After doing some reading, it seems TrueNAS does not support LUKS at all. So with encrypted datasets the data is protected when a single drive gets stolen out of a server, or returned/sold/decomissioned, but when the whole server gets stolen, it boots right up and unlocks any encrypted drives with the on board encryption keys. You can argue how big that issue practically is when the server is locked up in a datacenter, but in the world at large, that's definitely not acceptable.
I hope HexOS can improve on this situation, as many home servers will be small boxes that are portable enough. It walking off is one of the more likely threats, after hardware failure and misconfiguration perhaps.