Tamper-evident & physical security
Chain of custody isn't just for forensics labs: serialized seals on a server chassis, a cable lock on the laptop, keyed blockers in the open USB ports. Cheap, visible, auditable controls — and they cross-check with the Faraday line and safes for the full physical layer.
Kensington laptop locks
The physical control auditors actually look for at desks: a cable lock turns grab-and-go laptop theft into noisy, slow work. Check your laptop's slot type first (standard T-Bar vs. the newer Nano/wedge slots).
Combination Cable Lock (K64670AM)
Keyless 4-wheel combo, T-Bar, 6 ft carbon steel — the default pick.
T-Bar Keyed Lock (K65035AM)
Keyed and anti-pick with a 10 mm head for thin laptops. Not for newer Dell wedge slots.
Combination Ultra (K64675US)
60% thicker cut-resistant cable — the heavier-duty option.
Tamper-evident seals — chain of custody
Serialized, one-time-use seals are how evidence handling actually works: number logged, seal applied, any tampering is permanent and obvious. The same discipline works on server chassis, network closets, firmware-flashed laptops, and go-bags.
Wire padlock security seals — 500-pack, serialized
One-time-use, serial-numbered, non-removable without visible evidence. Assets, meters, cases, evidence.
Serialized bag and VOID-label picks get pinned ASINs after live verification — search links until then.
USB port blockers
Keyed physical plugs for unused USB-A/USB-C ports — the anti-juice-jacking, anti-exfil control that costs less than lunch. Pairs with the USB data blocker in the Nitrokey accessories and the Faraday travel kit.
Pinning a specific keyed set after live verification — search link until then.
From our own catalog
Two physical-layer accessories we stock ourselves — not Amazon:
The "harden your workstation" bundle
Cable lock + serialized seals + a Faraday keyfob pouch — the physical layer for a desk or travel kit, added to your Amazon cart in one click.
Add the bundle to your Amazon cart ↗Adds the cable lock, serialized seals, and Faraday keyfob pouch together. Round it out with keyed USB port blockers and our own data blocker.
Prices shown on Amazon. As an Amazon Associate we earn from qualifying purchases made through links on this page.
Controls this line satisfies, mapped across 12 frameworks. A dash means the framework does not address that domain — we don't stretch a control to fill a cell.
Supply chain risk — hardware and firmware
Open-source firmware is publicly auditable and reproducibly built. EU jurisdiction hardware is not subject to US National Security Letters. Directly addresses hardware supply chain risk in CMMC and NIS2.
Hardware attack-surface reduction
Intel Management Engine disabled at the firmware level across every open-firmware machine we carry (NitroPad, NitroPC, PrivacyGuard, SecurityTitan); SecurityTitan models go further — camera and microphone physically removed, anti-tamper seals verified by Heads + Nitrokey attestation. Least functionality, enforced in hardware.
Physical access and asset protection
Rated safes and vaults protect physical assets, documents, and hardware backups with UL-certified burglary ratings — from UL 1037 RSC (residential) up to UL 687 TL-15/TL-30 vault-grade for insurance-mandated or enterprise specialty storage (the tier insurers and auditors recognize; see the ratings ladder on /safe). SecurityTitan laptops extend physical protection to devices in transit: glitter-sealed tamper-evident screws with photographic verification make case intrusion detectable.