Yes, the boot partition isn't encrypted as it's EFI. So I'm afraid, no "plausible deniability" if that's what you were looking for. Maybe in a separate tutorial 😊
I've set everything up so you can simply install a legacy boot loader in parallel, but I must admit I'm focusing on UEFI systems in this tutorial and haven't tested the legacy boot option.
So far it's starting up nicely on all the machines I'm planning to use it with, but your mileage may obviously vary.