I believe I remember reading she aims at solving the issue of hardware and software vulnerabilities. I can't find the source, but she mentions that there's too much code out there that it would be impossible to secure everything.
Qubes' design means hardware and software are all separated so a vulnerability in one doesn't mean exposing another.
I like that in their docs they mention an approach they take and when it isn't secure[0]
That being said the main point of security contention is the admin (dom0).