Trustonic
Cambridge, UK-based provider of Trusted Execution Environment (TEE) technology embedded in Android device chipsets, used to hardware-isolate sensitive data and credentials from the main device operating system.
Visit Website ↗ + Add to CompareOverview
Trustonic builds and licenses a Trusted Execution Environment (TEE) — a hardware-isolated, physically separate secure area of a device’s main processor, built on Arm TrustZone technology, that stores and processes sensitive data (biometric templates, payment credentials, DRM keys, derived identity credentials) completely walled off from the main Android operating system. Because the TEE runs its own secure operating system independent of Android, an attacker who compromises the main OS still cannot reach data or code running inside it, which is why device manufacturers, mobile carriers, automakers, and financial institutions build payment, authentication, and content-protection features on top of it rather than relying on OS-level protections alone.
Trustonic was formed in 2012 as a joint venture between Arm, Gemalto, and Giesecke & Devrient, combining Arm’s TrustZone silicon technology with security and management software from its two co-founders. The joint-venture structure struggled financially for years, and in 2020 Arm sold its stake, with EMK Capital acquiring full ownership; Trustonic is now an independent, private equity-backed company headquartered in Cambridge, UK with more than 100 employees. Its TEE technology is reported to be embedded in more than 2 billion devices and is used by 9 of the top 10 Android device manufacturers, giving it an unusually deep, if largely invisible, footprint in the mobile device supply chain.
Trustonic’s business model is licensing foundational security infrastructure to device makers and service providers rather than selling a product directly to enterprise security buyers, which makes its relevance indirect: CISOs are more likely to depend on Trustonic’s TEE through the devices and payment/authentication SDKs their organizations already use than to procure it directly.
Innovation Matrix Assessment
As a mature infrastructure licensing business, Trustonic ships incremental extensions of its TEE platform into new verticals (automotive, healthtech, wearables) rather than the rapid feature velocity typical of application-layer security software.
Hardware-level isolation of sensitive data from the main device OS meaningfully reduces the attack surface for credential and payment theft on Android devices, a real operational benefit that OS-level software controls alone cannot replicate.
The joint venture lost money for most of its life before Arm exited in 2020; since being acquired outright by EMK Capital it has continued operating and expanding into automotive and healthtech, but no recent independent revenue or growth figures were found to confirm a strong current trajectory.
TEE technology built on Arm TrustZone has been an established mobile security approach for over a decade; Trustonic is a foundational incumbent supplier in this space rather than an innovator changing the approach.
Reported use by 9 of the top 10 Android device manufacturers and embedding in over 2 billion devices is a strong indirect efficacy signal, since device manufacturers subject security silicon partners to their own qualification processes; no independent penetration-test or CVE history was reviewed directly.
Hardware-backed credential and payment protection remains relevant as mobile devices carry more sensitive data, though Trustonic's relevance is mostly upstream in the device supply chain rather than something enterprise security buyers evaluate directly.
Why CISOs Should Care
Underpins the hardware-level trust that mobile payment, authentication, and DRM features on employee and customer Android devices already rely on, even though most CISOs will never procure it directly.
What Makes It Different
One of the few independent commercial suppliers of TrustZone-based TEE technology at real device-manufacturer scale, as opposed to device makers building the layer entirely in-house.
The Matrix Verdict
47/100 — EMERGING / UNRANKED
A foundational but largely invisible piece of the mobile security supply chain with genuine reach into the Android device ecosystem; stable and relevant infrastructure, though a mature category with limited near-term disruption potential.
Editorial Note: Claims vs. Verified Findings
The Arm/Gemalto/G&D joint-venture history and 2020 EMK Capital acquisition are independently reported by industry press (EE Times, CityAM, ITPro). The '2 billion devices' and '9 of top 10 Android manufacturers' figures are company-stated and not independently audited in this research.
Sources
Alternatives to Trustonic
Cyera
AI-powered, agentless data security platform combining DSPM, DLP, and AI-activity monitoring, and one of the fastest-funded startups in…
Bedrock Data
AI-native data security posture management (DSPM) platform using a Metadata Lake to discover, classify, and contextualize data across…
Halcyon
Ransomware-focused cyber resilience platform combining endpoint prevention, automated recovery, and data exfiltration protection.
Varonis
Data-centric security platform that monitors file, email, and cloud activity to detect insider threats and ransomware before data…
CyberRidge
Photonic-layer encryption that converts transmitted data into optical noise, defending fiber communications against quantum-era decryption.
AWS Wickr
AWS Wickr is Amazon's end-to-end encrypted messaging, voice, video, and file-sharing platform for regulated and government environments, holding…