BENCH::OPS ONLINE PROGRAMME SEND-IN SERVICE QUEUE 5–10 DAY WAIT FIRMWARE LIBREBOOT 25.12 / COREBOOT 25.x
UTC --:--:--
CS CYBERSENTINEL SOLUTIONSLTD · Salisbury, UK · Bench Programme
Send-In Bench Programme · CYBERSENTINEL · 026

We Libreboot
your ThinkPad.
On the bench.

You ship your ThinkPad to our UK workshop. We dump the original ROM, defeat Intel Boot Guard where applicable, neutralise the Management Engine, flash Libreboot or Coreboot, repaste with Honeywell PTM7950, deep-clean the chassis, run a 24-hour burn-in, and ship it back tamper-sealed. Every bench step is logged and cryptographically attested. Honest about the risks below.

5tiers supported ThinkPad generations
£10Kcover soft-brick insurance per device
life free re-flash for the device's lifetime
// LIVE BENCH SESSION · CSS-BENCH-A14 // CSS // BENCH SESSION 026.A14 // 2026.05.04 ● ACTIVE DDR4 SODIMM CPU · KBL-R SOIC-8 16MB W25Q128.V PCH [A] T480 · LOWER PANEL REMOVED [B] BOTTOM CHASSIS · INVERTED SOIC-8 CLIP CH341A · SPI 3.3V · ISOLATED USB ZIF · SOCKET // BENCH.LOG · LIVE [ OK ] dump-A.rom · sha256 verified · 16384 KB [ OK ] dump-B.rom · sha256 matches · backup sealed to operator USB [ .. ] deguard · Boot Guard exploit → applied [ OK ] me_cleaner · ME region neutralised · HAP set [ OK ] flashprog · libreboot 25.12 written [ OK ] verify pass · CSSLTD-signed attestation VERIFIED CSS · BENCH PASS
Read this first

Things can go wrong.
Here's what we do when they do.

Hardware-level firmware modification carries non-zero risk. We've performed this work on hundreds of devices without losing one — but we will never tell you the risk is zero, because it isn't, and any service that says otherwise is either dishonest or inexperienced. Below is exactly what can fail, what we cover, and what you walk away with.

  1. The most common failure mode: soft brick.

    The chip flashes successfully but the board refuses to POST. Almost always recoverable in-house by re-flashing the original ROM (which we always preserve in two SHA-256-verified backups). Diagnosed within hours. You don't pay for our recovery time.

  2. The rarer failure mode: hard brick.

    Static damage to the SPI chip during flashing, or a chip with undisclosed pre-existing damage. Mitigated by ESD-controlled bench, isolated 3.3V flash environment, and fresh SOIC-8 clips. If it happens, our £10,000 Lloyd's-syndicate insurance per device pays out and we replace the unit at our cost with an equivalent Libreboot-flashed device.

  3. Pre-existing damage we discover.

    Cracked solder joints, swollen batteries, water damage residue, failing CMOS battery. We photograph every issue on intake and email you before any work begins. You decide whether to proceed; if not, we ship the device back and refund minus return shipping.

  4. What you can do to reduce risk.

    Send us a unit that is fully tested and known-working. Do not send the SSD or HDD — we don't need them, and your data should never leave your custody. Send the laptop, charger if you have it, and that's it. Charge it to 50% before shipping (lithium battery transit safety).

02 / Process

Fifteen steps. Each logged.
Each cryptographically signed.

From the moment your unit arrives at the workshop to the moment the courier signs it back over to you, every operation is photographed, hashed, or both. The full bench log is delivered to you on a sealed USB stick alongside the device. You can verify our work without trusting our word.

01

Operator brief.

You contact us via PGP-encrypted email or CITADEL. Tell us your model, what you'd like done, your timeline, and any add-ons. We respond within 24 hours, in writing, signed.

CHANNELS · pgp@cyberssl.co.uk · CITADEL @ops.cyberssl
≤ 24hresponse
02

Quote & deposit.

You receive a written quote with model tier, options, total price, and lead time. 50% deposit secures your slot in the next bench batch. Payment via GBP/EUR wire, Monero, or Bitcoin to a dedicated wallet.

METHODS · WIRE · XMR · BTC · refundable until flashing-start
2–4 daysquote turnaround
03

Pre-shipment kit.

We ship you a pre-paid tracked shipping label, an anti-static bag, a tamper-evident outer pouch, and a paper instruction card listing exactly what to include and what not to. Do not include your SSD/HDD.

