File → Protect… sets a password on a document. The password is applied when the file is downloaded: what leaves Seben is encrypted, and inside Seben the document stays viewable and editable by people who already have access to the workspace.
A password is 8 to 256 characters. Seben does not keep it anywhere it can be read back, only enough to check that a password you type later is the right one. If you forget it, nobody at Aqili can recover it for you.
To remove protection, open File → Protect… again and enter the current password.
A signed document can’t be protected, because encrypting it would rewrite the file and leave its signatures unverifiable.
Because protection applies to downloads, an AI client connected with a workspace API key can read a protected document’s text. Downloading it through that client needs the password and returns the encrypted file; see MCP clients.