PDF Encryption

Recipient-Independent Protection

Back to Overview

Motivation – When the Recipient Has No PKI

External contacts often have neither S/MIME nor PGP certificates. In addition to the portal, PDF encryption provides another alternative to securely reach recipients without key material. Nevertheless, sensitive content (patient reports, audit documents, specifications) must arrive encrypted.

Secure Communication Without Key Material

PDF Container – Functional Principle

PDF containers enable secure email communication even when the recipient has no encryption keys. All content is packaged into an encrypted PDF container.

• Automatic conversion of email and attachments
• AES-256 encryption for maximum security
• Flexible password provision
• Compatible with all standard PDF readers

The PDF container ensures that sensitive information can be transmitted securely even without own key infrastructure.

PDF Container functional principle - PDF-Container Funktionsprinzip

Password Options

Specified by Sender

The sender can set the password themselves and communicate it to the recipient.

Automatically Generated

System generates secure password and communicates it separately (SMS, letter, portal).

From Customer Database

Password is generated from existing data (e.g., patient birth date + PIN).

Use Cases - Einsatzszenarien - PDF Encryption Application Scenarios

Practical Application Cases

Use Cases

PDF encryption is used in various industries and situations where secure communication without own key infrastructure is required.

Healthcare: Test report to patient, password via SMS-TAN
Authority ↔ Company: Award documents with password letter according to § 55 UVgO
Supply Chain Audit: Inspection report to supplier without own key
Support Return Channel: Message contains reply button "Respond Securely" → Portal login

These use cases demonstrate the versatility of PDF encryption for various compliance requirements and industries.

Automated Processing

Technical Process

The technical process of PDF encryption runs fully automatically through the workflow engine and various services that work seamlessly together.

SMTP Input: Email is received by the gateway
Workflow Engine: Detects "No Key" or Tag #PDFSEC
PDF Service: PDF-Lib creates encrypted container
Password Service: Selects appropriate password source
Delivery: Mail with .pdf attachment is sent
Additional Channel: Optional SMS gateway, API or letter printing for password

The entire process runs automatically and requires no manual intervention while meeting all compliance requirements.

PDF encryption technical process - Technischer Ablauf

Compliance Map

RequirementImplementation
DSGVO Art. 32AES-256, password policy, audit log
NIS2Encryption when PKI is missing, incident webhook
ISO 19005 (PDF/A)Long-term archiving ensured
Decorative gradient background

Protect Sensitive Documents

Protect sensitive documents, even when the recipient doesn't use keys.