How it works, and security

Sealrift is a web page that does all of its work on your computer. This page explains exactly what happens to your files, and how to use password protection well.

Where your documents go

Nowhere. When you add a PDF or a CSV, the browser reads it into the page's memory. From there:

All of this code is part of the page you loaded. None of it sends your data anywhere, and the page's security policy (connect-src 'self') stops it talking to any other website even if it tried.

Your CSV and your passwords are never saved to your browser's storage. When you press Start over or close the tab they are gone. After each export the background workers throw away their copies of your files and the finished PDFs, and the page keeps only what it needs for another run until you press Start over.

See it for yourself

The one request a paid licence makes

On the web version, if you have entered a Pro or Bureau licence key, the app checks it with sealrift.com about once or twice a day and when it is close to expiring. It sends only the licence key and receives an updated key (or a message that the subscription has ended). This request is shown in the counter and labelled. The browser extension never makes this check: you paste a refreshed key when your old one nears its end date (see Terms).

The encryption

Choosing and sending passwords

AES-256 is only as strong as the password. A strong cipher does not help if the password can be guessed.

  • Send passwords separately from the files. Tell people their password rule once, in person or by a different channel, rather than in the same email as the PDF.
  • Do not rely on date of birth alone for highly sensitive documents. Colleagues, family and social media can reveal it. Combine two facts, for example {NI_LAST4}{POSTCODE_NOSPACE} or {DOB:DDMM}{NI_LAST4}.
  • Longer is better: 10 or more characters from two or more facts is a good minimum.
  • Keep the passwords report somewhere safe. Sealrift cannot recover a password for you: we never see them.

Checking the files open correctly

Every build of Sealrift is tested automatically: a 200-page synthetic payslip file is split into 200 files, each with a different password, and every file is checked with the native qpdf tool (qpdf --check) and opened with pdf.js using the right password (it opens) and a wrong one (it refuses). Sample files are also opened automatically in Google Chrome's built-in PDF viewer and Mozilla Firefox's built-in PDF viewer, which must refuse a wrong password and show the page with the right one.

Our release checklist also includes opening sample files by hand in Adobe Acrobat Reader (Windows and macOS) and macOS Preview.

We recommend you do the same with one file from your first batch: open it, check the password works, and check a wrong password is refused.

Open-source components

Sealrift is built with pdf-lib (MIT), pdf.js (Apache-2.0), qpdf (Apache-2.0) via the qpdf-wasm build (ISC), fflate (MIT), Papa Parse (MIT), Preact (MIT), @noble/ed25519 (MIT) and the Inter typeface (SIL Open Font License). Their licences are included in the app bundle in third-party-licences.txt.