You ship your ThinkPad to our UK workshop. We dump the original ROM, defeat Intel Boot Guard where applicable, neutralise the Management Engine, flash Libreboot or Coreboot, repaste with Honeywell PTM7950, deep-clean the chassis, run a 24-hour burn-in, and ship it back tamper-sealed. Every bench step is logged and cryptographically attested. Honest about the risks below.
Hardware-level firmware modification carries non-zero risk. We've performed this work on hundreds of devices without losing one — but we will never tell you the risk is zero, because it isn't, and any service that says otherwise is either dishonest or inexperienced. Below is exactly what can fail, what we cover, and what you walk away with.
The chip flashes successfully but the board refuses to POST. Almost always recoverable in-house by re-flashing the original ROM (which we always preserve in two SHA-256-verified backups). Diagnosed within hours. You don't pay for our recovery time.
Static damage to the SPI chip during flashing, or a chip with undisclosed pre-existing damage. Mitigated by ESD-controlled bench, isolated 3.3V flash environment, and fresh SOIC-8 clips. If it happens, our £10,000 Lloyd's-syndicate insurance per device pays out and we replace the unit at our cost with an equivalent Libreboot-flashed device.
Cracked solder joints, swollen batteries, water damage residue, failing CMOS battery. We photograph every issue on intake and email you before any work begins. You decide whether to proceed; if not, we ship the device back and refund minus return shipping.
Send us a unit that is fully tested and known-working. Do not send the SSD or HDD — we don't need them, and your data should never leave your custody. Send the laptop, charger if you have it, and that's it. Charge it to 50% before shipping (lithium battery transit safety).
From the moment your unit arrives at the workshop to the moment the courier signs it back over to you, every operation is photographed, hashed, or both. The full bench log is delivered to you on a sealed USB stick alongside the device. You can verify our work without trusting our word.
You contact us via PGP-encrypted email or CITADEL. Tell us your model, what you'd like done, your timeline, and any add-ons. We respond within 24 hours, in writing, signed.
You receive a written quote with model tier, options, total price, and lead time. 50% deposit secures your slot in the next bench batch. Payment via GBP/EUR wire, Monero, or Bitcoin to a dedicated wallet.
We ship you a pre-paid tracked shipping label, an anti-static bag, a tamper-evident outer pouch, and a paper instruction card listing exactly what to include and what not to. Do not include your SSD/HDD.
Your unit arrives at our Salisbury workshop. We photograph the seals and packaging on arrival, log the serial number, and email you a confirmation including the seal photographs.
Full hardware test before any modification: POST, RAM check, SSD/HDD slot test (with our diagnostic drive), display, keyboard, trackpad, battery, all USB ports. Any pre-existing issue is photographed and emailed to you before we proceed.
The unit is opened on an ESD-controlled mat. The BIOS chip is exposed: bottom panel only on T440p, full mainboard removal on T480 / X230 / T430. All screws are organised on a magnetic mat keyed to the disassembly diagram.
The SOIC-8 clip attaches to the BIOS flash chip. The chip is dumped twice through an isolated 3.3V SPI programmer (CH341A or Raspberry Pi). Both dumps are SHA-256 verified — they must match. The original ROM is preserved on a sealed USB stick that travels with your unit.
For T480/T480s/T580: the dumped ROM is processed through deguard, the community-developed exploit that defeats Intel Boot Guard fuse-locking. This step is the reason 8th-gen support exists at all and why this tier is the most expensive.
The ROM is processed through me_cleaner with HAP bit set. The Intel Management Engine region is reduced to the minimum CPU bring-up stub; the runtime ME is no longer executing. Earlier platforms (X200, T400) allow 100% ME removal.
The patched ROM is written to the SPI chip with flashprog. Verification reads the chip back and SHA-256 compares — the written hash must match the source. Reboot to bench.
Old thermal compound is removed with isopropanol. Honeywell PTM7950 phase-change pad is applied to CPU/GPU dies — proper enterprise-grade thermal interface, not paste. Heatsink reseated, fans cleaned ultrasonically, dust extracted under positive-pressure airflow.
Every reflashed unit runs a continuous 24-hour stress profile: CPU prime95 small FFT, RAM pattern test, full SSD/HDD slot under our diagnostic drive, thermal monitoring. Any anomaly fails the burn-in and the bench process is reviewed before re-running.
