Who Is Crypt-in For?
This is the most honest page on this site. Read it before buying anything.
The profiles that fit
Section titled “The profiles that fit”The independent professional
Section titled “The independent professional”You are a lawyer, accountant, doctor, notary, financial advisor, or consultant.
You have confidential client documents on your laptop: contracts, medical records, financial statements, legal strategies. Things that cannot leak.
Your risk is concrete and common:
- laptop stolen from your car or office
- external hard drive lost during travel
- old PC sold or discarded without wiping it properly
- a colleague or employee who should not have access
Crypt-in solves this. Your files are encrypted with a key that lives on a physical dongle in your pocket. No dongle, no access. Even if someone has your laptop, your disk and your backup, nothing opens.
The small business
Section titled “The small business”You run an SME, a professional studio, an agency, a small manufacturing company.
You have commercially sensitive data: offers, contracts, price lists, patents, supplier relationships, product formulas.
Your risk:
- a disgruntled employee copies everything before leaving
- a competitor gets access to your systems
- ransomware encrypts your data and someone pays the ransom — but the data had already been copied before the encryption
Crypt-in solves this. The Vault keeps your most sensitive documents on your own server, encrypted with a physical key. No cloud, no vendor with access. Unplug the dongle and the server goes blind in under ten seconds.
The developer and security researcher
Section titled “The developer and security researcher”You build things. You understand what you are buying. You want control, not trust.
You want to check that the device does what it says — by exercising the protocol yourself, not by taking a datasheet on faith. You want to flash your own ESP32-S3 and not depend on anyone for the hardware. You want to read the protocol specification and implement your own client if you feel like it.
Crypt-in is built for you first. The HID protocol is publicly documented, the .crin format has a published specification, the SDK is open source under Apache 2.0, and the hardware is commodity — you source it yourself. We activate, you build.
The firmware itself is closed source, distributed as a signed binary: with its source, anyone could strip the PIN and the licence check and rebuild the product. Nothing about it is needed to write your own client — the protocol and the format are enough, which is the point.
The privacy-conscious individual
Section titled “The privacy-conscious individual”You are a journalist, an activist, a researcher, or simply someone who takes their digital privacy seriously.
You have documents, sources, communications or personal data that you do not want in any cloud, on any server you do not control, or accessible to anyone without your explicit consent.
Your risk:
- cloud storage breached or subpoenaed
- a service provider that complies with government requests
- a data breach that exposes your private life
Crypt-in solves this. lake8.dev cannot decrypt your files — not by choice, by architecture. The key never leaves your dongle. We have never seen it, and we cannot hand it to anyone because we do not have it.
The extreme case — cold storage
Section titled “The extreme case — cold storage”This is not a typical use case. It is a real one, and it shows what vendor-blind architecture actually means when you push it.
The scenario
- Buy a dongle — a €5 ESP32-S3 or the Kit Standard
- Write your 24 words and your PIN on paper
- Encrypt your files
- Make five or six encrypted copies on different media
- Upload them to Google Drive, Dropbox, anywhere — publicly if you want
- Verify that everything opens
- Destroy the dongle
Your files are now on Google’s servers, on every cloud you uploaded them to, visible to anyone who knows where to look.
Nobody can open them. Not Google. Not your government. Not lake8.dev. Not you, until you restore the seed.
Four years later
- Buy a new ESP32-S3, ~€5, anywhere
- Flash the firmware
- Type your 24 words
- Your PIN comes back on its own — it is derived from the seed, not stored
- Your files open
One practical note: decryption never depends on a licence, so old files open on a restored dongle regardless. Encrypting new files does need an active licence and one of the three annual transfers.
Why it works
The file keys derive from your 24 words. Those words never left the paper. The dongle was a vessel: useful for ten minutes, then thrown away. lake8.dev cannot help anyone open those files, because lake8.dev never held the key material.
And one more thing. Nobody memorises 24 random words. You cannot be made to recite what was never in your head — the secret lives on paper, not in memory. That is not immunity from coercion, and this page is the wrong place to pretend otherwise: the summary below lists physical coercion among the things Crypt-in does not solve, because no technology does. What changes is narrower and real — where the paper is remains a human problem, not a cryptographic one.
The only three things that matter
- your 24 words, on paper, somewhere safe
- the
.crinfiles, anywhere, even public - a €5 chip, available everywhere, indefinitely
The CIA test
Section titled “The CIA test”Now the important part.
