ThinkPad T14 (representative photo)
ThinkPad T14 (representative photo)ThinkPad T14 (representative photo)

Capabilities

Boot & firmware

Measured boot + TOTPabsent

Heads measures the firmware at boot and proves its integrity via a TOTP code. Requires flashed Heads with the TPM bound — done at the workshop.

Source

Open firmware (Coreboot)stock (upstream)

if supported

The boot firmware is Coreboot — open-source and auditable — instead of the vendor BIOS.

Depends on a configurator choice.

Source

No Intel MEstock (upstream)

AMD

No active Intel Management Engine. On AMD there is no Intel ME (but the proprietary AMD PSP remains). Neutralization is never total.

AMD PSP present, proprietary.

Source

Secure elementabsent

Dedicated chip that stores keys and throttles PIN attempts (Titan M2 on Pixel, dTPM on some ThinkPads).

Source

Guaranteed updatesabsent

Security-update window documented by the manufacturer. Shown only when it is guaranteed.

Source

System & data

Encrypted at restonsecret workshop

LUKS

Data is encrypted while the device is locked (FBE on phones, LUKS applied at the workshop on laptops).

Source

Compartmentalization (Qubes)option

Qubes

Qubes OS isolates your activities in walled VMs — a compromise does not spread to the rest.

Source

Amnesic (Tails)option

Tails

Tails leaves no trace: everything runs in RAM and vanishes at shutdown, save an optional persistent volume.

Source

Workshop & support

Installed, verified at the workshoponsecret workshop

We flash, verify integrity and re-lock every unit. For USB keys we provide the signature-verification procedure — don't take our word for it.

Tamper-evident seal appliedonsecret workshop

A tamper-evident seal is applied at the workshop: opening it leaves a visible mark.

stock (upstream) onsecret workshop option absent

What this does not protect against

  • AMD has no Intel ME, but the **PSP** co-processor remains proprietary and unauditable.
  • No protection once the session is open.
  • Internal radios are proprietary.
  • Coreboot is not always available on this platform — check the delivered config.

What the workshop does to this device

Our pipeline

  1. Coreboot/Heads flash depending on the model (X1C G8: measured boot + TOTP; X1C G11: stock firmware kept — this generation is unsupported, we won't tell you otherwise).
  2. Chosen OS install (Qubes, Tails, Debian) + LUKS encryption.
  3. Tamper-evident seal applied, where claimed.
  4. Integrity check and unit sheet handed over.

What you can ask us

  • Questions and advice: Signal / PGP / anonymous ticket (see /support).
  • Help re-flashing or changing the OS.
  • Verification: we show you how to check our work.

What we do not do

  • No RustDesk-style remote support on laptops: the managed stack only covers Android phones.
  • No vendor-firmware update guarantee.
  • On the X1C G11 we do not claim to neutralize Intel ME or set up measured boot — the hardware does not allow it.

Choose within the range

ThinkPad X1 Carbon Gen 8 — hardened« Maximum firmware trust »€665 Monero€950 cardThinkPad T14 Gen 3 AMD — hardenedHERE« No Intel ME »€1,015 Monero€1,450 cardThinkPad X1 Carbon Gen 11 — hardened« Recent hardware »€1,463 Monero€2,090 card
Differences
Measured boot + TOTP Heads + TOTP
Open firmware (Coreboot) Coreboot if supported*perConfig
No Intel ME AMD
Secure element TPM dTPM 2.0
Compartmentalization (Qubes) Qubes Qubes Qubes
Tamper-evident seal applied

More expensive does not mean safer: the recent model keeps its vendor firmware where the older one offers measured boot.

Top threat = evil-maid / firmware → X1C G8. Refusing Intel ME and needing performance → T14. Recent hardware with Qubes compartmentalization as your defence → X1C G11.

What it is

What this is

A T14 Gen 3 AMD: the platform avoids the Intel Management Engine. Encrypted disk (LUKS), and your choice of Qubes OS, Tails or a hardened Debian. The line's best balance of modern power and reduced attack surface.

Honest positioning

No Intel ME ≠ "no proprietary firmware": AMD's PSP exists. We say so plainly.

Usage guide

Getting started

  1. Check the anti-tamper seal (reference provided).
  2. Unlock LUKS, open your OS.

Choosing your OS

  • Qubes OS: VM-based isolation — docs.
  • Tails: amnesic + Tor — tails.net.
  • Hardened Debian: classic hardened workstation (auditd, AppArmor, auto-updates).

Good practice

  • Encrypted offline backups; strong LUKS passphrase.

Specifications

ModelLenovo ThinkPad T14 Gen 3 AMD (Ryzen Pro)
PlatformAMD (no Intel ME; PSP present)
Storage512 GB NVMe (LUKS)
FirmwareCoreboot where supported; else hardened BIOS
OSQubes OS / Tails / hardened Debian
ConditionRefurbished, anti-tamper seal

After purchase

Your device arrives already prepared — this guide is for redoing everything yourself or checking our work.

Open the full guide

Mise en route

  1. Vérifiez le sceau anti-tamper (référence fournie).
  2. Déverrouillez LUKS, ouvrez votre système.

Choisir son système

  • Qubes OS : isolation par machines virtuelles — doc.
  • Tails : amnésique + Tor — tails.net.
  • Debian durci : poste durci classique (auditd, AppArmor, mises à jour automatiques).

Bonnes pratiques

  • Sauvegardes chiffrées hors-ligne ; phrase secrète LUKS forte.

Verifiable sources

Support