Skip to content

Trustonic

Cambridge, UK-based provider of Trusted Execution Environment (TEE) technology embedded in Android device chipsets, used to hardware-isolate sensitive data and credentials from the main device operating system.

Visit Website ↗ + Add to Compare
47/100Emerging / Unranked

Overview

Trustonic builds and licenses a Trusted Execution Environment (TEE) — a hardware-isolated, physically separate secure area of a device’s main processor, built on Arm TrustZone technology, that stores and processes sensitive data (biometric templates, payment credentials, DRM keys, derived identity credentials) completely walled off from the main Android operating system. Because the TEE runs its own secure operating system independent of Android, an attacker who compromises the main OS still cannot reach data or code running inside it, which is why device manufacturers, mobile carriers, automakers, and financial institutions build payment, authentication, and content-protection features on top of it rather than relying on OS-level protections alone.

Trustonic was formed in 2012 as a joint venture between Arm, Gemalto, and Giesecke & Devrient, combining Arm’s TrustZone silicon technology with security and management software from its two co-founders. The joint-venture structure struggled financially for years, and in 2020 Arm sold its stake, with EMK Capital acquiring full ownership; Trustonic is now an independent, private equity-backed company headquartered in Cambridge, UK with more than 100 employees. Its TEE technology is reported to be embedded in more than 2 billion devices and is used by 9 of the top 10 Android device manufacturers, giving it an unusually deep, if largely invisible, footprint in the mobile device supply chain.

Trustonic’s business model is licensing foundational security infrastructure to device makers and service providers rather than selling a product directly to enterprise security buyers, which makes its relevance indirect: CISOs are more likely to depend on Trustonic’s TEE through the devices and payment/authentication SDKs their organizations already use than to procure it directly.

Innovation Matrix Assessment

Innovation Velocity 4/10

As a mature infrastructure licensing business, Trustonic ships incremental extensions of its TEE platform into new verticals (automotive, healthtech, wearables) rather than the rapid feature velocity typical of application-layer security software.

Operational Value 6/10

Hardware-level isolation of sensitive data from the main device OS meaningfully reduces the attack surface for credential and payment theft on Android devices, a real operational benefit that OS-level software controls alone cannot replicate.

Market Momentum 4/10

The joint venture lost money for most of its life before Arm exited in 2020; since being acquired outright by EMK Capital it has continued operating and expanding into automotive and healthtech, but no recent independent revenue or growth figures were found to confirm a strong current trajectory.

Category Disruption 3/10

TEE technology built on Arm TrustZone has been an established mobile security approach for over a decade; Trustonic is a foundational incumbent supplier in this space rather than an innovator changing the approach.

Real-World Efficacy 6/10

Reported use by 9 of the top 10 Android device manufacturers and embedding in over 2 billion devices is a strong indirect efficacy signal, since device manufacturers subject security silicon partners to their own qualification processes; no independent penetration-test or CVE history was reviewed directly.

Enduring Relevance 5/10

Hardware-backed credential and payment protection remains relevant as mobile devices carry more sensitive data, though Trustonic's relevance is mostly upstream in the device supply chain rather than something enterprise security buyers evaluate directly.

Why CISOs Should Care

Underpins the hardware-level trust that mobile payment, authentication, and DRM features on employee and customer Android devices already rely on, even though most CISOs will never procure it directly.

What Makes It Different

One of the few independent commercial suppliers of TrustZone-based TEE technology at real device-manufacturer scale, as opposed to device makers building the layer entirely in-house.

The Matrix Verdict

47/100 — EMERGING / UNRANKED

A foundational but largely invisible piece of the mobile security supply chain with genuine reach into the Android device ecosystem; stable and relevant infrastructure, though a mature category with limited near-term disruption potential.

Editorial Note: Claims vs. Verified Findings

The Arm/Gemalto/G&D joint-venture history and 2020 EMK Capital acquisition are independently reported by industry press (EE Times, CityAM, ITPro). The '2 billion devices' and '9 of top 10 Android manufacturers' figures are company-stated and not independently audited in this research.

Sources