Wow what a great gift. You’ll love it but read up on all the things you need to do Loud Thunder above has been at it for a while and his advice is solid.
And the encryption code (and also firmware validation) runs in a trusted execution environment (TEE) on the ARM processor. This protects the keys from being accessed by malware.