Are the components really new?
Yes — every functional component is installed new. Panel, keyboard, palmrest, trackpad, batteries (both cells), RAM, NVMe SSD, fans, thermal compound, screws. The motherboard and roll-cage chassis are sourced as factory-sealed New Old Stock — Lenovo discontinued the line, but factory-sealed parts are still available through enterprise channels and we inspect every seal before opening. We chose the T480 because newer Intel platforms ship with Boot Guard fuses that physically prevent third-party firmware. There is no "more secure new laptop" we could ship instead.
Why no discount on bulk orders?
Because bulk discounts mean either we cut margin (hurting the long-term programme) or we cut quality (hurting the team that ordered units 6–10). Neither is acceptable. The same hands build every SENTINEL. The same 48-hour burn-in. The same attestation. If the per-unit price is too high for the team's budget, the answer is fewer operators get equipped, not that the operators we do equip get worse units.
Is this "military-grade encryption"?
"Military-grade" is a marketing term. The actual answer: X25519 for key agreement, AES-256-GCM for symmetric encryption, the Signal Protocol Double Ratchet for messaging, WireGuard (Curve25519 + ChaCha20-Poly1305) for VPN, aes-xts-plain64 / 512-bit with Argon2id KDF for disk. These are the primitives endorsed by NSA Suite B for SECRET-classified traffic and used by Signal, ProtonMail's E2EE channel, and most modern privacy platforms. The advantage of CITADEL specifically is we operate the relay infrastructure and don't link the account to a phone number.
Are you "100% open-source firmware"?
No, and anyone telling you that on a modern x86 platform is lying or confused. CPU microcode and the Intel FSP (Firmware Support Package) blobs are required to bring the silicon up — Coreboot + Libreboot replace everything else, and we run me_cleaner against the Intel ME region (HAP bit set, runtime stub only). The ME is neutralised, not removed. We document exactly which blobs remain and supply their hashes with each unit. If "literally zero closed blobs" is your requirement, we can quote you on T400 / X200 builds with Libreboot's vendor-blob-free profile — but performance is significantly lower (Core 2 era). For real operator workflows, the SENTINEL is the right trade.
How do you provision identities without linking them to me?
Every account on every platform is registered over Tor, paid with Monero (or cash via a third-party Monero seller for platforms that don't accept it directly), and registered to an operator codename you choose. None of the identities require — or are linked to — your real-world name, address, or phone number. Credentials are printed once, sealed, handed over physically, and not retained by us. If you lose them, they're gone.
What if I lose my YubiKey?
If you have the backup YubiKey we recommend at handover (£99) — you swap it in, revoke the lost key from each platform's account settings, and we ship you a new one provisioned over a CITADEL session. If you don't have a backup — most things are recoverable via the printed recovery codes (kept in your secure location, never on the unit), but LUKS unlock and any FIDO2-resident SSH keys are gone. The disk is not. You can boot from a Tails USB and decrypt with your passphrase, then re-provision keys to a new YubiKey. Full procedure is in the Recovery binder.
Can I host illegal services on the .onion stack you ship?
The infrastructure is operator-owned — we don't audit what you put on it. But the SENTINEL programme is sold to teams operating within the law of their jurisdiction: journalists, security researchers, NGOs, lawyers, doctors, executives in jurisdictions with hostile threat models. We refuse orders that, in our judgement, point at criminal use. We do not ship to jurisdictions where strong encryption itself is restricted by import law (a small list — we'll tell you if you're affected).
How do I verify you didn't backdoor the unit?
Three layers of verification, all of which you can perform yourself: (1) The Libreboot ROM we flash is built from upstream source — we ship the build container, you re-build it, the SHA-256 of the resulting image must match the value on your unit's attestation. (2) The Arch Hardened image is provisioned via a public Ansible manifest you receive — every package, every config, every hash. Re-provision a unit yourself and compare. (3) The CITADEL client is open-source with a third-party audit report shipped per licence. The only thing you have to trust is the silicon and the chassis seal — same as any other laptop, except we let you crack the case open and look inside.
Lead time? Where do you ship?
Lead time is 4–6 weeks from order confirmation, longer for bespoke orders. We ship UK and EU mainland by default (couriered, signed delivery to the named recipient). For US, CH, IS, NO, and selected APAC destinations, contact us — there's an additional shipping & customs handling fee, and we discuss tamper-evident chain-of-custody options. We do not ship to jurisdictions where Libreboot, strong encryption, or operator-controlled hardware is restricted by import law.