# Security documentation
Understand the foundations of Qualcomm^®^ Linux^®^ Security and its secure components. Get started with security verification and configuration to secure your device.
## Security overview
Qualcomm Linux product security
An overview of Qualcomm Linux product security and its components.
https://docs.qualcomm.com/doc/80-70030-11/topic/overview.html#overview
Security architecture
Learn about TrustZone and security framework.
https://docs.qualcomm.com/doc/80-70030-11/topic/architecture.html#architecture
Security features
Explore Qualcomm Linux security features, integrating essential hardware and software components to ensure the development of trusted systems.
https://docs.qualcomm.com/doc/80-70030-11/topic/features.html#features
Security tools
Learn about security tools for secure software provisioning and validation workflows.
https://docs.qualcomm.com/doc/80-70030-11/topic/tools.html#tools
Watch a video on IoT security
An introduction to the Qualcomm Processor Security.
https://docs.qualcomm.com/doc/80-70030-11/topic/overview.html#section-watch-video-iot-security-label
## Verify security configurations
Verify the security configurations of Qualcomm Linux
Verify and activate the required security features for Qualcomm Linux development.
https://docs.qualcomm.com/doc/80-70030-11/topic/bring-up.html#bring-up
## Configure security services
Enable device configurations from Qualcomm TEE
Manage Qualcomm^®^ Trusted Execution Environment (Qualcomm TEE) settings through the device configuration framework.
https://docs.qualcomm.com/doc/80-70030-11/topic/enable-device-devcfg-from-qtee.html#enable-device-devcfg-from-qtee
Enable secure boot
Enable secure boot by programming Qualcomm fuse programmable read only memory (QFPROM) fuses, generating keys and certificates, and signing and flashing the image.
https://docs.qualcomm.com/doc/80-70030-11/topic/enable-secure-boot.html#enable-secure-boot
Enable secure boot on SAIL
Enables secure boot on Safety Island (SAIL) to ensure only trusted firmware runs during system startup.
https://docs.qualcomm.com/doc/80-70030-11/topic/enable-secure-boot-on-sail.html#enable-secure-boot-on-sail
Enable SELinux
Enable SELinux to provide a powerful layer of security by enforcing mandatory access control.
https://docs.qualcomm.com/doc/80-70030-11/topic/enable-selinux.html#enable-selinux
Enable UEFI secure boot
Enable unified extensible firmware interface (UEFI) secure boot by generating keys, signing images, and configuring the bootloader to enforce secure startup.
https://docs.qualcomm.com/doc/80-70030-11/topic/enable-uefi-secure-boot.html#enable-uefi-secure-boot
Install or upgrade soft SKU feature packs
Upgrade licensed soft stock keeping unit (SKU) feature packs through Qualcomm^®^ wireless edge services (Qualcomm WES).
https://docs.qualcomm.com/doc/80-70030-11/topic/upgrade-qualcomm-wes-feature-pack.html#upgrade-qualcomm-wes-feature-pack
## Customize security services
Customize SEPolicy
Customize Qualcomm SEPolicy.
https://docs.qualcomm.com/doc/80-70030-11/topic/customize.html#section-customize-sepolicy-customization-label
## Debug security issues
Debug Qualcomm TEE and secure devices
Log and debug security issues.
https://docs.qualcomm.com/doc/80-70030-11/topic/debug.html#debug
## Develop applications
Develop trusted and client applications
Develop and run trusted and client applications, use security APIs and sample code.
https://docs.qualcomm.com/doc/80-70030-11/topic/develop_lru.html#develop-lru
Last Published: Jun 25, 2026
[Next Topic
Security overview](https://docs.qualcomm.com/bundle/publicresource/80-70030-11/topics/overview.md)