OK, no TPM, that's a bummer. The other thing I was expecting was an included Nitrokey, used as a token to decrypt the hard drive (with or without PIN). Obviously with an optional passphrase as alternative, in case the key is damaged or lost. Why not propose this as an option, or is it a bad idea to set up a system like that?