Hardware & Solutions

14 solutions rated across 10 categories by our panel of co-authors. Only solutions co-authors have personally tested are rated. All ratings pending until voting closes.

Filter:
Solution Type Country CPU Hidden
Subsystem
Open
BIOS
Cost Votes Build
Quality
OS
Range
Security Ease of
Use
Docs Reliability Update
Quality
Privacy Community
Support
Value Consensus
Score
DIFM x86 ME Disabled ✓ Coreboot $400-600
Pre-configured OPNsense on Protectli hardware with remote onboarding and VLAN WiFi. Ratings derived from Protectli (HW) and OPNsense (OS) consensus scores.   HW:   OS:

Consumer Routers & Gateways

Not formally rated by the panel. Approximate scores provided so you can see where your current setup falls relative to dedicated security solutions.

Solution Type Country Subsystem Security Ease of Use Privacy Cost Recurring Note

Firewall Operating Systems

The hardware is only half the equation. The OS determines what your network can actually do. All ratings pending until voting closes.

OS Built On 100%
Open Source
Votes Capability Ease of
Use
Docs Reliability Update
Frequency
Plugin
Ecosystem
Community
Support
Privacy Security
Defaults
Transparency Consensus
Score

Rating Guide

Star Ratings (1-5)

★ = Poor or nonexistent
★★★ = Solid with some gaps
★★★★★ = Best in class

Consensus Score

Average of all 10 category ratings, weighted equally. Higher is better. Only includes votes from co-authors who have personally used the solution. Scores populate after voting closes.

Solution Types

DIFM Do It For Me. Pre-configured, plug and play.
PCS Ships with OS, you configure it.
DIY Bare hardware, you build everything.

Hidden Subsystem

Most processors run a hidden execution environment below the OS at Ring -3. Intel has ME (Management Engine). AMD has PSP (Platform Security Processor). ARM chips have TrustZone.
Disabled = vendor has neutralized it
Active = running proprietary code you cannot inspect
None (SoC) = no separate management processor

Open BIOS

✓ Coreboot = open source BIOS, fully auditable
✓ U-Boot = open source bootloader (ARM/SBC)
= proprietary BIOS, closed source, not auditable

CPU Architecture

x86 Intel/AMD processors. Higher throughput for security processing (IDS/IPS, VPN, DNS filtering).
ARM Lower power, lower cost, but limited throughput for heavy security workloads.

Cost

Average cost range for the hardware only. No additional components or accessories. Actual prices vary by configuration and retailer. Cost does not factor into the consensus score.

Vote Count

Shows how many co-authors rated each solution. More votes = stronger consensus. Solutions with fewer votes may shift in future editions.

Privacy

Does the vendor collect telemetry? Can the OS phone home? Is the firmware auditable? Are there hidden subsystems running code you cannot inspect?

Referenced Solutions

Consumer routers and ISP gateways are shown for context only. Not formally rated by the panel. Approximate scores help you see where your current setup falls.