Secure booting from LPC18Sxx internal flash

The LPC18xx User Manual has a boot flow chart for encrypted images on flashless parts (Fig 27), but not for encrypted images on chips with internal flash. Figure 27 does make a little note about flash parts: "For parts with on-chip flash, the boot source is checked when the ISP pin is pulled LOW." However, that doesn't specify how the encrypted image in internal flash is handled once the bootloader determines the boot source is internal flash.

Is the encrypted image stored in internal flash decrypted in total to SRAM like for flashless parts? Or is the encrypted image in flash decrypted on-the-fly from flash as needed?