Security
What to know before booting from Ventoy
Community notes on the tool's security posture — written for curious users, not auditors.
Secure Boot
Ventoy ships a signed EFI binary. Some builds require enrolling its key via MokManager the first time.
Image integrity
Ventoy leaves the ISO byte-for-byte intact, so the vendor's checksum still matches after copying.
Password plugin
You can protect the whole menu, an image family, or a single entry with an optional password prompt.
Read-only mode
Advanced users can lock the data partition read-only to prevent accidental writes on shared machines.
Signed source
Releases are published under GPLv3 with detached signatures on GitHub for anyone who wants to verify.
Zero telemetry
The bootloader has no network stack — nothing to phone home.