You fit one of the profiles above. But before you buy, answer this honestly: who is after you, and why?
Crypt-in protects you from opportunistic threats — theft, curiosity, carelessness, ransomware. It does not protect you from targeted, well-resourced, professional adversaries.
Here is the honest breakdown.
You are a lawyer with normal clients
Section titled “You are a lawyer with normal clients”Your risk: laptop theft, a curious colleague, ransomware, an old disk with client data on it.
→ Crypt-in is your solution. These are exactly the threats it was designed for.
You are a lawyer defending a whistleblower against a government
Section titled “You are a lawyer defending a whistleblower against a government”Your risk: state-level surveillance, targeted malware, physical interception, legal coercion to hand over keys, sophisticated adversaries with resources and patience.
→ Crypt-in is not enough.
Not because it is poorly made. Because no €100 product protects against a determined state actor with budget, technical capability and legal authority.
What you need instead:
- air-gapped devices for sensitive work
- specialised legal counsel on digital evidence
- threat modelling with a professional cybersecurity firm
- physical security protocols
- possibly Tails OS, Signal, and tools designed specifically for high-risk work
Crypt-in can be part of a layered defence. It cannot be the whole defence.
You are a small business with normal data
Section titled “You are a small business with normal data”Your risk: employee data theft, opportunistic competitor espionage, ransomware.
→ Crypt-in is your solution.
You are a small business with trade secrets worth millions
Section titled “You are a small business with trade secrets worth millions”In a contested industry, with known state-sponsored competitors.
Your risk: sophisticated industrial espionage, targeted attacks, insider threats with professional backing.
→ Crypt-in is not enough.
You need a specialised cybersecurity firm, penetration testing, physical security audits, employee screening, and a security budget proportional to what you are protecting.
Crypt-in can protect the files on a laptop. It cannot protect a company from a coordinated intelligence operation.
You are a journalist covering local corruption
Section titled “You are a journalist covering local corruption”Your risk: sources leaking, files stolen, a laptop seized without notice.
→ Crypt-in is your solution. Your sources and documents are encrypted. A stolen laptop reveals nothing. A seized disk reveals nothing.
You are a journalist investigating a government or organised crime
Section titled “You are a journalist investigating a government or organised crime”Your risk: targeted surveillance, device compromise at OS level, physical threats, legal pressure, and adversaries who can invest serious resources to find your sources.
→ Crypt-in is not enough on its own.
Talk to the Committee to Protect Journalists or Reporters Without Borders before anything else. They have specialised resources for exactly this.
The risk continuum
Section titled “The risk continuum”Security is not binary. It is a scale.
The honest summary
Section titled “The honest summary”Crypt-in is for people who want serious protection against common, realistic threats: without complexity, without cloud dependency, without trusting a vendor with their keys.
It is not for people facing adversaries with unlimited resources, state-level capabilities, or legal coercive power.
If you are not sure which category you are in, ask yourself: would the realistic threat be a professional thief or a curious employee — or an intelligence agency?
If the answer is the first: welcome. If it is the second: call a specialist. If you are not sure, read the threat model and the security model first, then decide.
Crypt-in is made by lake8.dev, a one-person software house in San Pietro in Casale, Bologna, Italy. We are not a cybersecurity agency. We are engineers who built a tool we use ourselves and decided to make available to others.
If your problem requires a cybersecurity agency, we are happy to point you in the right direction. Write to info@lake8.dev.
Terms of ServicePrivacy PolicySecurity contact: security@lake8.devVulnerability Disclosure Policy
Alcuni contenuti sono stati redatti con il supporto di strumenti di intelligenza artificiale generativa e revisionati dall'autore. Le immagini hardware hanno scopo puramente illustrativo.
Some content was drafted with the support of generative AI tools and reviewed by the author. Hardware images are purely illustrative.
Einige Inhalte wurden mit Unterstützung generativer KI-Werkzeuge verfasst und vom Autor überprüft. Hardware-Abbildungen dienen ausschließlich illustrativen Zwecken.
Algunos contenidos han sido redactados con el apoyo de herramientas de IA generativa y revisados por el autor. Las imágenes de hardware tienen carácter meramente ilustrativo.
In caso di conflitto tra versioni linguistiche, prevale il testo in lingua italiana.