Document protection from AI use

Open to people.Locked to AI.

Seal a confidential document into one file. A recipient opens it with a code. AI tools such as GPT cannot receive its decryption key.

One encrypted fileHuman and device checkAI key requests denied
Send the documentOpen it for peopleKeep an access record

Open a received file

Did you receive a protected document?

Install SealSend for Windows, then double-click the same .sseal file again. It opens in the secure viewer.

  1. 1Install SealSend
  2. 2Open the .sseal file again
  3. 3Enter the sender's code
  4. 4Read it in the secure viewer

Opens DOCX · PDF · PPTX · XLSX · CSV · HWP — without those apps installed

Windows PC only — .sseal files cannot be opened on phones or tablets

Required appGet SealSend for WindowsWindows 10/11 · x64 · v0.6.0
01 / WHY

It started with one simple question

“Should this document
really go into GPT?”

One translation or review can turn a confidential document into a prompt. Training alone is not enough. SealSend stops the key before the document can become AI input.

We do not claim to detect every AI.We release decryption keys only to verified people.
02 / WORKFLOW

Simple for the recipient, too

Seal it. Send it.
Open it with a code.

No separate original and key file to manage. You send one .sseal file and share an invitation code.

01

Seal

Encrypt DOCX, PDF, PPTX, XLSX, CSV and HWP-family documents on the device.

02

Send

Email or message the single .sseal file. The original is inside, but it remains encrypted.

03

Human opens

After the recipient verifies the code and device, the server allows the key and the secure viewer draws the document on screen only.

03 / JOURNEY

Step by step, in the open

From the moment you send to the moment it locks.

One delivery, unfolded into five steps. For each one we state what happens — and exactly what reaches the SealSend server. Document content never does.

  1. 01
    Sender

    Seal

    Pick a document and your PC encrypts all of it. The original never leaves your PC.

    What reaches the SealSend serverHalf a key + the access policy — no document content
  2. 02
    Sender

    Send

    Send the single .sseal file over the email or messenger you already use. SealSend is not part of this transfer.

    What reaches the SealSend serverNothing
  3. 03
    Recipient

    Verify

    The recipient opens the file and enters the invitation code. The server checks person, device, expiry and open count — only then releases the other half of the key.

    What reaches the SealSend serverCode check + device registration — no document content
  4. 04
    Recipient

    Read

    The secure viewer draws the document on screen only. Save, copy and print are blocked, and every page carries the reader, device and time.

    What reaches the SealSend serverAn open event
  5. 05
    Automatic

    Lock

    Close the viewer or let it expire and the document locks again. The sender can see who opened it, when, and how many pages.

    What reaches the SealSend serverA close event + pages read — no text, no search terms
04 / CAPABILITIES

One file, two outcomes

Verified person: open.
Anything else: stay locked.

Without the key, the same file reveals no content. The policy server releases keys for human viewing and rejects AI-purpose requests.

H / 01For people

Verify, then open in the secure viewer

It opens only for someone who passes the invitation code, registered device, allowed uses and expiry. The original is drawn on screen and never written to disk.

AI / 02For AI

Give them nothing readable

Upload only the sealed file and AI receives ciphertext. AI-purpose key requests are denied by the policy server.

05 / SECURITY

One key, split in two

The device and server
must both allow access.

The document key is restored only with both the device share and policy-server share. Document content is never stored on the server.

Explore use cases →
Device shareKdevice
2 / 2
Policy shareKpolicy
Authorized releaseKdoc
01

Nothing leaves the viewer

Save, copy and print are disabled, and the decrypted original is never written to disk.

02

The reader is marked

Every page carries the reader, device and time, and the pages they opened are recorded.

03

Honest about the edge

We cannot stop someone photographing the screen. What we can do is make sure that photo carries their identity.

06 / DATA

Where the document goes

Document content never touches our servers.

The SealSend server is a lock, not a vault. Your document is encrypted on the sender's PC and travels over your own channel. The server decides one thing only: open, or stay locked.

Sender's PCThe original lives here · encrypted here
Your email · messengerOne encrypted .sseal file — never routed through SealSend
Recipient's PCSecure viewer · drawn on screen only
SealSend policy server
What it receives

Half a key · access policy · open records

What it never receives

Document content · the .sseal file · search terms

0 bytesof document content stored on our servers

What does the locking

Math, not promises.

C / 01

AES-256-GCM document encryption

The whole document is sealed with the standard authenticated cipher. Flip one bit and decryption itself fails.

C / 02

2-of-2 key split

The document key is split in two: half inside the file, half on the server. Stealing either one opens nothing.

C / 03

Ed25519 signed permits

Every viewing permit is signed by the server and used once. Forged, replayed or expired permits are rejected on the recipient's PC.

C / 04

Signed requests + TLS

Every request between app and server is signed with a device secret and encrypted in transit. Without the secret, a device cannot be impersonated.

C / 05

403 for AI

AI-purpose key requests are always denied. Upload the sealed file to an AI tool and all it receives is ciphertext.

07 / COMPARE

Beyond a file password

A password protects the file.
SealSend controls the opening.

Standard PDF and Word passwords are useful for static access. SealSend adds a live policy decision every time a recipient opens the file.

PDF / Word password

Anyone with the password can open it

  • The same password is shared between recipients
  • Hard to revoke after the password is shared
  • No built-in record of who opened a local copy
  • PDF permissions can restrict printing and copying
SealSend

The server checks each person and device

  • Set device count, expiry and number of opens
  • Revoke future access after sending
  • Record each verified open, close and pages read
  • Block save, copy and print, and deny AI-purpose keys

SealSend complements endpoint DLP. The viewer blocks save, copy and print, but we do not claim to stop someone photographing the screen.

08 / USE CASES

For documents that must not become AI input

Ready to send.
Not ready to train on.

LEGAL

Contracts & legal

Reduce contracts and review files becoming translation or summary prompts.

FINANCE

Finance & investment

Stop pricing, account and approval data before it reaches an outside AI.

PUBLIC

Public & personal data

Open citizen, HR and personal records only for verified recipients.

AI

AI use control

Turn “do not upload to AI” from a notice into document access policy.

Lock it before you send it

Deliver the document.
Not the prompt.

Seal it with SealSend. The recipient can open it safely with a code.