🔧 Developer beta launches 30 September 2026 — free for developers. Flash your own ESP32-S3 and test it. Learn more →

Your key is in your pocket.

Hardware-backed root of trust for file encryption and document management. Vendor-blind by architecture.

Is Crypt-in for me? →

How it works

How Crypt-in works, in three stepsInsert the dongle and your files become accessible. Remove it and they become inaccessible again.Insert dongleRoot secret stays on chipFiles accessibleDecrypted on demandRemove dongleFiles inaccessible

Unplugging is the whole revocation mechanism — no console, no network call, no session to expire. The session closes in under 5 seconds; wait at least 5 seconds before plugging the dongle back in, because a fast replug may not fully power-cycle the chip. Seeclosing the security window.

Products

Personal

File encryption on your own machine. The dongle holds the root secret; files stay readable only while it is plugged in.

Explorer — €50 one-time

Encrypted file manager for Windows. Browse, open, move and rename .crin files as if they were normal files. No drag-and-drop required. Available at public launch — April 2027. Windows 10/11 required; Linux and macOS planned, no date confirmed.

Vault

Zero-knowledge document server. Remove the dongle and the vault goes blind in under ten seconds. That is physical removal. Separately, an idle dongle left plugged in auto-locks after roughly ten minutes — though any command resets that timer, so it only protects a genuinely idle chip.

SDK

Integrate the HID protocol and the .crin format directly into your own applications.

Every Crypt-in product requires a physical dongle. The dongle is an ESP32-S3 (~€5): source it yourself or buy our Kit.

Currently in development

Developer beta — 30 September 2026. Every Crypt-in dongle is an ESP32-S3: commodity hardware available anywhere, in a case we designed. Kits will ship assembled, flashed and tested.

Join the waitlist →

For professionals

Order the Kit Standard. It arrives flashed, tested and ready. Plug it in, activate, start encrypting. No terminal required.

Order Kit Standard →

For developers

Buy any ESP32-S3 (~€5 anywhere), flash the signed firmware yourself, activate your licence.

Developer Beta →
Crypt-in dongle, anthracite case with the key logo on the lid and lake8.dev engraved on the side: the ESP32-S3 dev board variant, with two USB-C ports on the front
ESP32-S3 dev board — two USB-C ports
The same Crypt-in case in the compact ESP32-S3 Supermini variant, with a single USB-C port on the front
ESP32-S3 Supermini — one USB-C port

Renders of the case design — anthracite PLA, key logo on the lid, lake8.dev marking on the side.

Why Crypt-in

Physical kill switch

Unplugging the dongle is the revocation mechanism — the session closes in under 5 seconds. No console, no network call, no waiting for a session to expire. Wait at least 5 seconds before reconnecting, to be sure the chip fully powered down.

Offline-first

The licence server is contacted at activation, then only for annual renewal, for registering a backup dongle (one per calendar year) and for transferring the licence to a replacement dongle — at most three times a year. Decryption works forever on your existing files: no network, no expiry. New encryption requires an active licence (€30/year).

Zero-knowledge by architecture

The root secret never leaves the chip. lake8.dev cannot decrypt your files — not by policy, but because it is technically impossible.

Read the threat model for an explicit account of what Crypt-in does not protect against.

The risk continuumA scale from low to high risk with four kinds of adversary: a curious colleague, an opportunistic thief, a targeted attacker and a state-level adversary. Crypt-in covers the first three; the fourth is explicitly out of scope.LOW RISKHIGH RISKCuriouscolleagueOpportunisticthiefTargetedattackerState-leveladversaryCrypt-in covers thisOut of scope
See who Crypt-in is for →

Your keys, not ours

Whichever route you take, the part that matters is identical: we sell the activation, not the keys.

Buy the Kit

We ship it ready: assembled, flashed and tested. The factory test ends by erasing NVS, so the keys it generated are destroyed before the dongle is boxed.

Or source it yourself

Any ESP32-S3 becomes a Crypt-in dongle. Buy it wherever you like: we have no idea where your chip came from, and no reason to.

Either way, activation is yours

We ship hardware with firmware, no keys and no identity. Your dongle has no secrets until you power it on.

At first boot your dongle generates its own keys from hardware entropy. That moment happens in your hands, not ours.

lake8.dev has never seen your seed.
lake8.dev cannot see your seed.
Not even if you buy the Kit.

The full sequence is documented step by step in First Boot Key Generation.

What reaches lake8.dev and what does notK_root, K_attestation and the recovery seed never leave the dongle. Session keys, file keys and .crin files stay on the user device and are never transmitted. lake8.dev always receives payment data and the public half of K_identity.DongleUser devicelake8.devK_rootK_attestationK_recovery seednever leave the chipNEVER TRANSMITTEDK_sessionK_file.crin filesALWAYS RECEIVEDpayment dataK_identity pubkeyThis is an architectural property, not a policy promise.

At activation you also choose how much you tell us about yourself: an anonymous activation sends no email, no name and no tax ID. See the full activation model →

Your seed, your responsibility

The 24-word recovery seed works like a crypto wallet. Write it down. Store it safely. Never share it. If you lose it we cannot help — and neither can anyone else. That is the guarantee.

Extreme cold storage

Buy a dongle. Write down your 24 words and PIN. Encrypt your files. Upload them to Google Drive — publicly, if you want. Verify everything opens. Destroy the dongle.

☁️Google has your files
🏛️Your government has your files
🌍Everyone has your files
🔒Nobody can open them

Four years later, buy a €5 chip. Type your 24 words. Your files open.

The dongle lived for 10 minutes. The encryption lasted forever.

And one more thing. Nobody memorises 24 random words. You cannot be made to recite what was never in your head — the secret is on a piece of paper, not in your memory.

That is not protection from coercion, and we do not claim it is: the threat model says plainly that no technology is. Where the paper lives stays a human problem.

Upload your secrets to Google Drive. Nobody can open them.Not even us.