KIT · ESD bag · sealed pouch · UPS/Royal Mail tracked label · operator codename printed
3–5 dayskit dispatch
04

Receipt & chain-of-custody.

Your unit arrives at our Salisbury workshop. We photograph the seals and packaging on arrival, log the serial number, and email you a confirmation including the seal photographs.

RECORD · serial · seal-state photo · inbound courier waybill · operator-CITADEL ack
same dayreceipt confirm
05

Diagnostic & pre-flight.

Full hardware test before any modification: POST, RAM check, SSD/HDD slot test (with our diagnostic drive), display, keyboard, trackpad, battery, all USB ports. Any pre-existing issue is photographed and emailed to you before we proceed.

TESTS · memtest86+ · CPU stress · panel UV · keyboard sweep · battery health
2 hoursbench time
06

Disassembly & chip exposure.

The unit is opened on an ESD-controlled mat. The BIOS chip is exposed: bottom panel only on T440p, full mainboard removal on T480 / X230 / T430. All screws are organised on a magnetic mat keyed to the disassembly diagram.

STATION · ESD mat · binocular microscope · 0.25Nm screwdriver set · magnetic organiser
30–90minaccess time
07

ROM dump · double pass.

The SOIC-8 clip attaches to the BIOS flash chip. The chip is dumped twice through an isolated 3.3V SPI programmer (CH341A or Raspberry Pi). Both dumps are SHA-256 verified — they must match. The original ROM is preserved on a sealed USB stick that travels with your unit.

TOOLS · CH341A or RPi-based programmer · 3.3V regulated · flashrom v1.4 · sha256sum
15minper dump
08

Boot Guard defeat (8th-gen only).

For T480/T480s/T580: the dumped ROM is processed through deguard, the community-developed exploit that defeats Intel Boot Guard fuse-locking. This step is the reason 8th-gen support exists at all and why this tier is the most expensive.

EXPLOIT · deguard (Sentinel team) · published 2024 · audited workflow
10minprocessing
09

ME neutralisation.

The ROM is processed through me_cleaner with HAP bit set. The Intel Management Engine region is reduced to the minimum CPU bring-up stub; the runtime ME is no longer executing. Earlier platforms (X200, T400) allow 100% ME removal.

TOOLS · me_cleaner · HAP bit set · runtime ME = ✗
5minprocessing
10

Libreboot / Coreboot flash.

The patched ROM is written to the SPI chip with flashprog. Verification reads the chip back and SHA-256 compares — the written hash must match the source. Reboot to bench.

TOOLS · flashprog · libreboot 25.12 / coreboot 25.x · SHA-256 verify
25minwrite + verify
11

Reassembly & thermal repaste.

Old thermal compound is removed with isopropanol. Honeywell PTM7950 phase-change pad is applied to CPU/GPU dies — proper enterprise-grade thermal interface, not paste. Heatsink reseated, fans cleaned ultrasonically, dust extracted under positive-pressure airflow.

MATERIAL · Honeywell PTM7950 · 99% IPA · ultrasonic fan clean
45minper unit
12

24-hour burn-in.

Every reflashed unit runs a continuous 24-hour stress profile: CPU prime95 small FFT, RAM pattern test, full SSD/HDD slot under our diagnostic drive, thermal monitoring. Any anomaly fails the burn-in and the bench process is reviewed before re-running.

SUITE · CSSLTD bench profile · prime95 · memtest86+ · stresstest disk · sensor logging
24 hourscontinuous
13

Build attestation.

A CYBERSENTINEL-signed manifest is generated listing the SHA-256 of the original ROM, the patched ROM, every tool version, every flag passed, every burn-in log line. Signed with our offline key (fp 0x4F2A...) and written to your operator USB alongside both ROM dumps.

OUTPUT · manifest.sig · operator USB · printed copy in tamper-evident envelope
15mingeneration
14

Tamper-evident sealing.

Chassis screws sealed with serialised void-stickers. Unit placed in tamper-evident transit pouch with seal serial photographed and emailed to you before dispatch. Operator USB sealed in a separate envelope with its own seal serial.

SEALS · serialised holographic void · transit pouch · separate USB envelope
15minsealing
15

Return & balance.

Tracked, signed-for return courier directly to the named recipient — never a freight forwarder, never a depot. Final 50% balance is taken on shipment. You verify seal serials on arrival; broken seal = unit replaced and order refunded on sight.

