coreboot

coreboot provides a boot-firmware solution that is secure, fast and reliable. Millions of devices around the world already run on coreboot:
- Fast, light-weight and secure BIOS
- Get maximum security, transparency, and audit-ability
- Select during configuration of your Vault (see compatible models below)
Advantages
Using coreboot on the Vault, instead of the traditional AMI BIOS, has numerous advantages.
1. FAST
- coreboot is very light weight. It is designed to do the minimum amount necessary and get out of the way.
2. BROAD SUPPORT
- coreboot has been validated to work with pfSense, OPNsense, FreeBSD, Untangle, Ubuntu, Windows, and ESXi when used on the Vault
3. DESIGNED FOR SECURITY BY DEFAULT
- Uses a minimal trusted computing base for each platform which is easily auditable, helping to guarantee security.
- As coreboot is Open Source, anyone can check the codebase.
- After it has completed initialization, more than 99% of the code is removed from memory.
- when paired with SecureBoot on the FW6, the solution can be used to ensure that only signed firmware is allowed to run, thereby creating a highly secure environment

How does coreboot stack up?
Should you pick coreboot or the traditional AMI? We’ll help you decide! We at Protectli are big fans of coreboot, mostly because it’s Open Source and therefore the highest level of security available today. We highlighted how both stack up against each other:
coreboot | AMI | |
---|---|---|
Features | ||
BIOS menu options | Not Necessary (customized to hardware) | Standard menu |
Set boot order | mSATA, 2.5" drive, USB, PXE | Fully customizable |
Set power modes & reset | Hardware jumper on MB | Hardware jumper, plus BIOS configuration |
Memory Compatibility | Limited to Kingston & specific other modules * | Also compatible with most major brands |
Custom Boot Splash Screen | ✅ | ✅ |
Enhanced performance (tuned for the Vault) | ✅ | ❌ |
PXE Boot | ✅ | ✅ |
Security | ||
Source Code | Open Source | Proprietary |
Auditability | ✅ | ❌ |
Support | ||
Support Options | Protectli fully supports coreboot & committed to it long-term | Limited |
Release Schedule | Every 6 months, supported by the community | As necessary to address security defects |