Say if someone got my computer physically and it was logged in already there’s no protection for Qubes so I am wondering is there a way to make certain Qubes encrypted and need passwords to access them?
Encrypted qube or such like how you can encrypt different VM’s when using Fedora Workstation
You can use encrypted volumes such as ZuluCrypt, VeraCrypt, and Cryptomator to store personal data in appVMs. I have a separate qube super‑vault that contains my ZuluCrypt volumes, and I use Cryptomator in some appVMs. For extra protection you can use buskill or USB Kill Switch for Qubes OS - Physical Security Enhancement.
You can used this solutions to defend against forensic analysis: dom0 ZRAM Live Mode dom0 OverlayFS Live Mode
I work only in RAM mode in varlibqubes, but my storage is located in the vm‑pool, so data saved in the encrypted volumes remains after a reboot, while all sessions and processes in varlibqubes are destroyed.