A CYBERSENTINEL-signed manifest is generated listing the SHA-256 of the original ROM, the patched ROM, every tool version, every flag passed, every burn-in log line. Signed with our offline key (fp 0x4F2A...) and written to your operator USB alongside both ROM dumps.
Chassis screws sealed with serialised void-stickers. Unit placed in tamper-evident transit pouch with seal serial photographed and emailed to you before dispatch. Operator USB sealed in a separate envelope with its own seal serial.
Tracked, signed-for return courier directly to the named recipient — never a freight forwarder, never a depot. Final 50% balance is taken on shipment. You verify seal serials on arrival; broken seal = unit replaced and order refunded on sight.
We work on the ThinkPads where Libreboot or Coreboot has mature, well-documented support paths. Older platforms permit fuller Intel ME removal but have less performance; newer platforms have better hardware but require more invasive bench work to defeat Boot Guard. Every tier ends in a clean machine you fully control.
External hardware flash only. Requires SOIC-8 clip on the 16 MB SPI chip with the mainboard partially removed from the chassis. Critical: the dumped factory ROM is processed through deguard, the community-developed Boot Guard exploit, before me_cleaner neutralises the ME region.
The patched image is written via flashprog from a separate workstation (never the running OS). Re-verification on second read.
Why this tier exists at all: the deguard breakthrough in 2024 made 8th-gen Boot Guard-locked ThinkPads flashable. Before deguard, this tier was impossible.
External hardware flash with SOIC-8 clip. Significantly easier than T480 or X230: the SPI chip on T440p is accessible immediately under the lower service cover — no need to extract the mainboard from the chassis.
No Boot Guard bypass required on this generation. The Libreboot image compiles with built-in neutralised Intel ME — straight dump → patch → flash.
Best balance for buyers entering the Libreboot world: still-fast hardware, lowest-risk bench operation, lowest service cost in our catalogue.
Hardware path (Libreboot): these mainboards have two SPI chips (4 MB + 8 MB). Full chassis disassembly required to expose both. We dump both, neutralise ME, write the new payload to both chips, reassemble. £299.
Software path (Coreboot via 1vyrain): a Linux-based exploit allows BIOS downgrade and modified Coreboot installation without opening the case. Faster, cheaper — but does not modify the protected Intel ME region. £179.
We recommend the hardware path for buyers who want full ME neutralisation; the 1vyrain path for buyers who prioritise the open-firmware boot stack and don't mind ME remaining active.
External hardware flash. The X220 has a single 8 MB SPI chip on the BD82HM65 PCH. Mainboard partial removal required for clip access — easier than T480, harder than T440p.
No Boot Guard. Libreboot image compiled with built-in ME neutralisation; straight dump → patch → flash. After first flash, future updates can be done from the running OS — the chip is unlocked.
Why this tier matters: the X220 sits in a sweet spot — old enough to flash easily, new enough to handle modern workflows comfortably. Genuine bargain in the Libreboot catalogue.
The first flash must be hardware-based with external programmer. After that, the SPI chip is unlocked permanently — every future Libreboot update can be done from the operator's terminal with flashprog -p internal, no opening the case.
Unique property of this tier: the GM45 platform predates the Intel Management Engine architecture used in 2nd-gen onwards. me_cleaner isn't required because there's nothing to clean — the ME isn't there. True 100% blob-free firmware is achievable on this generation alone.
For buyers whose threat model demands literally zero closed code anywhere in the boot chain: this tier exists for you. Performance is Core 2 Duo-era (slow by modern standards), but cryptographic auditability is total.
// MODEL NOT LISTED? // X280 is in the Coreboot tree but not yet officially supported in Libreboot. T420, T520, X201 are technically flashable but we don't currently bench them — not because we can't, but because we want to maintain a tight, well-audited tier set rather than a sprawling list. Email us with your model and we'll either quote a custom tier or recommend a community service we trust.
Every flash service includes professional internal cleaning, ultrasonic fan service, and a Honeywell PTM7950 thermal repaste at no extra cost. Beyond that, we'll replace whatever needs replacing while the unit is on the bench. Cheaper than doing it as a separate visit.
