# Security documentation Understand the foundations of Qualcomm^®^ Linux^®^ Security and its secure components. Get started with security verification and configuration to secure your device. ## Security overview Qualcomm Linux product security An overview of Qualcomm Linux product security and its components. https://docs.qualcomm.com/doc/80-70030-11/topic/overview.html#overview Security architecture Learn about TrustZone and security framework. https://docs.qualcomm.com/doc/80-70030-11/topic/architecture.html#architecture Security features Explore Qualcomm Linux security features, integrating essential hardware and software components to ensure the development of trusted systems. https://docs.qualcomm.com/doc/80-70030-11/topic/features.html#features Security tools Learn about security tools for secure software provisioning and validation workflows. https://docs.qualcomm.com/doc/80-70030-11/topic/tools.html#tools Watch a video on IoT security An introduction to the Qualcomm Processor Security. https://docs.qualcomm.com/doc/80-70030-11/topic/overview.html#section-watch-video-iot-security-label ## Verify security configurations Verify the security configurations of Qualcomm Linux Verify and activate the required security features for Qualcomm Linux development. https://docs.qualcomm.com/doc/80-70030-11/topic/bring-up.html#bring-up ## Configure security services Enable device configurations from Qualcomm TEE Manage Qualcomm^®^ Trusted Execution Environment (Qualcomm TEE) settings through the device configuration framework. https://docs.qualcomm.com/doc/80-70030-11/topic/enable-device-devcfg-from-qtee.html#enable-device-devcfg-from-qtee Enable secure boot Enable secure boot by programming Qualcomm fuse programmable read only memory (QFPROM) fuses, generating keys and certificates, and signing and flashing the image. https://docs.qualcomm.com/doc/80-70030-11/topic/enable-secure-boot.html#enable-secure-boot Enable secure boot on SAIL Enables secure boot on Safety Island (SAIL) to ensure only trusted firmware runs during system startup. https://docs.qualcomm.com/doc/80-70030-11/topic/enable-secure-boot-on-sail.html#enable-secure-boot-on-sail Enable SELinux Enable SELinux to provide a powerful layer of security by enforcing mandatory access control. https://docs.qualcomm.com/doc/80-70030-11/topic/enable-selinux.html#enable-selinux Enable UEFI secure boot Enable unified extensible firmware interface (UEFI) secure boot by generating keys, signing images, and configuring the bootloader to enforce secure startup. https://docs.qualcomm.com/doc/80-70030-11/topic/enable-uefi-secure-boot.html#enable-uefi-secure-boot Install or upgrade soft SKU feature packs Upgrade licensed soft stock keeping unit (SKU) feature packs through Qualcomm^®^ wireless edge services (Qualcomm WES). https://docs.qualcomm.com/doc/80-70030-11/topic/upgrade-qualcomm-wes-feature-pack.html#upgrade-qualcomm-wes-feature-pack ## Customize security services Customize SEPolicy Customize Qualcomm SEPolicy. https://docs.qualcomm.com/doc/80-70030-11/topic/customize.html#section-customize-sepolicy-customization-label ## Debug security issues Debug Qualcomm TEE and secure devices Log and debug security issues. https://docs.qualcomm.com/doc/80-70030-11/topic/debug.html#debug ## Develop applications Develop trusted and client applications Develop and run trusted and client applications, use security APIs and sample code. https://docs.qualcomm.com/doc/80-70030-11/topic/develop_lru.html#develop-lru Last Published: Jun 25, 2026 [Next Topic Security overview](https://docs.qualcomm.com/bundle/publicresource/80-70030-11/topics/overview.md)