Skip to content

Commit 1d85099

Browse files
committed
Add About/Vendors_resellers.md, change order of navigation
Signed-off-by: Thierry Laurion <insurgo@riseup.net>
1 parent 8686c4a commit 1d85099

File tree

2 files changed

+81
-1
lines changed

2 files changed

+81
-1
lines changed

About/FAQ.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
layout: default
33
title: FAQ
44
permalink: /FAQ/
5-
nav_order: 1
5+
nav_order: 4
66
parent: About
77
---
88

About/Vendors_resellers.md

Lines changed: 80 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,80 @@
1+
---
2+
layout: default
3+
title: Heads Vendors and Resellers
4+
permalink: /Vendors/
5+
nav_order: 1
6+
parent: About
7+
---
8+
9+
# Heads Vendors and Resellers
10+
11+
For those who prefer not to manually flash Heads firmware on their devices,
12+
several vendors and resellers offer laptops, workstations, and servers with
13+
Heads preinstalled. These vendors provide a range of secure and privacy-focused
14+
devices, making it easier for potential users to get started with Heads without
15+
the hassle of searching for options online. By choosing one of these vendors or
16+
resellers, users who don't want to open their devices and flash manually can
17+
easily get a device with Heads preinstalled. This provides a straightforward
18+
solution for those who would benefit from Heads' secure firmware but need a more
19+
accessible option. Additionally, many of these vendors offer customization
20+
options, preinstallation of various operating systems, and anti-interdiction
21+
mechanisms to ensure the security and integrity of the devices.
22+
23+
The vendors are listed alphabetically.
24+
25+
## Vendors and Resellers
26+
27+
### HardenedVault (VaultBoot)
28+
HardenedVault provides VaultBoot (a variant of Heads) preinstalled on their
29+
devices.
30+
31+
- **Website:** [HardenedVault](https://hardenedvault.net)
32+
- **Products:** Servers
33+
34+
### Nitrokey (Heads)
35+
Nitrokey offers Heads preinstalled on some of their devices. Nitrokey is also
36+
a reseller of some of NovaCustom's laptops with BootGuard unfused. Additionally,
37+
Nitrokey sells refurbished laptops with Intel ME neutralized for their older
38+
refurbished models.
39+
40+
- **Website:** [Nitrokey](https://www.nitrokey.com)
41+
- **Products:** Laptops, servers, workstations, USB security dongles, and
42+
refurbished laptops with ME neutralized
43+
44+
### NovaCustom (Heads)
45+
NovaCustom offers devices with Heads preinstalled. They focus on providing
46+
customizable and secure devices for their customers. They also resell Nitrokey
47+
USB security dongles. NovaCustom sells Clevo laptops with BootGuard not fused,
48+
meaning the final manufacturing step of fusing BootGuard keys is not done. This
49+
ensures that the firmware remains user-controlled.
50+
51+
- **Website:** [NovaCustom](https://novacustom.com)
52+
- **Products:** Laptops and USB security dongles
53+
54+
### Purism (Pureboot Heads fork)
55+
Purism offers their Pureboot (a fork of Heads) preinstalled on their devices.
56+
57+
- **Website:** [Purism](https://puri.sm)
58+
- **Products:** Laptops, phones, workstations, tablets, and USB security dongles
59+
60+
## General Information
61+
62+
Many of these vendors offer additional services and features, including:
63+
64+
- **OS Preinstallation Options:** Vendors may offer preinstallation of various
65+
operating systems, including QubesOS, PureOS, and others.
66+
- **Anti-Interdiction Mechanisms:** Vendors provide anti-interdiction services
67+
to ensure the security and integrity of the devices during shipping.
68+
- **QubesOS Certification:** Some devices may be QubesOS certified, ensuring
69+
compatibility and security.
70+
- **CSME/ME Status:** Some vendors offer options to neutralize or disable Intel
71+
CSME/ME. "Neutralized" means most parts of the ME are removed, while "disabled"
72+
means the ME is deactivated. Users should verify these options on the respective
73+
vendor websites. For more information, refer to Purism's blog post on this topic:
74+
[Deep Dive into Intel ME Disablement](https://puri.sm/posts/deep-dive-into-intel-me-disablement/).
75+
- **Blob Status:** The newer the platform, the more it relies on proprietary
76+
blobs. Users should consider their threat model when choosing a device. For
77+
more information, refer to the [threat modeling page](/Heads-threat-model/).
78+
79+
Please verify the specific offerings and services on the respective vendor
80+
websites.

0 commit comments

Comments
 (0)