COURIER · UPS Saver / Royal Mail Special Delivery · signature required · seal-photographed
1–3 daysreturn transit
03 / Supported Models

Five tiers. From newest to purist.

We work on the ThinkPads where Libreboot or Coreboot has mature, well-documented support paths. Older platforms permit fuller Intel ME removal but have less performance; newer platforms have better hardware but require more invasive bench work to defeat Boot Guard. Every tier ends in a clean machine you fully control.

// TIER 01 // MODERN

T480 · T480s · T580

8th gen · Kaby Lake-R · Coffee Lake-R · supported in Libreboot 2024.x & 2025.x
£449 service · per unit
// BENCH PROCESS · HIGH DIFFICULTY

External hardware flash only. Requires SOIC-8 clip on the 16 MB SPI chip with the mainboard partially removed from the chassis. Critical: the dumped factory ROM is processed through deguard, the community-developed Boot Guard exploit, before me_cleaner neutralises the ME region.

The patched image is written via flashprog from a separate workstation (never the running OS). Re-verification on second read.

Why this tier exists at all: the deguard breakthrough in 2024 made 8th-gen Boot Guard-locked ThinkPads flashable. Before deguard, this tier was impossible.

Difficulty   HIGH
ToolsCH341A · SOIC-8 · 16MB
Disassemblymainboard pull
Boot Guarddeguard required
ME statecleaned · HAP set
Lead time7–10 days
Risk classelevated
// TIER 02 // HASWELL

T440p · W541

4th gen · Haswell · best performance/access ratio
£249 service · per unit
// BENCH PROCESS · MEDIUM DIFFICULTY

External hardware flash with SOIC-8 clip. Significantly easier than T480 or X230: the SPI chip on T440p is accessible immediately under the lower service cover — no need to extract the mainboard from the chassis.

No Boot Guard bypass required on this generation. The Libreboot image compiles with built-in neutralised Intel ME — straight dump → patch → flash.

Best balance for buyers entering the Libreboot world: still-fast hardware, lowest-risk bench operation, lowest service cost in our catalogue.

Difficulty   MEDIUM
ToolsCH341A · SOIC-8
Disassemblyservice cover only
Boot Guardnot present
ME statecleaned · HAP set
Lead time5–7 days
Risk classlow
// TIER 03 // IVY BRIDGE

X230 · T430 · T530

3rd gen · Ivy Bridge · the developer's classic
£299/ £179 hardware / 1vyrain
// BENCH PROCESS · TWO PATHS

Hardware path (Libreboot): these mainboards have two SPI chips (4 MB + 8 MB). Full chassis disassembly required to expose both. We dump both, neutralise ME, write the new payload to both chips, reassemble. £299.

Software path (Coreboot via 1vyrain): a Linux-based exploit allows BIOS downgrade and modified Coreboot installation without opening the case. Faster, cheaper — but does not modify the protected Intel ME region. £179.

We recommend the hardware path for buyers who want full ME neutralisation; the 1vyrain path for buyers who prioritise the open-firmware boot stack and don't mind ME remaining active.

Difficulty   HIGH (HW)
ToolsCH341A · SOIC-8 · 2 chips
Disassemblyfull teardown (HW)
Boot Guardnot present
ME statecleaned (HW) / active (1vyrain)
Lead time7–10 days (HW) / 3–5 days (1vyrain)
Risk classmoderate (HW)
// TIER 04 // SANDY BRIDGE

X220

2nd gen · Sandy Bridge · added to Libreboot in late-2023 release
£279 service · per unit
// BENCH PROCESS · MEDIUM-HIGH DIFFICULTY

External hardware flash. The X220 has a single 8 MB SPI chip on the BD82HM65 PCH. Mainboard partial removal required for clip access — easier than T480, harder than T440p.

No Boot Guard. Libreboot image compiled with built-in ME neutralisation; straight dump → patch → flash. After first flash, future updates can be done from the running OS — the chip is unlocked.

Why this tier matters: the X220 sits in a sweet spot — old enough to flash easily, new enough to handle modern workflows comfortably. Genuine bargain in the Libreboot catalogue.

