PDFly · Blog
The Contract I Accidentally Sent to the Wrong Person
It happened during a late night. I was exhausted, trying to get a contract out to a new client so they would have it first thing in the morning. I attached the file, typed a quick email, hit send, and closed my laptop. It wasn't until the next morning that I realized I had sent it to a completely different person with a very similar name. That person was an old client, and I had just sent them a contract that included pricing, terms, and details that were absolutely none of their business.
I felt sick. It was a complete disaster.
I called the person immediately and asked them to delete the file. They said they would. I had no way of verifying that they actually did. I spent the next three days worrying about it, checking my inbox every five minutes, and hoping nothing came of it. Nothing did, but the feeling never really went away. That moment changed how I think about PDF security forever.
What I should have done before sending that email
In hindsight, the solution was so simple. If I had password-protected that contract, the person who received it accidentally would not have been able to open it. They would have seen a prompt asking for a password, realized they were not supposed to have it, and probably just deleted it without a second thought. Instead, I sent an unprotected file that any random person could open and read.
I learned that lesson the hard way. And since then, I've been annoyingly careful about protecting PDFs. But I've also discovered that security isn't just about passwords. There's a whole world of things you can do to protect a document, and I wish I had known about them earlier.
Passwords are not as simple as they seem
I used to think that if you password-protect a PDF, you just type in a password and you're done. That's not exactly true. There are actually two different types of password protection you can apply. One of them prevents someone from opening the document at all. The other prevents someone from editing or printing it, even if they can open it. I didn't know there was a difference until I spent twenty minutes trying to figure out why I could open a document but couldn't copy text from it.
That distinction matters more than you might think. If you're sending a document to someone you trust but you don't want them to edit it, you can set a permission password. They can read it just fine, but they can't change anything. If you're sending a document to someone who you're not sure should even be seeing it, you set an open password. That way, only people with the password can view the content at all.
I've also learned that some password-protected PDFs are basically useless if someone is determined enough. The security is only as good as the password. If the password is something obvious or easy to guess, it's not really protecting much. I used to use simple passwords because I was afraid of forgetting them. Now I use password managers, which means I can use long, complex passwords without worrying about remembering them.
The one security feature I completely ignored for years
For a long time, I didn't even know redaction was a thing. I thought if you needed to remove something from a PDF, you would just use the edit tool to delete the text or use a black rectangle to cover it up. It turns out that's not how it works. If you cover text with a black rectangle and save the file, the text is still there. Anyone who knows what they're doing can just remove the rectangle and see the information underneath. I learned this when a colleague sent me a redacted document that I was able to reveal the hidden information from in about two minutes. They had no idea it wasn't secure.
Redaction is different from covering up. When you properly redact something, the information is permanently removed from the document. It's not just hidden — it's gone forever. You can't get it back. That's what you need to do when you're dealing with sensitive information like social security numbers, bank account details, or confidential business information.
I had a document that needed redaction once, and I had no idea what I was doing. I used an online tool that claimed to redact PDFs, and it was a disaster. The tool was incredibly slow, it made the document huge, and I was never quite sure if it had actually removed the information or just hidden it. I ended up just recreating the document from scratch, which was time-consuming and frustrating.
Now I know that proper redaction tools show you exactly what has been redacted and verify that the information is completely removed. That verification step is something I never knew existed, and it made a huge difference in my confidence about what I was sending.
What I still mess up sometimes
I'm not going to pretend I've figured everything out. I still make mistakes. Sometimes I'm in a rush and I forget to protect a document that I should have protected. Other times I set a password and then forget to actually test it before sending the file. That's always a fun surprise for the recipient when they try to open it and it doesn't work.
I also still struggle with the balance between security and convenience. If I put a password on every document, people get annoyed. But if I skip it on something sensitive, I worry about it all day. I haven't found a perfect solution yet. The best I've come up with is that I err on the side of caution and only leave documents unprotected if they're genuinely public information. That means a lot of extra clicks and a lot of passwords, but it also means less worrying.
There was one time I sent a protected document to a client and realized the password was in the subject line of the email. That kind of defeats the whole purpose, doesn't it. I had put the password in the email body, but the client had read the subject line first and tried that, and it didn't work. So they were confused. Eventually, they read the email properly, but for a few minutes, they thought I had sent them a broken file. That was a good reminder to keep passwords separate from the email.
What I actually do now
These days I don't really think about security in terms of one big solution. I think about it in terms of layers. A password is one layer. Redaction is another. Making sure I send the right file to the right person is another. None of these are perfect on their own, but together they make it much harder for anything to go wrong.
I've also started thinking about security differently. It's not just about preventing bad things from happening. It's also about having a plan for when things do go wrong. What happens if you send a document to the wrong person? What if you need to recall a file? What if someone opens a document they're not supposed to? Having a plan for those situations makes the whole thing less stressful.
One thing I do now is before I send any sensitive document, I stop and think about what would happen if the wrong person got it. If the answer is "something bad," I protect it. If the answer is "nothing really matters," I don't. It's a simple rule, but it forces me to actually think about what I'm sending.
And for the actual protecting part, I use PDFly's Protect PDF tool. It handles both types of password protection and shows me exactly what I'm setting up. I don't have to guess whether I'm doing it right. It's one of those things where I just wish I had found it earlier, before that late-night email incident. It would have saved me a lot of worrying.
The contract incident happened a few years ago, and I still think about it sometimes. It's a reminder that PDF security isn't optional if you're dealing with sensitive information. It's just something you have to do, every time, even when you're tired or in a rush. Because it only takes one slip-up to turn a simple document into a much bigger problem.
Alex Rivera
PDFly Team