This line gathers refurbished ThinkPads prepared for a hardened system — full-disk encryption (LUKS), with a choice of Qubes OS, Tails or a hardened Debian base. Unlike the phones, the trust level here depends heavily on the model, because it is decided at the firmware level. That is the main decision point: how far down the trust chain, beneath the operating system, do you want to go.
The X1 Carbon G8 supports Coreboot and Heads, with measured boot and TOTP — it is the pick if your primary threat is an evil-maid attack or firmware compromise. The T14 G3 AMD has no Intel ME and offers a good performance / openness balance, without measured boot. The X1 Carbon G11 is the most recent hardware but keeps its vendor firmware: Coreboot and Heads are unavailable, and the Intel ME of this generation cannot be neutralized — we will not claim otherwise. On the G11, the main defence becomes Qubes compartmentalization. A counter-intuitive but honest result: the most expensive model has fewer boot protections than the oldest one.
Our workshop installs the system and encryption, applies a tamper-evident seal where the model allows it, and flashes firmware where it is supported. The managed support stack (RustDesk, FMD, push) is reserved for Android phones: on a laptop, support goes through the generic encrypted channels (SimpleX, Signal, PGP, anonymous ticket). Each page also lists the limits — for example, in modern standby the keys stay in memory: power the device off completely.
On payment, every price comes on four rails: Monero (−30 %, the most prominent), Bitcoin/Lightning (−5 %), cash on handover (−10 %, under the legal ceiling) and card. Laptops are refurbished then hardened to order, with an assembly lead time shown on each page; we keep no unnecessary personal data, and order tracking works without an account, from a single token.