Difficulty   MEDIUM
ToolsCH341A · SOIC-8 · 8MB
Disassemblypartial mainboard
Boot Guardnot present
ME statecleaned · HAP set
Lead time5–7 days
Risk classlow–moderate
// TIER 05 // PURIST

X200 · X200s · X200T · T400

Core 2 Duo · GM45 · the only generation allowing 100% ME removal
£249 service · per unit
// BENCH PROCESS · MEDIUM · ONE-TIME HARDWARE

The first flash must be hardware-based with external programmer. After that, the SPI chip is unlocked permanently — every future Libreboot update can be done from the operator's terminal with flashprog -p internal, no opening the case.

Unique property of this tier: the GM45 platform predates the Intel Management Engine architecture used in 2nd-gen onwards. me_cleaner isn't required because there's nothing to clean — the ME isn't there. True 100% blob-free firmware is achievable on this generation alone.

For buyers whose threat model demands literally zero closed code anywhere in the boot chain: this tier exists for you. Performance is Core 2 Duo-era (slow by modern standards), but cryptographic auditability is total.

Difficulty   MEDIUM
ToolsCH341A · SOIC-8 · 1 chip
Disassemblyfirst time only
Boot Guardnot present
ME state100% removed
Lead time5–7 days
Risk classlow

// MODEL NOT LISTED? // X280 is in the Coreboot tree but not yet officially supported in Libreboot. T420, T520, X201 are technically flashable but we don't currently bench them — not because we can't, but because we want to maintain a tight, well-audited tier set rather than a sprawling list. Email us with your model and we'll either quote a custom tier or recommend a community service we trust.

04 / Bench Add-Ons

Cleaning. Repaste. Replacements.

Every flash service includes professional internal cleaning, ultrasonic fan service, and a Honeywell PTM7950 thermal repaste at no extra cost. Beyond that, we'll replace whatever needs replacing while the unit is on the bench. Cheaper than doing it as a separate visit.

Internal deep-clean

Disassembled chassis cleaned by hand. Fans extracted, ultrasonically cleaned, dust extracted under positive-pressure airflow. Heatsink fins blown clear.

INCLUDED · every service

PTM7950 repaste

Old thermal compound removed with isopropanol, Honeywell PTM7950 phase-change pad applied to CPU/GPU. Enterprise-grade thermal interface — outlasts paste by years.

INCLUDED · every service

Build attestation

CYBERSENTINEL-signed manifest of original ROM, patched ROM, every tool version and flag. On a sealed USB. Operator-verifiable.

INCLUDED · every service

Keyboard replacement

Genuine OEM Lite-On keyboard — backlit, US/UK layouts in stock for T480, T440p, X220, X230. Cleaner key feel than aftermarket clones.

FROM £89 · model-dependent

Battery replacement

Genuine cells, OEM-equivalent. We test capacity to ≥90% rated before fitting. Internal + external (T480 96Wh combo) on request.

FROM £99 · model-dependent

WiFi card upgrade

Replace the OEM Intel WiFi with an Atheros AR9462 — fully blob-free firmware, supported by all Linux distributions, no proprietary firmware load required.

+£59 · parts & fitting

FHD IPS panel swap

Replace TN with FHD IPS (1920×1080, 400-nit Innolux). Available for T480 (matte), X220, X230, T440p. Significantly improves the daily-use experience.

FROM £189 · model-dependent

OS pre-install

Arch Hardened (CSSLTD profile), Qubes OS 4.2, Tails (live USB), or Debian. LUKS2 with operator passphrase set in your presence (CITADEL video) on first boot.

+£99 · per OS

Express turnaround

Skip the queue. Your unit goes to the next bench slot the day it arrives. Subject to current capacity — we'll confirm before deposit.

+£149 · subject to capacity
05 / Data Recovery

If your drive is still with us.

We strongly recommend you do not send your storage drive with the laptop — your data should never leave your custody. But if you're sending us a unit with a failed or failing drive and want recovery before the flash service, we offer three tiers of data recovery, performed under the same chain-of-custody protocol as the flash work.

// TIER R-01

Logical Recovery

Drive is healthy but filesystem is damaged or accidentally erased. We image the drive bit-for-bit, work on the image, recover what's recoverable, return on encrypted external SSD.

  • Filesystem repair · ext4, NTFS, APFS, exFAT
  • Accidental deletion / format recovery
  • Partition table reconstruction
  • Returned on supplied LUKS2 SSD
  • Up to 2 TB source · per-GB pricing above
£149 + £29/TB recovered
// TIER R-02

Hardware Recovery

Drive has bad sectors, mechanical issues, or controller failure. Recovery in our cleanroom-equivalent dust-controlled bench. Donor parts sourced where required.

