Skip to content

Threat Model

  • Theft of device (PC, laptop, external drive)
  • Unauthorized physical access to PC or server
  • Remote exfiltration of encrypted files
  • Ransomware targeting already-encrypted files
  • Clone of dongle identity via same seed (mitigated by K_attestation)
  • Advanced physical chip attacks (side-channel, fault injection, electron microscope)
  • Malware with system-level privileges active during a decryption session
  • Server compromise with K_vault already loaded in RAM
  • Manual copy of content during an authorized session

lake8.dev is architecturally incapable of providing decryption keys to third parties. This is a construction property, not a policy promise.

“The root secret never leaves the dongle. lake8.dev cannot decrypt your files — not by choice, but because it is technically impossible.”