I think it means Apple considers their secure enclave "secure"
User data is still encrypted.
I'm not so sure. Wouldn't leaving the bootloader/root filesystem unencrypted make the device more vulnerable to physical tampering by a non-Apple party that could compromise user data?
I'm assuming that these things were previously encrypted/signed with a key that only Apple controls. I could be wrong.
Everything is signed and most likely the parts that do the checking will stay encrypted.