Evidence and risk△Partial evidence/■StandardSome material claims still need confirmation.; no material risk recorded in them.
Last reviewedReviewed 5 Jul 2026KYC checked 13 Mar 2026 · inferred jurisdiction · Source → older source, not independently verifiedHow to cite this pageSource coveragePartial evidenceRecorded riskStandard
Evidence and facts
Evidence and facts
CUNICULA SCORE 4.0
41/100△Limited evidencePrivacy 12/25 · Control 0/20 · Transparency 0/20 · Security 25/25 · Accountability 4/10 · Cap 69 · Method
JURISDICTIONUS
NOTESecurity depends on compartmentalization plus prompt updates and required restarts. QSB-116 states that multiple Xen issues could allow a malicious qube to compromise Qubes OS or leak data; patched Xen packages are identified for Qubes 4.3.
KYC TRIGGERSAdvertises No-KYC, but strictly adhere to OPSEC rules. Access via Tor, pay with XMR.
FEEFree
NETWORKSFOSS
CATEGORIESPrivacy OS
TORNot listed
REGIONSGlobal availability
Review analysis, source material, related services, and history
Analysis
OVERVIEW
Qubes OS uses Xen virtualization to isolate different tasks into separate VMs, with the current stable release at 4.3.1 while 4.2 has reached end-of-life.
LIMITS
The Qubes OS Foundation has received about $570,000 in Open Technology Fund (US State Department/USAGM) funding plus a $100,000 USDT grant from Tether/Bitfinex, funding sources the record also associates with Briar, Tor and Signal.
USEFUL FOR
Suited to users who want VM-level compartmentalization of computing tasks and accept a foundation that discloses US government-linked funding.
No identity verification is recorded for typical use. Advertises No-KYC, but strictly adhere to OPSEC rules. Access via Tor, pay with XMR.
Which payment methods are accepted?
Accepted payment methods: FOSS.
Where is it available?
Recorded availability: GLOBAL.
Is the operator based in a Five Eyes country?
Yes. The recorded jurisdiction is US, a Five Eyes country (US, UK, CA, AU, NZ). This is jurisdiction context and does not by itself establish that a service is safer or less safe.
How are identity, operator, and evidence fields reported?
Identity exposure is level 0 of 4. No hosted operator data is recorded. Jurisdiction is shown as context, not a safety verdict. Source coverage is partial evidence, last reviewed 2026-07-05, and recorded risk is standard.
Which payment networks are supported?
Accepted networks: FOSS.
Related Services
DivestOSdivested.devdivested.dev · Privacy Tools · US
No changes to the document we watch since we started checking on 9 Aug 2026. Last checked 9 Aug 2026.
Evidence basis: Claims on this page are linked to published sources for comparison, not certification, audit, endorsement, or recommendation; read the methodology and coverage map before relying on an entry.
Service history
Latest meaningful changes to the facts shown on this provider page.
Apply full-service rereview and score 4.0
Privacy warning, Score assessment
Corporate registry information updated
Corporate / Entity type
Corporate registry information updated
Corporate
Full service history
updated
Reconcile score 4.0 evidence
Score assessment / Control model
local-self-custody → unknown
Score assessment / Operator data exposure
none → unknown
Score assessment / Source model
closed → unknown
Score review
not set → Outcome: HOLD; Checked at: 2026-08-25; Inputs: Operator data exposure: unknown; Control model: unknown; Source model: unknown; Audit: Score eligible: no; Reason: No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit.
not set → Security depends on compartmentalization plus prompt updates and required restarts. QSB-116 states that multiple Xen issues could allow a malicious qube to compromise Qubes OS or leak data; patched Xen packages are identified for Qubes 4.3.
Score assessment
not set → Operator data exposure: none; Control model: local-self-custody; Source model: closed
A reasonably secure operating system using Xen to isolate different parts of your computing life in separate VMs. Current stable release checked as Qubes OS 4.3.1; 4.2 is end-of-life. → Operating system using Xen to isolate activities in separate VMs, with 4.3.1 stable and 4.2 end-of-life.
A reasonably secure operating system. Uses Xen hypervisor to isolate different aspects of your computing life in separate VMs (compartmentalization). Endorsed by Edward Snowden. → A reasonably secure operating system using Xen to isolate different parts of your computing life in separate VMs. Current stable release checked as Qubes OS 4.3.1; 4.2 is end-of-life.