The compromise that no longer has to be made
For years the choice was open firmware you could audit or a secure element that resisted physical attack. Trezor's earlier models were the open option, and published research showed they could be opened: with the device in hand, a seed could be extracted. The Safe line closes that hole by pairing a certified secure element with firmware that remains fully open and reproducibly buildable.
Why openness matters more than it sounds
Every certified secure element on the market is closed by contract — nobody ships an auditable one. What can be open is everything around it, and that is where the decisions live: how the PIN is checked, what the screen shows before signing, how the passphrase is handled. Trezor publishes all of it and runs a public disclosure process, so problems are found by researchers rather than by owners.
Signing you can actually read
The colour touchscreen decodes transaction details before you approve, which is the feature that prevents the loss that actually happens: a user approving something they did not understand. A device that stores keys perfectly and shows an unreadable hash has solved the wrong problem.
What you give up
Fewer supported chains than Ledger, and older Trezor models remain vulnerable to physical extraction — if you own one, that is a reason to upgrade rather than a reason to distrust the brand.