This article provides information about ESXi configuration encryption.
In vSphere 7.0 U2 or later, the ESXi configuration is always protected by encryption.
When an ESXi host is protected by a TPM, the ESXi configuration encryption key is sealed by the TPM.
For more information about securing the ESXi configuration, refer to Securing the ESXi Configuration
For vSphere 9.0, refer to Securing the ESX Configuration