MoatGoat DRM

Enterprise PDF DRM — On-Premises

Your documents.
Your server.
Your keys.

When a document leaks, it's usually not the encryption that failed.

MoatGoat solves the part everyone ignores: your files are encrypted and served from your infrastructure, with keys that never leave it. Not even to us.

10 documents/month free · No credit card

moatgoat protect
$ curl -X POST https://your-server/api/v1/documents/protect \
     -H "X-Api-Key: mgk_•••" \
     -F "file=@due-diligence.pdf" \
     -F "expiresAt=2026-09-30" \
     -F "maxPrints=2" \
     -F 'watermark="{name} — {date}"'

  Encrypting    AES-256-GCM (random IV per session)
  Key wrap      RSA-4096 from your server
  Document ID   7f3a9b2e-4c81-4d2e-aa9f-…

  ✓ due-diligence_drm.pdf  (211 KB)
    0 bytes left your firewall.
AES-256-GCMRSA-4096SAML 2.0 / OIDC / ADWindows · macOS · LinuxiOS · AndroidInstant revocationZero vendor access

Every decryption call goes through your server

Not a cloud relay. Not a key escrow service. When a recipient opens a protected file, the viewer connects directly to your on-premises server to verify the license. The decryption key never exists outside your infrastructure.

Your PDF
Original file
Encrypted on your server
AES-256-GCM
_drm.pdf
Distribute anywhere
Recipient
Any device
MoatGoat Viewer
Native app
Verified by your server
License check

Your server is in the loop on both ends. If your server goes down, documents don't open. That's the point.

You don't trust us with your documents.
Good.

We designed MoatGoat assuming you'd never hand us your files. Your server runs the encryption engine. Your server holds the RSA key pairs. Your server handles every license verification request.

MoatGoat's role is authentication, billing, and the viewer apps — not your content. We have no technical means to decrypt your documents, and we structured the system that way deliberately.

If a regulator, a subpoena, or a data breach ever touches MoatGoat's infrastructure — your documents are not there to find.

How it works in practice

The features that matter to the people who actually use this.

Encryption

Not password protection. Actual encryption.

PDF password "protection" is a permission flag that Acrobat enforces voluntarily. Any PDF library can strip it in one line of code. MoatGoat replaces the file content entirely — a stolen _drm.pdf is binary noise without an authorized viewer session.

Unique AES-256-GCM key per document
Random IV per session · RSA-wrapped for the requesting device

xxd due-diligence_drm.pdf | head
00000000: 4d47 444d 5201 0000 0001 7f3a 9b2e 4c81
00000010: a4f7 219b c3e8 5f10 b832 40dc 917e 6a2b
00000020: f19c 3d48 02c7 e5a8 9b14 7623 d4f8 1e05
00000030: 8e2a c041 7fd9 3b62 aa05 f317 c8e6 4d90
00000040: 3b7f 018d e249 c56a 8012 baf1 60dc 223e
...
(211 KB of this. Acrobat sees garbage.)
maxPrints3 total, or 1/day, or both
maxDevicesMax N simultaneous registered devices
expiresAtHard date or TTL from first open
offlineHoursN hours without connectivity
watermark{name}, {email}, {date}, {ip}
copyPasteDisabled at render level — not a flag

Access policies

Per-document, per-recipient control

Set different rules on every encryption call. An investor gets 2 prints and a 30-day expiry. A contractor gets 8 hours offline. A prospect gets view-only with a watermark. All enforced by your server on every open — not by trust.

Identity

Recipients use the credential they already have

No separate MoatGoat account for your employees or clients. The viewer authenticates through your corporate IdP — Okta, Azure AD, Active Directory, or any SAML 2.0 / OIDC-compliant provider.

OktaAzure ADActive DirectorySAML 2.0OpenID ConnectOAuth 2.0 + PKCE

Audit

Know who opened what, when, and from where

Every open, failed auth, print attempt, and device registration is logged with timestamp, IP address, user agent, and device fingerprint. Stored on your server. Exportable for legal discovery, compliance audits, and leak investigations.

Built for teams where leaks have consequences

Legal & Compliance

The M&A prospectus went out to twelve parties. Three weeks later it's on a competitor's desk and nobody admits to leaking it. With MoatGoat you know which device opened it on which date — and you already revoked access for the party who dropped out before the leak happened.

Financial Services

Investor reports and LP updates contain material non-public information. You need an audit trail that holds up to SEC or FCA scrutiny. A cloud DRM vendor's access log is their word against yours. Your own server's logs are yours to produce.

Healthcare & Life Sciences

Clinical trial protocols, patient case summaries, and IRB documents are PHI the moment they touch a cloud server. HIPAA doesn't care that the vendor signed a BAA — it cares where the data lives. On-premises means the question doesn't arise.

Engineering & IP

Technical schematics shared with contractors don't need to be leaked — they need to be unrecoverable when the contract ends. Revoke access at termination. The file they downloaded last month is unreadable from that moment. No file recall. No phone calls.

MoatGoat isn't the right tool for everyone

If you're protecting casual personal PDFs, Acrobat password protection is free and probably enough. We're built for teams where a leaked document triggers a legal response, an SEC inquiry, or a lost deal — not just an angry email.

You also need a server to run this. A Docker-capable machine in your datacenter, VPC, or private cloud. If managing that isn't something your team wants, we're probably not the right fit right now.

Try it before you commit

Open a real DRM-protected file. It's unreadable in Acrobat — try that first.

1 — Get the viewer

Download the MoatGoat Viewer for Windows. The protected file won't open in anything else.

Download Viewer

2 — Download the sample

A real protected PDF. AES-256-GCM encrypted. Open it in Acrobat first — you'll see what we mean.

Download sample.pdf

3 — Open in the viewer with these credentials

Email     sample@email.com
Password  Testdrmrocks01

Start free. Own your DRM stack.

Free plan covers 10 documents/month — enough to test with a real workflow. Paid plans start at $220/month when you're ready to go further.

Questions? Contact us