The product is early on in the development stages and we currently use LUKS. Our technicians enter in the decryption password to unlock these servers at the beginning of the day.
When this product makes it to production, providing our customers with the decryption key is definitely a no-go. We need to guarantee that our source code and secrets are protected in addition to ensuring that the system hasn't been tampered with.
What are some common ways to handle this in physical products? Any links or tips on this topic would be massively appreciated!