Disassembled chassis cleaned by hand. Fans extracted, ultrasonically cleaned, dust extracted under positive-pressure airflow. Heatsink fins blown clear.
Old thermal compound removed with isopropanol, Honeywell PTM7950 phase-change pad applied to CPU/GPU. Enterprise-grade thermal interface — outlasts paste by years.
CYBERSENTINEL-signed manifest of original ROM, patched ROM, every tool version and flag. On a sealed USB. Operator-verifiable.
Genuine OEM Lite-On keyboard — backlit, US/UK layouts in stock for T480, T440p, X220, X230. Cleaner key feel than aftermarket clones.
Genuine cells, OEM-equivalent. We test capacity to ≥90% rated before fitting. Internal + external (T480 96Wh combo) on request.
Replace the OEM Intel WiFi with an Atheros AR9462 — fully blob-free firmware, supported by all Linux distributions, no proprietary firmware load required.
Replace TN with FHD IPS (1920×1080, 400-nit Innolux). Available for T480 (matte), X220, X230, T440p. Significantly improves the daily-use experience.
Arch Hardened (CSSLTD profile), Qubes OS 4.2, Tails (live USB), or Debian. LUKS2 with operator passphrase set in your presence (CITADEL video) on first boot.
Skip the queue. Your unit goes to the next bench slot the day it arrives. Subject to current capacity — we'll confirm before deposit.
We strongly recommend you do not send your storage drive with the laptop — your data should never leave your custody. But if you're sending us a unit with a failed or failing drive and want recovery before the flash service, we offer three tiers of data recovery, performed under the same chain-of-custody protocol as the flash work.
Drive is healthy but filesystem is damaged or accidentally erased. We image the drive bit-for-bit, work on the image, recover what's recoverable, return on encrypted external SSD.
Drive has bad sectors, mechanical issues, or controller failure. Recovery in our cleanroom-equivalent dust-controlled bench. Donor parts sourced where required.
Sensitive case — needs documented chain of custody, hash-verified imaging, and a written report admissible in legal proceedings. Performed by our forensic-trained engineer.
// HONEST DISCLAIMER // Recovery is not guaranteed. We charge the diagnostic fee (£149/£399/£999 depending on tier) regardless of outcome — that pays for the bench time, the imaging, and the engineering attempt. Recovered data is paid per-TB only on what we actually recover. If the drive is unrecoverable, the diagnostic fee covers our time and you pay nothing further. We'll tell you the prognosis honestly within 48 hours of receiving the drive.
Every line item is a real cost. The base service includes everything you need for a working Libreboot ThinkPad. Add-ons are optional and quoted before any work starts. The single number on your invoice is what you pay.
Chain of custody is documented at every transfer. We photograph the seals on receipt and the seals on dispatch. You receive both sets of photographs. Any seal mismatch on arrival means we replace the unit on sight.
Same terms as the CYBERSENTINEL hardware programmes. Underwritten by professional indemnity insurance. Backed by SLAs. Written into the service contract you sign before any work begins.
Each device is covered by a £10,000 Lloyd's-syndicate professional indemnity policy. If the device is bricked during our bench work and unrecoverable, the policy pays out and we replace the unit at our cost with an equivalent Libreboot-flashed device.
Every flashed unit ships with a CYBERSENTINEL-signed manifest listing the original ROM SHA-256, the patched ROM SHA-256, every tool version, every flag, and the burn-in log. Manifest hash mismatch on receipt = unit re-bench at our cost.
If you ever suspect compromise, ship the unit back. We re-flash and re-attest free for the device's life. We don't charge for paranoia. The only thing you pay is the courier both ways — and even that, we cover within the first 12 months.
Components we replace (keyboard, battery, panel, WiFi card) are warrantied for five years, parts and labour. We don't void warranty for opening the case after handover — quite the opposite, we expect operators to inspect their own machines.
We don't ask for your SSD, we don't want it, and we don't accept it for the bench programme. If you're sending a unit for data recovery (separately), we work on bit-for-bit images and never on the original drive. Your data never leaves your custody beyond what is strictly required.
Tamper-evident packaging on inbound and outbound legs. Photographs of seal state at every transfer point. Each device serial, build hash, and courier waybill recorded. If you receive the unit with a broken seal, we replace it on sight — no questions, no debate.
