It uses one open secure element (tropic) and one closed secure element.
So I don't share this new philosophy. There is still an element of trust, and your seed will be vulnerable to a weak PIN or a bug or backdoor in the secure element, so in the end you're going to have to use the passphrase, which brings us back to square one: a seed with a strong passphrase (+128 bits) does not need a secure element.