Regarding encryption as an end customer, on our platform, you can use LUKS or eCryptFS. With HVM mode, you could also use TrueCrypt.
As for how we had leverage, that is very simple -- in exchange for the hardware being returned, we would give them the current encryption passphrase. We then...