I've seen several variants of secure laptops. First one is no boot on the disk at all, just a full disk encryption and a bootable CD.
The alternative is generally just full disk encryption.
If you have a super secure laptop that your post leads me to believe you want, you don't want to write to USB ever. This is how data leaks if you ever have the laptop stolen. Instead, enable read-only on the USB ports (you can do this in Windows via regedit, haven't had to do a Linux laptop).
For traveling with secure devices, simply don't travel with the assembled device. Ship the laptop ahead of you, and only travel with the hard drive, which has the sensitive data. The laptop sans drive is mostly useless, and you're acting as the physical courier for the data. The Dell business laptops that only need 1 or 2 screws removed to take out the hard-drive work well for this.
Also use a SSD for FDE, it's just too painful on 5400 rpm.