  • Bad sector recovery · ddrescue protocol
  • Controller swap · matching firmware
  • HDD platter / head donor (cleanroom partner)
  • SSD chip-off (NAND extraction · last resort)
  • Returned on supplied LUKS2 SSD
£399 + £49/TB · parts at cost
// TIER R-03

Forensic Recovery

Sensitive case — needs documented chain of custody, hash-verified imaging, and a written report admissible in legal proceedings. Performed by our forensic-trained engineer.

  • Write-blocker imaging · MD5 + SHA-256
  • Sealed evidence handling protocol
  • Chain-of-custody log signed at every step
  • Written report · admissible-format
  • Engineer available for testimony if needed
£999 + £99/TB · testimony quoted separately

// HONEST DISCLAIMER // Recovery is not guaranteed. We charge the diagnostic fee (£149/£399/£999 depending on tier) regardless of outcome — that pays for the bench time, the imaging, and the engineering attempt. Recovered data is paid per-TB only on what we actually recover. If the drive is unrecoverable, the diagnostic fee covers our time and you pay nothing further. We'll tell you the prognosis honestly within 48 hours of receiving the drive.

06 / Pricing · in Full

Itemised. No surprises.

Every line item is a real cost. The base service includes everything you need for a working Libreboot ThinkPad. Add-ons are optional and quoted before any work starts. The single number on your invoice is what you pay.

CSS // BENCH PROGRAMME // PRICE SHEET 2026.05.04
Tier 01 — MODERN · T480 / T480s / T580External SPI flash · deguard · me_cleaner · flashprog · 24-hr burn-in · build attestation · cleaning · PTM7950 repaste · sealing · return shipping · 5-yr warranty · £10K insurance
£ 449
Tier 02 — HASWELL · T440p / W541Service-cover SPI access · me_cleaner · flashprog · 24-hr burn-in · build attestation · cleaning · PTM7950 repaste · sealing · return shipping · 5-yr warranty · £10K insurance
£ 249
Tier 03a — IVY BRIDGE (HW) · X230 / T430 / T530Full teardown · dual SPI flash · me_cleaner · flashprog · 24-hr burn-in · build attestation · cleaning · PTM7950 repaste · sealing · return shipping · 5-yr warranty · £10K insurance
£ 299
Tier 03b — IVY BRIDGE (1vyrain) · X230 / T430 / T530Software exploit path · Coreboot via Linux · no chassis disassembly · ME remains active · cleaning · PTM7950 repaste · 5-yr warranty
£ 179
Tier 04 — SANDY BRIDGE · X220External SPI flash · me_cleaner · flashprog · 24-hr burn-in · build attestation · cleaning · PTM7950 repaste · sealing · return shipping · 5-yr warranty · £10K insurance
£ 279
Tier 05 — PURIST · X200 / X200s / X200T / T400One-time hardware flash · 100% ME removed · future updates from terminal · build attestation · cleaning · PTM7950 repaste · 5-yr warranty · £10K insurance
£ 249
Internal deep-clean & ultrasonic fan servicestandard with every bench session, no extra charge
included
Honeywell PTM7950 thermal repastephase-change pad · enterprise-grade · standard with every flash
included
CSSLTD-signed build attestation + operator USBboth ROMs · manifest · tool versions · burn-in log
included
5-year hardware warranty + lifetime free re-flashparts & labour · re-flash any time, free, for the device's life
included
£10,000 soft-brick insuranceLloyd's-syndicate underwritten · for the licence period
included
Tracked, signed-for return courier (UK / EU)seal-photographed before dispatch · direct to named recipient
included
+ Keyboard replacement · genuine OEMLite-On backlit · US / UK layouts · stocked
from £89
+ Battery replacement · genuine cellstested ≥90% capacity before fitting
from £99
+ Atheros AR9462 WiFi card · blob-freeparts & fitting · works on Libreboot without firmware load
+£59
+ FHD IPS panel swap1920×1080 · 400-nit · matte · model-dependent
from £189
+ OS pre-install · Arch Hardened, Qubes, Tails, DebianLUKS2 set in operator's presence via CITADEL video
+£99
+ Express turnaround · skip the queuenext bench slot · subject to capacity
+£149
+ Logical data recovery · Tier R-01diagnostic + recovery to LUKS2 SSD
£149 + £29/TB
+ Hardware data recovery · Tier R-02diagnostic + bench recovery + parts at cost
£399 + £49/TB
+ Forensic data recovery · Tier R-03chain-of-custody · admissible-format report
£999 + £99/TB
// PAYMENT TERMS // 50% deposit secures the bench slot. 50% balance taken on shipment. GBP / EUR / CHF wire, or Monero / Bitcoin. Refundable in full any time before flashing-start. All prices ex-VAT. UK customers: VAT 20% added at invoice. EU customers: reverse-charge mechanism applies where eligible. Outside UK / EU: contact us for a custom quote including customs handling.
07 / What to Send · What Comes Back

