Ubuntu: Engineered for security.
Built for usability
Ubuntu's platform security features are carefully designed to enhance security while providing an intuitive user experience – from hardware roots of trust to secure boot and confidential computing.
Secure boot
Secure boot is a security feature that enforces a chain of trust during the boot process, preventing unauthorized code from running and ensuring that only signed, trusted software is loaded. On Ubuntu, all pre-built boot binaries, except the initrd, are signed with Canonical’s UEFI certificate.
Securing early boot software and firmware is critically important as it acts as a root of trust for the entire platform. When compromised, they allow malware to execute with the highest privileges, even before the OS security mechanisms are loaded.
Full disk encryption

Full-disk encryption
Ubuntu’s full-disk encryption (FDE) protects data at rest against unauthorized access if a device is lost or stolen.
Passphrase-based FDE
Available on Ubuntu Desktop and Server, this option uses Linux Unified Key Setup (LUKS) to encrypt the disk, which users unlock by entering a passphrase at startup.
TPM-backed FDE
Available on supported hardware in Ubuntu Desktop 26.04 LTS and coming to Ubuntu Server, TPM-backed FDE uses the device’s Trusted Platform Module (TPM) to protect encryption keys and automatically unlock the disk when the boot state matches what’s expected. Users can add a PIN or passphrase for extra protection.
Constrain the impact of zero day vulnerabilities with AppArmor
AppArmor enforces Mandatory Access Control through profiles that define strict limits on what applications can access and do. This significantly restrains the attacker’s ability to move laterally within the system.
Ubuntu comes pre-installed with a range of AppArmor profiles for common applications. But if your critical workload application doesn’t have a profile, it is straightforward to create one.
Leading platform for confidential computing
A new threat model
Unlike traditional VMs, where you have to trust that the host software is also secure, confidential VMs only require you to trust the software running within it and the platform’s hardware root of trust. To achieve this, Ubuntu confidential VMs make use of the newer hardware encryption engines to keep your data encrypted in system memory.
Public cloud portfolio
Ubuntu offers the largest portfolio of confidential VMs across all major public cloud providers. It is also the preferred launch partner for all confidential AI offerings that leverage the confidential computing properties of Nvidia’s H100 GPUs.
Private cloud portfolio
Ubuntu is the first enterprise Linux distribution to support both Intel TDX and AMD SEV-SNP across host and guest. With Ubuntu 26.04 LTS, deploy enterprise-ready confidential VMs on your own infrastructure, protecting sensitive data during processing with hardware-backed isolation.
Platform security resources
Ubuntu's defense in depth approach
Ubuntu's security offerings are much more than just a collection of tools. They are an ecosystem of layered defenses, each tuned to address specific threat levels and attacker capabilities. By understanding the unique threats each counter measures, you can make informed choices about which defenses are most important for your environment.
Confidential computing in the private cloud
Your on-premises servers face risks from insider threats and run similar privileged system software as public clouds, making them vulnerable to the same security issues. To enhance confidential computing in private clouds, Canonical offers Intel® Trust Domain Extensions (TDX) on Ubuntu. Intel TDX optimized images include base host and guest operating systems, along with remote attestation capabilities.
Organizations leveraging machine learning in the cloud face concerns over data security and model protection. Strict industry regulations frequently restrict the sharing of sensitive information, limiting AI's potential in critical sectors. Learn how confidential computing can alleviate these concerns.
Enhance your security with vulnerability management and compliance

Ubuntu Pro unlocks the full potential of open source for your enterprise, extending the latest in security maintenance across your entire fleet and elevating your platform security.
Free your team from security patching for up to 15 years, with our comprehensive coverage for your platform – from your OS and infrastructure to your application stack, across desktops, servers, public clouds, and smart devices. Make your pathway to compliance easier, with full access to a trusted repository of open source toolchains and frameworks, as well as hardening configurations and compliance profiles for FIPS, DISA-STIG, and other stringent security standards.