> They're encrypted with keys that remain in hardware. You can never read the keys, only encrypt files with them, from applications running in a separate physical address space, accessible only through the hypervisor.
By 'in hardware', I'm guessing you don't mean real silicon / flash, but rather whatever persistent storage is provided by the SoC vendor's TrustZone implementation. In my opinion calling that 'hardware' implies a level of security and verification that is not actually present, and is disingenuous.
If history has shown us anything, it's that relying on a chipmaker's security assurances for platform software features can only end in tears. You don't need to look very far to find real world examples of exploits against TZ stacks [1].
[1] https://www.blackhat.com/docs/us-15/materials/us-15-Shen-Att...