It's not whole-disk encryption, it's file-level encryption which is better. (more security guarantees)
Zeroing allocated memory is complicated because it also has performance benefits, since it improves compressed swap.