← All articles

May 12, 2026 · 6 min read

How Browser-Side Encryption Keeps Your Files Private

When most people hear the word "encryption" they picture IT departments and enterprise software. In reality, modern browsers are capable of military-grade encryption entirely within a web page — no software to install, no server access required. PrintGuard uses exactly this capability to ensure your documents are protected before they leave your device.

What is AES-256-GCM?

AES stands for Advanced Encryption Standard. The 256 refers to the key length in bits — a 256-bit key has 2²⁵⁶ possible combinations, a number so large that even the fastest supercomputer on Earth would take longer than the age of the universe to crack it by brute force.

GCM (Galois/Counter Mode) is the operational mode that makes AES not just confidential but also authenticated. Authentication means the encrypted data includes a mathematical proof that it has not been tampered with. If anyone modifies even a single byte of the encrypted file, decryption will fail and produce an error instead of corrupted data. This is critical for a document printing workflow, where a tampered file could result in printing wrong content.

Where does the key come from?

Encryption requires a key — a secret value used to scramble and unscramble data. In PrintGuard, the key is derived entirely from the passphrase you enter. This is done using PBKDF2, a "password-based key derivation function".

PBKDF2 works by running the passphrase through a hashing function (SHA-256 in PrintGuard's case) hundreds of thousands of times, combined with a random "salt" value. This process is intentionally slow and computationally expensive — which means that even if an attacker captured the encrypted file, they could not feasibly test billions of passphrases per second to find the right one.

The salt is stored alongside the encrypted data and is not secret. Its purpose is to ensure that the same passphrase produces a different key every time, so that two documents encrypted with the same passphrase cannot be linked to each other.

What is zero-knowledge architecture?

Zero-knowledge means the server — in this case PrintGuard's infrastructure — has zero knowledge of the plaintext content of your file at any point.

The encryption and decryption both happen in your browser using the Web Cryptography API, a standard set of cryptographic functions built into all modern browsers. The passphrase you enter never leaves your device. The server receives only the encrypted output, which is meaningless without the passphrase.

This is different from "encrypted in transit" (HTTPS), which protects data while it moves across the network but leaves it readable on the server. With PrintGuard, even the server operator cannot read your file — not during upload, not during storage, and not during printing.

The printing step

When the print shop enters the job code and passphrase, the browser downloads the encrypted blob from the server and decrypts it locally, again using the Web Cryptography API. The plaintext file exists in the browser's memory for only as long as the print dialogue is open. It is never written to disk on the print shop computer.

After the shop confirms printing, a deletion request is sent to the server, and the encrypted blob is permanently removed. An automatic expiry mechanism deletes all blobs within one hour of upload regardless, so if a session is abandoned the file is still cleaned up.

What this means for you

In practical terms, it means that even if someone intercepted the network traffic, broke into the server, or stole the hard drive, they would have nothing but ciphertext — data that is mathematically useless without the passphrase you chose.

The passphrase is the only secret. Keep it strong (at least 10 characters with a mix of letters and numbers), share it only verbally with the print shop operator, and your document remains private throughout the entire journey.