Qubes OS live mode. dom0 in RAM. Non-persistent Boot. RAM-Wipe. Protection against forensics. Tails mode. Hardening dom0. Root read‑only. Paranoid Security. Ephemeral Encryption

Done it too! I suggested they take ideas not just from this thread but also from
Madaidan’s Linux Hardening Guide and from this interesting Qubes hardening guide by @abdullah