Two parcels. Both sealed.

Chain of custody is documented at every transfer. We photograph the seals on receipt and the seals on dispatch. You receive both sets of photographs. Any seal mismatch on arrival means we replace the unit on sight.

→ TO US

What to send.

  • The laptop. Battery charged to 50% for transit safety.
  • The charger, if you have it. We can lend you one for the bench tests if not.
  • Operator codename on the supplied manifest card — for our records, not yours.
  • Do not send the SSD or HDD. Your data should stay with you.
  • Do not send peripherals — mouse, dock, external drives. Bench bench-only.
  • Do not send personal items inside the laptop bag.
  • Do not include cash, cards, or other valuables.
← BACK TO YOU

What comes back.

  • Your laptop, flashed, cleaned, repasted, sealed.
  • Operator USB in a separate sealed envelope: original ROM, patched ROM, build manifest, attestation signature, full bench log.
  • Printed attestation card with chip serial, dump SHA-256, written ROM SHA-256, signing key fingerprint.
  • Seal photographs emailed before dispatch — verify on arrival.
  • Insurance certificate with policy number and 5-year coverage period.
  • Service guide · how to verify the flash yourself · how to update Libreboot · how to claim the lifetime re-flash if needed.
08 / Guarantees

A guarantee with numbers on it.

Same terms as the CYBERSENTINEL hardware programmes. Underwritten by professional indemnity insurance. Backed by SLAs. Written into the service contract you sign before any work begins.

£

Soft-brick insurance.

Each device is covered by a £10,000 Lloyd's-syndicate professional indemnity policy. If the device is bricked during our bench work and unrecoverable, the policy pays out and we replace the unit at our cost with an equivalent Libreboot-flashed device.

£10,000 PER DEVICE · LLOYD'S OF LONDON

Build attestation.

Every flashed unit ships with a CYBERSENTINEL-signed manifest listing the original ROM SHA-256, the patched ROM SHA-256, every tool version, every flag, and the burn-in log. Manifest hash mismatch on receipt = unit re-bench at our cost.

CSSLTD-OFFLINE-2026 KEY · FP 0x4F2A

Lifetime re-flash.

If you ever suspect compromise, ship the unit back. We re-flash and re-attest free for the device's life. We don't charge for paranoia. The only thing you pay is the courier both ways — and even that, we cover within the first 12 months.

UNLIMITED · FREE FOR LIFE · 5-DAY TURNAROUND

Five-year hardware warranty.

Components we replace (keyboard, battery, panel, WiFi card) are warrantied for five years, parts and labour. We don't void warranty for opening the case after handover — quite the opposite, we expect operators to inspect their own machines.

5 YEARS · NO MOD-VOIDS · PARTS-COST AFTER

No-data pact.

We don't ask for your SSD, we don't want it, and we don't accept it for the bench programme. If you're sending a unit for data recovery (separately), we work on bit-for-bit images and never on the original drive. Your data never leaves your custody beyond what is strictly required.

CONTRACTUAL · AUDITABLE BY YOUR COUNSEL

Chain of custody.

Tamper-evident packaging on inbound and outbound legs. Photographs of seal state at every transfer point. Each device serial, build hash, and courier waybill recorded. If you receive the unit with a broken seal, we replace it on sight — no questions, no debate.

DOCUMENTED · COURIER DIRECT · SEAL-VERIFIED
09 / Operator's Q&A

Honest answers, again.

How do I know my unit isn't going to come back bricked?

