Disk Encryption allows you transparently encrypt the writable portion of the local storage medium. In case a device or storage medium gets stolen, no data can be read. Furthermore, disk encryption prevents "evil maid" type attacks where somebody might try to modify the contents of the local storage medium after hours by booting with another OS. Nevertheless, people may wonder - why? Thin Client type devices and VDI endpoints are not supposed to store personal information. Now that is certainly true, but there is still some data that you may or may not define to be worth of protecting, such as your Citrix URL, or private certificates to get onto the network. When switched on, NoTouch will encrypt the writable part of the disk. It will not encrypt the Linux kernel and firmware.