Crypt-in — July 2026
This document is public and intentionally transparent. Radical transparency is a design principle at lake8.dev, not a pitch strategy.
Crypt-in is a hardware-backed root of trust commodity. The root secret never leaves the dongle. The computer never possesses the key.
€30/year
File encryption into .crin containers.
€50
Encrypted file manager.
€150 + €100/year
HID protocol and .crin integration.
€100/month
Self-hosted, vendor-blind document server.
| Capability | Crypt-in |
|---|---|
| Commodity DIY hardware (~€5) | yes |
| Physical hardware kill switch | yes |
| Instant kill switch on USB removal event | yes |
Universal cross-platform .crin format | yes |
| Vendor-blind self-hosted Docker vault | yes |
| Granular SME pricing | yes |
| EU manufacturer — GDPR and CRA scope | yes |
| Structurally zero CAC (agentic-first) | yes |
Competitive research conducted July 2026. No product currently combines all of the above. This is a claim about the combination — each element exists elsewhere in isolation.
Each physical ESP32-S3 chip generates a unique hardware attestation key (K_attestation) from hardware entropy, independent from the recoverable BIP-39 seed. The license server binds activation to K_attestation — a clone built from the same seed is detected and blocked.
Verified on real hardware: Krypt@9c756da, Krypt@d3e71df.
lake8.dev receives: email, payment, tax/VAT number, dongle public key.
lake8.dev never receives: root secret, BIP-39 seed, encrypted files, session keys, Vault master secret, telemetry of any kind.
This is an architectural property, not a policy promise: the material required to decrypt was never transmitted, so no policy change or legal order can produce it.
The license server is contacted once at activation. After that, the dongle works offline indefinitely. lake8.dev could shut down tomorrow: already-activated dongles continue to work forever.
Krypt@9c756da, Krypt@d3e71df)server-licence@a472adc)llms.txt, llms-full.txt and a knowledge-graph.json of 17 nodes, published and interlinked with the lake8.dev graph. JSON-LD injected in the <head> of every page; schema.org validation passes with zero errors and zero warnings| Proof | Metric |
|---|---|
| Cryptographic | .crin spec published with test vectors |
| Security | Independent protocol audit report |
| Usability | 10 non-technical users complete setup and recovery |
| Commercial | 50 Year-2 renewals on Windows |
These are gates, not milestones. Expansion — multiplatform, Vault, SDK — happens only after all four are demonstrated.
We are not raising now.
Crypt-in is bootstrapped. The infrastructure runs on lake8.dev's existing Raspberry Pi setup. Development cost is near zero — the founder directs architecture, Claude Code accelerates implementation.
We will consider external capital after:
At that point, external capital makes sense to fund: independent security audit, CE marking for Kit Pro, and vertical marketing (legal, medical, manufacturing).
We are not open to equity dilution.
We consider non-dilutive instruments only:
Full-stack developer, embedded systems, applied cryptography. Architect of Crypt-in, lake8.dev Customer Zero. San Pietro in Casale, Bologna, Italy.
All firmware, license server, Windows app and infrastructure are developed in intensive Claude Code sessions directed by the founder. Not autonomous AI — high-velocity pair programming with a human making every architectural decision.
Lagotto BI, Lagotto Meter and MRP Scheduler run in production on a Raspberry Pi 4B. The same discipline that keeps lake8.dev at PageSpeed 100/100 on ARM hardware informs every Crypt-in architecture decision.
If you are a business angel, seed fund, system integrator, or potential Certified Integrator partner, write directly to:
No pitch deck required upfront. Read this page — if it makes sense to you, we can talk.
Full technical documentation ·Vulnerability Disclosure Policy