You don't, with 100% certainty — and we're upfront about that. What we can tell you: hundreds of bench operations, zero hard bricks to date. Soft bricks recoverable in-house from the SHA-256-verified original ROM dump. ESD-controlled bench, isolated 3.3V flash environment, fresh SOIC-8 clips. And if it does happen, your £10,000 Lloyd's-syndicate insurance pays out and we replace the unit at our cost. We'd rather lose money on a hard brick than lie to you about the risk.

Why do you not want my SSD?

Two reasons. One: we don't need it for the flash work — we never boot the unit's storage during the bench process. Two: your data should never leave your custody. The bench process touches the BIOS chip and the cooling system, nothing else. If you ship us your drive, you're trusting us with everything on it; if you keep your drive, you're only trusting us with a piece of hardware. The second framing is much better for both of us.

What's the difference between Libreboot and Coreboot?

Coreboot is the upstream open-source firmware project. Libreboot is a downstream distribution that ships ready-made firmware images with as much closed code excised as the platform allows. For the practical purpose of "I want a freer ThinkPad," they overlap heavily — the difference matters mostly to free-software purists. Tier 03b (1vyrain) installs Coreboot specifically; all other tiers install Libreboot. We're happy to do either on any supported platform if you have a preference.

What about Heads firmware?

Heads is a Coreboot payload that adds measured boot via a TPM and YubiKey-attested integrity verification. It's available for some of the platforms we work on (notably T480 and X230), but we don't currently include it in the base bench tiers because Heads requires a deeper config conversation with the operator (TPM ownership, YubiKey provisioning, recovery procedure). If you want a Heads build, mention it in your brief and we'll quote a bespoke tier — typically +£199 over the base service.

How long does the bench process actually take?

The hands-on bench work is between 4 and 8 hours of engineer time depending on tier. The end-to-end lead time (5–10 days for most tiers) includes the 24-hour mandatory burn-in, attestation generation, sealing, and outbound courier. Express turnaround (+£149) skips the queue but doesn't shorten the burn-in — the burn-in is non-negotiable because it's how we catch problems before they reach you.

Can I watch you do the work?

Not at the bench (insurance, ESD, and bench-discipline reasons), but yes via CITADEL video for the critical steps if you'd like — ROM dump, deguard application, ME clean, flash, verification. We'll book a slot and stream the bench camera. Add £49 for the bench-cam session. Most operators don't bother; the build attestation and signed manifest cover the same trust property without anyone losing their afternoon.

What if I need to send you a unit from outside the UK / EU?

We accept inbound shipments from Switzerland, Iceland, Norway, US, and selected APAC countries. There's an additional £99–£249 customs and handling fee depending on origin, and we'll discuss tamper-evident chain-of-custody options for the longer transit. We don't accept inbound shipments from jurisdictions where strong encryption or operator-controlled hardware is restricted by import law — we'll tell you upfront if you're affected.

I have a model that's not on your list.

Tell us. T420, T520, X201, P51, X1 Carbon Gen 6 — all technically flashable to varying degrees with varying community support. We don't bench every model because we'd rather maintain a tight, well-audited tier set than a sprawling list of "we'll figure it out." If your model is doable, we'll quote a custom tier (usually £349–£549 depending on complexity). If it's not, we'll recommend a community service we trust.

Why is the 8th-gen tier so much more expensive?

Three reasons. One: the deguard exploit step takes more bench time and more careful workflow than older tiers. Two: mainboard removal is required for 8th-gen — significantly more disassembly than T440p. Three: the risk profile is higher. We charge our risk-loaded rate so the £10,000 insurance is properly priced into each unit; a cheaper service that doesn't insure the bench work is taking your money and gambling with your hardware.

Can I just order a Libreboot-flashed laptop instead of sending you mine?

Yes — that's our SENTINEL programme. If you don't already own a ThinkPad, ordering a hand-built unit is often cheaper than buying a used T480 yourself plus our flash service. The SENTINEL programme starts at £4,499 and ships with Libreboot, hardened Arch, the 9-platform identity bundle, YubiKey, CITADEL licence, and the same insurance and warranty as this bench service. Email us for a comparison quote.

// BENCH QUEUE OPEN · NEXT BATCH · CSS-026 //

Ready to ship
your ThinkPad in?

Brief us by PGP-encrypted email or CITADEL. We respond within 24 hours, in writing, signed. The quote is fixed before any deposit, the deposit is refundable until flashing begins, and the work doesn't start until you've read and signed the risk notice.

bench@cyberssl.co.uk · PGP 0x4F2A on request · CITADEL @ops.cyberssl