So it's a random key, I think the nuance you are trying to make is that the key is created and kept in the secure element.
My follow up to that would be this:
AFAIK, you cannot do SECP256K1 on these secure elements. So how do you secure the key and use it?
AFAIK, usually you create a key in the secure element, then create another key, encrypt it with the first key and then save it to a file.
This way you can decrypt the file and load the key into memory during use, but the decryption key never leaves the secure element.
I think.