

There might be a better way, but if not, you could have the live boot portion not contain any sensitive data and store your sensitive data within a VeraCrypt container that you access from the live boot after.
Just make sure you use portable versions of any apps that might contain sensitive data as well and store them in the crypt, such as your browser.































This tweet has a different feel now…