You don't, with 100% certainty — and we're upfront about that. What we can tell you: hundreds of bench operations, zero hard bricks to date. Soft bricks recoverable in-house from the SHA-256-verified original ROM dump. ESD-controlled bench, isolated 3.3V flash environment, fresh SOIC-8 clips. And if it does happen, your £10,000 Lloyd's-syndicate insurance pays out and we replace the unit at our cost. We'd rather lose money on a hard brick than lie to you about the risk.
Two reasons. One: we don't need it for the flash work — we never boot the unit's storage during the bench process. Two: your data should never leave your custody. The bench process touches the BIOS chip and the cooling system, nothing else. If you ship us your drive, you're trusting us with everything on it; if you keep your drive, you're only trusting us with a piece of hardware. The second framing is much better for both of us.
Coreboot is the upstream open-source firmware project. Libreboot is a downstream distribution that ships ready-made firmware images with as much closed code excised as the platform allows. For the practical purpose of "I want a freer ThinkPad," they overlap heavily — the difference matters mostly to free-software purists. Tier 03b (1vyrain) installs Coreboot specifically; all other tiers install Libreboot. We're happy to do either on any supported platform if you have a preference.
Heads is a Coreboot payload that adds measured boot via a TPM and YubiKey-attested integrity verification. It's available for some of the platforms we work on (notably T480 and X230), but we don't currently include it in the base bench tiers because Heads requires a deeper config conversation with the operator (TPM ownership, YubiKey provisioning, recovery procedure). If you want a Heads build, mention it in your brief and we'll quote a bespoke tier — typically +£199 over the base service.
The hands-on bench work is between 4 and 8 hours of engineer time depending on tier. The end-to-end lead time (5–10 days for most tiers) includes the 24-hour mandatory burn-in, attestation generation, sealing, and outbound courier. Express turnaround (+£149) skips the queue but doesn't shorten the burn-in — the burn-in is non-negotiable because it's how we catch problems before they reach you.
Not at the bench (insurance, ESD, and bench-discipline reasons), but yes via CITADEL video for the critical steps if you'd like — ROM dump, deguard application, ME clean, flash, verification. We'll book a slot and stream the bench camera. Add £49 for the bench-cam session. Most operators don't bother; the build attestation and signed manifest cover the same trust property without anyone losing their afternoon.
We accept inbound shipments from Switzerland, Iceland, Norway, US, and selected APAC countries. There's an additional £99–£249 customs and handling fee depending on origin, and we'll discuss tamper-evident chain-of-custody options for the longer transit. We don't accept inbound shipments from jurisdictions where strong encryption or operator-controlled hardware is restricted by import law — we'll tell you upfront if you're affected.
Tell us. T420, T520, X201, P51, X1 Carbon Gen 6 — all technically flashable to varying degrees with varying community support. We don't bench every model because we'd rather maintain a tight, well-audited tier set than a sprawling list of "we'll figure it out." If your model is doable, we'll quote a custom tier (usually £349–£549 depending on complexity). If it's not, we'll recommend a community service we trust.
Three reasons. One: the deguard exploit step takes more bench time and more careful workflow than older tiers. Two: mainboard removal is required for 8th-gen — significantly more disassembly than T440p. Three: the risk profile is higher. We charge our risk-loaded rate so the £10,000 insurance is properly priced into each unit; a cheaper service that doesn't insure the bench work is taking your money and gambling with your hardware.
Yes — that's our SENTINEL programme. If you don't already own a ThinkPad, ordering a hand-built unit is often cheaper than buying a used T480 yourself plus our flash service. The SENTINEL programme starts at £4,499 and ships with Libreboot, hardened Arch, the 9-platform identity bundle, YubiKey, CITADEL licence, and the same insurance and warranty as this bench service. Email us for a comparison quote.
Brief us by PGP-encrypted email or CITADEL. We respond within 24 hours, in writing, signed. The quote is fixed before any deposit, the deposit is refundable until flashing begins, and the work doesn't start until you've read and signed the risk notice.
bench@cyberssl.co.uk · PGP 0x4F2A on request · CITADEL @ops.cyberssl