🔴 BETA — You are the red team
You build it. We activate it.
30 September 2026 — free for all beta participants.
The beta is for developers and security researchers who want to test the architecture, integrate the protocol, or give feedback before public launch.
We do not ship hardware during the beta. You source the ESP32-S3 yourself. That is intentional — the whole point is that any commodity chip becomes a Crypt-in dongle.
Beta dongles run Secure Boot v2 and Flash Encryption active— identical to the dongles of the public launch. There is no reduced version for the beta, and no dongle in a tester's hands is left unburned.
Flashing is what burns them. The moment the Crypt-in firmware is written to your ESP32-S3 the eFuses are burned: lake8.dev secure boot key, flash encryption, JTAG permanently disabled. From that point the board is a Crypt-in dongle with exactly the protections a launch unit has.
Burning eFuses is irreversible. Use a board you are willing to dedicate to Crypt-in: after the first flash it does not go back to being a general-purpose ESP32-S3, it will not accept unsigned firmware, and read-flash is refused. That is the point — but it is worth knowing before you connect the €5 board you were using for something else. Details in the flash guide and the security model.
Any ESP32-S3 board with a native USB-C OTG port works. This is what we develop and test on, and where it ends up.



Every Crypt-in beta participant is officially part of our security program.
Before this beta we ran three red team sessions using Claude Opus 5, with full source access, DnSpy, admin rights and a live dongle. We published everything — every attack, every byte of response, every finding.
Read the full red team report →
"I broke it" — tell us how.
"I couldn't break it" — tell us that too.
Both answers are valuable.
The most significant finding reported during the beta period will be acknowledged by name in the Q1 2027 public launch security report.
Three red team sessions ran before this beta — session 4 is this beta. The findings from the developer beta will be incorporated into the Q1 2027 public launch security report, alongside any fixes applied before launch.
Report security findings → security@lake8.dev
We tell you where the wall is low, so you know where to put the guard. Response times, the disclosure process and the PGP key are on the responsible disclosure page.
| Item | Beta |
|---|---|
| Firmware (signed binary) | Free |
| Windows client (Personal v1) | Free |
| SDK + Linux CLI (Apache 2.0) | Free |
| Licence activation (6 months) | Free |
| Automatic renewal if the beta continues | Free |
| Direct feedback channel | info@lake8.dev |
| Source code (firmware + tools) | Access at beta launch |
No credit card. No payment during the beta. Free automatic renewal while the beta continues; standard €30/year when the beta ends.
The source repository is private today and there is no public channel before 30 September 2026. Beta participants get access through dedicated channels at launch. What is public right now are the specifications: the HID protocol and the .crin format are documented in full, in enough detail to write an independent client.
Beta licence terms. There is an expiry — it renews itself free while the beta runs.
Expiry gates new encryption only. Files you have already encrypted stay decryptable forever with your dongle, licence or no licence.
Flash this on your ESP32-S3 to turn it into a Crypt-in dongle.
cryptin-firmware-beta.bin
SHA256: [Available at beta launch — 30 September 2026]
Signed with the lake8.dev firmware key.
Encrypt and decrypt .crin files on Windows.
setup.exe
SHA256: [Available at beta launch — 30 September 2026]
Windows 10/11 — 64-bit only.
Windows DLL + .NET 9 CLI for Linux and macOS. One package, one licence — the CLI is part of CryptinSDK, not a separate product. No licence key required.
github.com/lake8dev/cryptin-sdk
SHA256: [Available at beta launch — 30 September 2026]
Available at beta launch. The repository does not exist yet.
Full transparency: every component of the firmware and of the CLI is declared in the Software Bill of Materials → — SPDX 2.3, one document per artefact, published before the binaries ship. The Windows client, Personal v1, has no SBOM of its own yet.
First boot generates your keys — on your hardware, in your hands. We never see your seed. The full sequence is documented.
Beta testers get direct access to the developer.
[BETA] your topicBy participating in the Crypt-in beta, you acknowledge that:
By participating in the beta you accept the lake8.dev Terms of Service and Privacy Policy.