I have to be more precise:
- My CTs are more protected, because when stealing the host physically, the CTs are not accessible anymore, as they're living in an enc ZFS volume, which has to be manually mounted after each host-reboot
- The root can only then read my CT, when I mounted the enc ZFS...