|
| 1 | +--- |
| 2 | +layout: default |
| 3 | +title: Heads Vendors and Resellers |
| 4 | +permalink: /Vendors/ |
| 5 | +nav_order: 1 |
| 6 | +parent: About |
| 7 | +--- |
| 8 | + |
| 9 | +# Heads Vendors and Resellers |
| 10 | + |
| 11 | +For those who prefer not to manually flash Heads firmware on their devices, |
| 12 | +several vendors and resellers offer laptops, workstations, and servers with |
| 13 | +Heads preinstalled. These vendors provide a range of secure and privacy-focused |
| 14 | +devices, making it easier for potential users to get started with Heads without |
| 15 | +the hassle of searching for options online. By choosing one of these vendors or |
| 16 | +resellers, users who don't want to open their devices and flash manually can |
| 17 | +easily get a device with Heads preinstalled. This provides a straightforward |
| 18 | +solution for those who would benefit from Heads' secure firmware but need a more |
| 19 | +accessible option. Additionally, many of these vendors offer customization |
| 20 | +options, preinstallation of various operating systems, and anti-interdiction |
| 21 | +mechanisms to ensure the security and integrity of the devices. |
| 22 | + |
| 23 | +The vendors are listed alphabetically. |
| 24 | + |
| 25 | +## Vendors and Resellers |
| 26 | + |
| 27 | +### HardenedVault (VaultBoot) |
| 28 | +HardenedVault provides VaultBoot (a variant of Heads) preinstalled on their |
| 29 | +devices. |
| 30 | + |
| 31 | +- **Website:** [HardenedVault](https://hardenedvault.net) |
| 32 | +- **Products:** Servers |
| 33 | + |
| 34 | +### Nitrokey (Heads) |
| 35 | +Nitrokey offers Heads preinstalled on some of their devices. Nitrokey is also |
| 36 | +a reseller of some of NovaCustom's laptops with BootGuard unfused. Additionally, |
| 37 | +Nitrokey sells refurbished laptops with Intel ME neutralized for their older |
| 38 | +refurbished models. |
| 39 | + |
| 40 | +- **Website:** [Nitrokey](https://www.nitrokey.com) |
| 41 | +- **Products:** Laptops, servers, workstations, USB security dongles, and |
| 42 | + refurbished laptops with ME neutralized |
| 43 | + |
| 44 | +### NovaCustom (Heads) |
| 45 | +NovaCustom offers devices with Heads preinstalled. They focus on providing |
| 46 | +customizable and secure devices for their customers. They also resell Nitrokey |
| 47 | +USB security dongles. NovaCustom sells Clevo laptops with BootGuard not fused, |
| 48 | +meaning the final manufacturing step of fusing BootGuard keys is not done. This |
| 49 | +ensures that the firmware remains user-controlled. |
| 50 | + |
| 51 | +- **Website:** [NovaCustom](https://novacustom.com) |
| 52 | +- **Products:** Laptops and USB security dongles |
| 53 | + |
| 54 | +### Purism (Pureboot Heads fork) |
| 55 | +Purism offers their Pureboot (a fork of Heads) preinstalled on their devices. |
| 56 | + |
| 57 | +- **Website:** [Purism](https://puri.sm) |
| 58 | +- **Products:** Laptops, phones, workstations, tablets, and USB security dongles |
| 59 | + |
| 60 | +## General Information |
| 61 | + |
| 62 | +Many of these vendors offer additional services and features, including: |
| 63 | + |
| 64 | +- **OS Preinstallation Options:** Vendors may offer preinstallation of various |
| 65 | + operating systems, including QubesOS, PureOS, and others. |
| 66 | +- **Anti-Interdiction Mechanisms:** Vendors provide anti-interdiction services |
| 67 | + to ensure the security and integrity of the devices during shipping. |
| 68 | +- **QubesOS Certification:** Some devices may be QubesOS certified, ensuring |
| 69 | + compatibility and security. |
| 70 | +- **CSME/ME Status:** Some vendors offer options to neutralize or disable Intel |
| 71 | + CSME/ME. "Neutralized" means most parts of the ME are removed, while "disabled" |
| 72 | + means the ME is deactivated. Users should verify these options on the respective |
| 73 | + vendor websites. For more information, refer to Purism's blog post on this topic: |
| 74 | + [Deep Dive into Intel ME Disablement](https://puri.sm/posts/deep-dive-into-intel-me-disablement/). |
| 75 | +- **Blob Status:** The newer the platform, the more it relies on proprietary |
| 76 | + blobs. Users should consider their threat model when choosing a device. For |
| 77 | + more information, refer to the [threat modeling page](/Heads-threat-model/). |
| 78 | + |
| 79 | +Please verify the specific offerings and services on the respective vendor |
| 80 | +websites. |
0 commit comments