Any insight into how this is done without impacting performance for reads as they now need to decrypt the data?
To allow this to double as ”user level” encryption you need to coordinate & manage the keys used vs. just picking something random when the drive is formatted. This is how Apple’s and others’ full-disk encryption has worked for years.