Catalogue

Laptops

Buying guide

Choosing your hardened laptop

This line gathers refurbished ThinkPads prepared for a hardened system — full-disk encryption (LUKS), with a choice of Qubes OS, Tails or a hardened Debian base. Unlike the phones, the trust level here depends heavily on the model, because it is decided at the firmware level. That is the main decision point: how far down the trust chain, beneath the operating system, do you want to go.

The X1 Carbon G8 supports Coreboot and Heads, with measured boot and TOTP — it is the pick if your primary threat is an evil-maid attack or firmware compromise. The T14 G3 AMD has no Intel ME and offers a good performance / openness balance, without measured boot. The X1 Carbon G11 is the most recent hardware but keeps its vendor firmware: Coreboot and Heads are unavailable, and the Intel ME of this generation cannot be neutralized — we will not claim otherwise. On the G11, the main defence becomes Qubes compartmentalization. A counter-intuitive but honest result: the most expensive model has fewer boot protections than the oldest one.

Our workshop installs the system and encryption, applies a tamper-evident seal where the model allows it, and flashes firmware where it is supported. The managed support stack (RustDesk, FMD, push) is reserved for Android phones: on a laptop, support goes through the generic encrypted channels (SimpleX, Signal, PGP, anonymous ticket). Each page also lists the limits — for example, in modern standby the keys stay in memory: power the device off completely.

On payment, every price comes on four rails: Monero (−30 %, the most prominent), Bitcoin/Lightning (−5 %), cash on handover (−10 %, under the legal ceiling) and card. Laptops are refurbished then hardened to order, with an assembly lead time shown on each page; we keep no unnecessary personal data, and order tracking works without an account, from a single token.

Choose within the range

ThinkPad X1 Carbon Gen 8 — hardened« Maximum firmware trust »€665 Monero€950 cardThinkPad T14 Gen 3 AMD — hardened« No Intel ME »€1,015 Monero€1,450 cardThinkPad X1 Carbon Gen 11 — hardened« Recent hardware »€1,463 Monero€2,090 card
Differences
Measured boot + TOTP Heads + TOTP
Open firmware (Coreboot) Coreboot if supported*perConfig
No Intel ME AMD
Secure element TPM dTPM 2.0
Compartmentalization (Qubes) Qubes Qubes Qubes
Tamper-evident seal applied

More expensive does not mean safer: the recent model keeps its vendor firmware where the older one offers measured boot.

Top threat = evil-maid / firmware → X1C G8. Refusing Intel ME and needing performance → T14. Recent hardware with Qubes compartmentalization as your defence → X1C G11.

Laptops

ThinkPad X1 Carbon Gen 11 — hardened

« Recent hardware »

  • Compartmentalization (Qubes)
  • Secure element
  • Encrypted at rest

A 13th-gen Intel ThinkPad X1 Carbon Gen 11 (1 TB NVMe) provisioned for Qubes OS compartmentalisation. The proprietary firmware is retained — this generation is not supported by Coreboot or Heads — so hardening here is OS-level, not firmware-level.

From€1,463Monero · −30%14 days
Laptops

ThinkPad T14 Gen 3 AMD — hardened

« No Intel ME »

  • No Intel ME
  • Open firmware (Coreboot)
  • Encrypted at rest

Hardened ThinkPad T14 Gen 3 AMD: Ryzen Pro (no Intel ME), full-disk encryption, Qubes OS / Tails / hardened Debian. The performance-vs-security sweet spot.

From€1,015Monero · −30%14 days
Laptops

ThinkPad X1 Carbon Gen 8 — hardened

« Maximum firmware trust »

  • Measured boot + TOTP
  • Open firmware (Coreboot)
  • Tamper-evident seal applied

Hardened ThinkPad X1 Carbon Gen 8: Coreboot + Heads (TPM-measured boot), boot-time TOTP, anti-tamper seal. Qubes OS or Tails. Refurbished, the light-and-affordable tier.

From€665Monero · −30%14 days
Support