diff --git a/site/docs/linux/index.md b/site/docs/linux/index.md
index 32038c055109a6740177963431bfc4f31d47af8d..6493a138a9acc30633676b97e03e24ef8eda9bb8 100644
--- a/site/docs/linux/index.md
+++ b/site/docs/linux/index.md
@@ -54,8 +54,8 @@ Encrypted /boot via LUKS2 with argon2
 
 Full encryption for basic LUKS2 (with PBKDF or argon2 key derivation) is
 supported in libreboot. Legacy LUKS1 is also supported. On *most* other
-systems, `/boot` must be encrypted, but Libreboot supports use of the
-GRUB bootloader as a coreboot payload.
+systems, `/boot` must be unencrypted, but Libreboot supports use of the
+GRUB bootloader as a coreboot payload, directly in the boot flash.
 
 GRUB has code in it that can be used to unlock LUKS1 and LUKS2 dm-crypt,
 using the `cryptomount` command. With this, you can boot with *true* full