How it works, and security
Sealrift is a web page that does all of its work on your computer. This page explains exactly what happens to your files, and how to use password protection well.
Where your documents go
Nowhere. When you add a PDF or a CSV, the browser reads it into the page's memory. From there:
- Reading text (to find employee numbers or other IDs) is done by pdf.js, Mozilla's PDF library, running in a background worker inside your browser.
- Splitting is done by pdf-lib, which copies the chosen pages into a new PDF.
- Encryption is done by qpdf, a widely used open-source PDF tool, compiled to WebAssembly and running in another background worker.
- The ZIP is built by fflate, also in the browser.
All of this code is part of the page you loaded. None of it sends your data anywhere, and the page's security policy (connect-src 'self') stops it talking to any other website even if it tried.
Your CSV and your passwords are never saved to your browser's storage. When you press Start over or close the tab they are gone. After each export the background workers throw away their copies of your files and the finished PDFs, and the page keeps only what it needs for another run until you press Start over.
See it for yourself
- The app shows Network requests made with a live count of every request the page and its workers make after loading. It stays at 0 while you work.
- Works with Wi-Fi off. Load the app, then disconnect from the internet and use it. On the web, Sealrift also installs an offline copy of itself (a service worker), so it can open without a connection next time.
- Open your browser's developer tools, choose the Network tab, and watch: you will see no requests while you split and protect files.
The one request a paid licence makes
On the web version, if you have entered a Pro or Bureau licence key, the app checks it with sealrift.com about once or twice a day and when it is close to expiring. It sends only the licence key and receives an updated key (or a message that the subscription has ended). This request is shown in the counter and labelled. The browser extension never makes this check: you paste a refreshed key when your old one nears its end date (see Terms).
The encryption
- Each output file is encrypted with AES-256 using the standard PDF 2.0 security handler (revision 6). This is the strongest encryption the PDF format offers and is what Adobe Acrobat uses for "AES 256-bit".
- Each file has its own open password (the "user password"), from your CSV or template.
- Each file also has an owner password, which controls permissions. In the free version Sealrift sets a long random owner password that is never shown or kept. In Pro you can set your own, and choose no printing, no copying and no editing. These permission flags are honoured by mainstream readers but are not a security boundary: someone who can open a file can usually find a way to copy from it.
- Passwords must use letters, digits and common symbols (printable ASCII). Sealrift blocks accented or other special characters because PDF readers disagree about how to handle them, and a recipient could be locked out.
Choosing and sending passwords
AES-256 is only as strong as the password. A strong cipher does not help if the password can be guessed.
- Send passwords separately from the files. Tell people their password rule once, in person or by a different channel, rather than in the same email as the PDF.
- Do not rely on date of birth alone for highly sensitive documents. Colleagues, family and social media can reveal it. Combine two facts, for example
{NI_LAST4}{POSTCODE_NOSPACE}or{DOB:DDMM}{NI_LAST4}. - Longer is better: 10 or more characters from two or more facts is a good minimum.
- Keep the passwords report somewhere safe. Sealrift cannot recover a password for you: we never see them.
Checking the files open correctly
Every build of Sealrift is tested automatically: a 200-page synthetic payslip file is split into 200 files, each with a different password, and every file is checked with the native qpdf tool (qpdf --check) and opened with pdf.js using the right password (it opens) and a wrong one (it refuses). Sample files are also opened automatically in Google Chrome's built-in PDF viewer and Mozilla Firefox's built-in PDF viewer, which must refuse a wrong password and show the page with the right one.
Our release checklist also includes opening sample files by hand in Adobe Acrobat Reader (Windows and macOS) and macOS Preview.
We recommend you do the same with one file from your first batch: open it, check the password works, and check a wrong password is refused.
Open-source components
Sealrift is built with pdf-lib (MIT), pdf.js (Apache-2.0), qpdf (Apache-2.0) via the qpdf-wasm build (ISC), fflate (MIT), Papa Parse (MIT), Preact (MIT), @noble/ed25519 (MIT) and the Inter typeface (SIL Open Font License). Their licences are included in the app bundle in third-party-licences.txt.