Qubes OS Project Security Center
- Security FAQ
- Security Goals
- Security Pack
- Security Bulletins
- Xen Security Advisory (XSA) Tracker
- Why and How to Verify Signatures
- PGP Keys
Reporting Security Issues in Qubes OS
If you believe you have found a security issue affecting Qubes OS, either directly or indirectly (e.g. the issue affects Xen in a configuration that is used in Qubes OS), then we would be more than happy to hear from you! We promise to treat any reported issue seriously and, if the investigation confirms that it affects Qubes, to patch it within a reasonable time and release a public Qubes Security Bulletin that describes the issue, discusses the potential impact of the vulnerability, references applicable patches or workarounds, and credits the discoverer.
The Qubes Security Team
The Qubes Security Team can be contacted via email at the following address:
security at qubes-os dot org
Security Team PGP Key
Please use the Security Team PGP Key to encrypt all emails sent to this address. This key is signed by the Qubes Master Signing Key. Please see Why and How to Verify Signatures for information about how to verify these keys.