Hardware-backed Full Disk Encryption (FDE)

Encryption keys are stored in hardware (like a TPM or otherwise), meaning even if the disk is removed, it cannot be decrypted without the original device.