Add Password to PDF (AES Encryption)
Protect your sensitive documents with military-grade AES encryption. Being Zero Cloud, no one else has access to your original files.
Select PDF
or drag the file here
Password-protect a PDF with AES-256, without uploading it
Encrypt a PDF so it cannot be opened without the password. The encryption is performed in your browser, so neither the file nor the password is ever transmitted.
There is an obvious problem with encrypting a confidential document on a website: to do it, that site has to receive both the document and the password you are protecting it with. For a moment, a stranger's server holds the file in the clear along with the key. If the point of the exercise was confidentiality, that is a strange way to start.
This tool avoids the problem by not having a server in the loop. The encryption runs inside your browser tab, using an engine compiled to WebAssembly. Your PDF and your password stay on your machine from beginning to end.
The result is a standard encrypted PDF using AES-256, the strongest scheme the PDF specification defines. Any compliant reader — Acrobat, Preview, Chrome, Edge — will prompt for the password before displaying a single page.
AES-256 encryption
The strongest encryption the PDF format supports, applied by the same open-source engine that desktop tools use.
Your password never travels
The password is used to derive the key inside your browser. It is never sent anywhere, never logged and never stored.
Opens in any PDF reader
Standard PDF encryption, so recipients simply enter the password in whatever reader they already use.
How to password-protect a PDF
Select the PDF you want to encrypt.
Choose a strong password and type it in.
Encryption runs locally in your browser.
Download the protected file and share the password separately.
Neither your file nor your password is uploaded
This matters more here than on any other tool. Encrypting a document on a server means handing that server the plaintext document and the key at the same moment. Doing it in your own browser means there is no such moment.
When people reach for this
Emailing a document you would rather not leak
Email is not a private channel: it passes through servers you do not control and lands in an inbox that may be shared or breached. Encrypting the attachment means an intercepted copy is useless without the password.
Sending payroll, invoices or tax paperwork
Financial documents routinely contain bank details, salaries and tax identifiers. Many organisations require these to be encrypted in transit as a matter of policy.
Storing sensitive files in shared cloud storage
A shared drive folder is only as private as its permissions, which drift over time. An encrypted file stays protected even if the folder is shared more widely than intended.
Handing a document to a client or counterparty
A signed agreement or a medical report needs to reach one specific person. Encryption plus a password sent through a different channel gives you a simple second factor.
What actually happens to your file
Your PDF is read into memory and passed to pdfcpu, a mature open-source PDF library written in Go, which we compile to WebAssembly so it runs inside the browser rather than on a server.
Encryption uses AES with a 256-bit key, which is the default and the strongest option the library offers. The key is derived from the password you type, in the tab, and is discarded when the operation ends.
Both the user password (required to open the document) and the owner password (which governs permissions) are set to the same value. That is a deliberate simplification: a PDF whose owner password differs can have its restrictions stripped by many tools, so a single strong password is more honest than the illusion of two tiers.
The default permission set allows printing on the decrypted document. The encrypted file is then written out and handed to your browser as a download. At no point does the file or the password leave the tab.
What this does and does not protect against
- Encryption is only as strong as the password. AES-256 is not brute-forcible, but a short or common password is guessable regardless of the cipher. Use a long passphrase.
- There is no recovery. We do not hold your file or your password, so a forgotten password means the document is unreadable — by you as well as by anyone else. Store it in a password manager before you close the tab.
- Once someone opens the document legitimately, they can do what they like with it. Permissions in the PDF specification are advisory, and many readers ignore them. Treat this as protecting the file in transit and at rest, not as controlling what a recipient does afterwards.
- Sending the password in the same email as the file defeats the entire exercise. Use a different channel — a message, a call, a password manager share.
- It does not protect a file already on a compromised machine. This encrypts a document; it does not secure the computer it sits on.
Compared with an online encryption service
| This tool | Typical cloud service | |
|---|---|---|
| Who sees the file | Only you. | Their server, in the clear, before encrypting. |
| Who sees the password | Only you. | Transmitted to their server. |
| Encryption strength | AES-256. | Varies; sometimes weaker RC4. |
| File size limits | Bounded only by your device's memory. | Commonly capped on free tiers. |
| Works offline | Yes, once the page has loaded. | No. |
| Retention risk | None — nothing is uploaded. | Depends on their retention policy. |