fixed file shared with a known person or small group.
How the upload and password are handled
The PDF is sent to the server for the encryption job. The password passes transiently through the worker queue so the encryption worker can use it. It is excluded from the application job record and logs, and it is not kept as a recoverable account value. The uploaded file and generated result are removed from the server automatically about an hour later.
That retention window is useful for ordinary documents, but it does not override a workplace or legal rule that says a document cannot be uploaded. Use approved offline software in that case. The broader handling policy is explained on the privacy page.
Save the protected download promptly. The server deletion policy is a privacy feature, not long-term storage or a backup service.
For a fuller checklist before uploading a sensitive document, read what happens to a PDF you upload.
Before you send the protected copy
Open the downloaded PDF in a normal viewer and enter the password yourself. Check several pages, especially if the document contains forms, signatures, links, or unusual fonts. Encryption should protect the contents without changing their appearance, but testing the exact file you plan to send is safer than assuming.
Store the password somewhere recoverable before closing your work. TryDeputize cannot retrieve it later because it is not retained in the application job record or logs. Keep an unprotected original in a secure place if you may need to create another copy with a new password.
When this won’t work
- You need per-person access or the ability to revoke it later. A PDF password is one shared secret; once it is out it cannot be recalled. Use a document platform with real access controls.
- The recipient uses incompatible old software. Current mainstream viewers support the encryption, but an old application may fail to open the file.
- You want to stop copying and screenshots. Nothing can. Once someone can read a document, they can reproduce it.
- The PDF is larger than 50 MB. The online tool will reject it. Use an approved desktop application rather than splitting a sensitive document merely to bypass the limit.
- The file cannot be uploaded under your policy. Automatic deletion about an hour later is not the same as local-only processing.
Questions
How strong is the protection?
The cipher is AES-256, the strongest the PDF specification defines, and current Acrobat, Preview, and major browser viewers support it. The weak point is the password: a short or common one can be guessed offline no matter how good the encryption is.
Can you recover my password if I forget it?
TryDeputize cannot recover it because it is not retained in the application job record or logs. A weak password may still be guessed offline, but a strong passphrase has no practical recovery path, so save it securely.
What is the difference between a password and restrictions?
An open password stops the file being opened at all. Owner restrictions let anyone open it but block printing or copying, and they are trivially removable, so they are a courtesy rather than a protection.
Do you keep my password?
It passes to the encryption worker through the task queue, but it is excluded from the application job record and logs and is not retained for password recovery.
What is the file size limit?
You can protect one PDF up to 50 MB per job. For a larger file, use an approved desktop PDF application instead of trying to work around the upload limit.
Protect PDF
Add a password with real AES-256 encryption
Free · no signup · files deleted in 60 minutes