You must not have cats or children if you think that last one is reasonable

Ok just unload the filevault key from ram, better? And if possible tell the secure enclave to revert to the before-first-unlock state