Upload your secrets to Google Drive. Nobody can open them. Not even us.
This is not a privacy policy promise. It is an architectural property: lake8.dev cannot decrypt customer files because the key material was never transmitted to us. Not by choice — by construction.
A user buys a Crypt-in dongle, encrypts their files, uploads everything to Google Drive — publicly — and destroys the dongle. Four years later they buy a €5 chip, type 24 words, and the files open. In those four years the data sat in plain sight, mathematically inaccessible to everyone. Including us.
Not even to the owner, without that piece of paper. Nobody memorises 24 random words, so the secret is not in a person's head — which is a smaller and more honest claim than immunity from coercion, something our threat model says no technology provides.
Crypt-in — July 2026
This document is public and intentionally transparent. Radical transparency is a design principle at lake8.dev, not a pitch strategy.
Crypt-in is a hardware-backed root of trust commodity. The root secret never leaves the dongle. The computer never possesses the key.
€30/year
File encryption into .crin containers.
€50
Encrypted file manager.
€150 + €100/year
Dedicated support for HID protocol and .crin integration. The SDK itself is Apache-2.0 and free.
€100/month
Self-hosted, vendor-blind document server.
| Capability | Crypt-in |
|---|---|
| Commodity DIY hardware (~€5) | yes |
| Physical hardware kill switch | yes |
| Instant kill switch on USB removal event | yes |
Universal cross-platform .crin format | yes |
| Vendor-blind self-hosted Docker vault | yes |
| Granular SME pricing | yes |
| EU manufacturer — GDPR and CRA scope | yes |
| Structurally zero CAC (agentic-first) | yes |
Competitive research conducted July 2026. No product currently combines all of the above. This is a claim about the combination — each element exists elsewhere in isolation.
Each physical ESP32-S3 chip generates a unique hardware attestation key (K_attestation) from hardware entropy, independent from the recoverable BIP-39 seed. The license server binds activation to K_attestation — a clone built from the same seed is detected and blocked.
Verified on real hardware: Krypt@9c756da, Krypt@d3e71df.
lake8.dev also receives the tax/VAT number where invoicing requires it. It never receives the root secret, the BIP-39 seed, encrypted files, session keys, the Vault master secret, or telemetry of any kind.
This is an architectural property, not a policy promise: the material required to decrypt was never transmitted, so no policy change or legal order can produce it.
The licence server is contacted at activation, then only for annual renewal and for transferring a licence to a replacement dongle — at most three times a year. There is no periodic check-in during normal use. lake8.dev could shut down tomorrow: already-activated dongles keep decrypting forever.
Krypt@9c756da, Krypt@d3e71df)server-licence@a472adc)llms.txt, llms-full.txt and a knowledge-graph.json of 17 nodes, published and interlinked with the lake8.dev graph. JSON-LD injected in the <head> of every page; schema.org validation passes with zero errors and zero warnings
Prototype render — ESP32-S3 in anthracite PLA case. Case design, not a photograph of a production unit.
| Milestone | Status | Date |
|---|---|---|
| Firmware K_attestation | ✅ Complete | July 2026 |
| Licence server K_attestation | ✅ Complete | July 2026 |
| HID end-to-end test (7/7) | ✅ Complete | July 2026 |
| cryptin.lake8.dev live | ✅ Complete | July 2026 |
| SBOM published (SPDX 2.3) | ✅ Complete | July 2026 |
| Flash encryption + secure boot | ✅ Complete | July 2026 |
| Secure boot verified on production hardware | ✅ Complete | July 2026 |
| Windows client (Personal v1) — core flows (main window, PIN, serial recovery) verified on hardware. Setup, activation and payment wizards not yet exercised by an external user. | ✅ Complete | August 2026 |
| Internal security audit (3 sessions) — 3 internal red team sessions conducted by lake8.dev using Claude Opus 5. Full report published at /security/red-team-2026-08/. Not equivalent to an independent third-party audit: that is planned from Q3 2027, subject to budget and enterprise demand, and is not a blocker for the April 2027 public launch. | ✅ Complete | August 2026 |
| SDK open source (Apache 2.0) — code complete and licensed Apache 2.0 since August 2026. The repository is private until it opens at the developer beta; there is no public address yet. | 🔄 In progress | Opens 30 September 2026 |
| Red team (developer beta) — all developer beta participants are official red team members. Report findings to security@lake8.dev. | 🔄 In progress | From 30 September 2026 |
Linux CLI client — CLI wrapper around CryptinSDK. .NET 9, cross-platform, Apache 2.0. cryptin encrypt / cryptin decrypt. Ships with the developer beta to cover all platforms. Fallback: 30 October 2026. | ⏳ Planned | Target 30 September 2026 |
Python client — if ready earlier, it ships earlier. Apache 2.0. The Python files in tools/ today are an internal test harness, not a client. | ⏳ Planned | Q2 2027 |
| Developer beta launch | ⏳ Planned | 30 September 2026 |
| Public launch | ⏳ Planned | April 2027 |
| Independent protocol audit — subject to budget and enterprise demand. Not a blocker for the public launch. | ⏳ Planned | From Q3 2027 |
Dates for planned items are targets, not commitments. The four proofs below gate the public launch: if one of them is not demonstrated, the date moves.

Kit Standard, render of the case design at true scale — it fits between two fingers, with an ESP32-S3 inside. Kits ship pre-flashed and tested; the factory test ends by erasing NVS, so the keys you use are generated at first boot in your hands, never in ours.
| Proof | Metric |
|---|---|
| Cryptographic | .crin spec published with test vectors |
| Security | Independent protocol audit report |
| Usability | 10 non-technical users complete setup and recovery |
| Commercial | 50 Year-2 renewals on Windows |
These are gates, not milestones. Expansion — multiplatform, Vault, SDK — happens only after all four are demonstrated.
We are not raising now.
Crypt-in is bootstrapped. The infrastructure runs on lake8.dev's existing Raspberry Pi setup. Development cost is near zero — the founder directs architecture, Claude Code accelerates implementation.
We will consider external capital after:
At that point, external capital makes sense to fund: independent security audit, CE marking for Kit Pro, and vertical marketing (legal, medical, manufacturing).
We are not open to equity dilution.
We consider non-dilutive instruments only:
Full-stack developer, embedded systems, applied cryptography. Architect of Crypt-in, lake8.dev Customer Zero. San Pietro in Casale, Bologna, Italy.
The entire stack — firmware, license server, Windows client, infrastructure — is developed using an AI-assisted pipeline directed by the founder. Every architectural decision is made by a human. The pipeline enables solo-founder velocity without compromising on technical depth.
Lagotto BI, Lagotto Meter and MRP Scheduler run in production on a Raspberry Pi 4B. The same discipline that keeps lake8.dev at PageSpeed 100/100 on ARM hardware informs every Crypt-in architecture decision.
If you are a business angel, seed fund, system integrator, or potential Certified Integrator partner, write directly to:
No pitch deck required upfront. Read this page — if it makes sense to you, we can talk.
Full technical documentation ·Vulnerability Disclosure Policy