But here’s what matters most: how a wallet uses this chip. This choice defines what you are ultimately asked to trust, and it splits the industry into two fundamentally different philosophies.
Why ‘Trusted’ Hardware Can’t Be Trusted
A standard Secure Element operates on a principle of secrecy. Manufacturers shield their chip’s inner workings with non-disclosure agreements (NDAs).
This makes independent security review impossible. Users and makers alike must take the manufacturer’s word for it. Researchers and hardware wallet makers cannot freely test or publicly discuss what they find. Even if a critical flaw is discovered, the NDA can legally prevent its disclosure, leaving users in the dark.
We learned this the hard way. Years ago, Trezor evaluated a leading Secure Element under NDA for a prototype. Our testing revealed issues we couldn’t publicly discuss, as the NDA prevented transparency.
Two Designs, One Critical Difference
Design 1: The Chip Holds Your Keys
The Logic: Contain all sensitive operations in a tamper-proof box. What You Trust: The chip maker’s reputation, their secret internal code, and the hope their certifications match your real-world threats. The Reality: You get strong physical protection but must accept that the most critical processes are invisible and unauditable.Design 2: The Chip Unlocks Your Keys
The Logic: Strong and verifiable encryption beats hidden secrets. With auditable code, you can prove how your keys are protected. With closed hardware, you can only believe the claims. What You Trust: Cryptography and public code. The Secure Element only handles access control like PIN verification. The Reality: Complete transparency. The chip provides hardware protection without becoming an unverifiable single point of trust.Why We Built for Transparency
This aligns with our founding principle: true security requires transparency, not obscurity. You shouldn’t have to trust us; you should be able to verify how your wallet works.
This commitment to verification guides our entire approach. We believe you should have hardware security without compromise, which is why we advocate for and develop open security tools where every layer of protection can be examined.
The Bottom Line
A Secure Element is not a guarantee of security by itself. It is a component whose value depends entirely on how it is implemented.
_________________________________________________________________________



















