@QubesParanoia Hello. I added default Kicksecure ram wipe module since it has passed an independent audit. Extracting the disk in zram live mode requires a very large amount of device memory: 64-128 GB, and also involves copying all qubes to the varlibqubes pool, so it’s too specific a use case. I don’t see any issues with disk access, since the disk is required for system boot and is mounted read-only anyway. Regarding dom0 kernel hardening, I removed some hardening options because it caused stability issues on dom0 for some devices used by users in this chat and my friends. I believe it’s sufficient that the disk is read-only and all operations are performed in an entirely separate directory (upper overlay or zram block device). However, in theory, a script could be created specifically for zram mode that copies all AppVMs (or just Whonix-Qubes) to the varlibqubes pool and then extracts the SSD from the device. You could test this and develop a working version based on your experience. Then, we could update the zram mode in my script accordingly. For kernel hardening, I’ve kept only the sysctl options. I also chose not to modify dom0 in default mode, in order to keep the live mode isolated from the default boot.