Your key is in your pocket.

Hardware-backed root of trust for file encryption and document management. Vendor-blind by architecture.

Products

Personal

File encryption on your own machine. The dongle holds the root secret; files stay readable only while it is plugged in.

Vault

Zero-knowledge document server. Remove the dongle and the vault goes blind in under ten seconds.

SDK

Integrate the HID protocol and the .crin format directly into your own applications.

Why Crypt-in

Physical kill switch

Unplugging the dongle is the revocation mechanism. No console, no network call, no waiting for a session to expire.

Offline-first

The license server is contacted once at activation. After that the dongle works with no network at all, indefinitely.

Zero-knowledge by architecture

The root secret never leaves the chip. lake8.dev cannot decrypt your files — not by policy, but because it is technically impossible.

Read the threat model for an explicit account of what Crypt-in does not protect against.