I knew this was too good to be true. The reason Tropicsquare is not mentioned anywhere is that the secure element is "OPTIGA Trust M (V3)" from Infineon. Additionally, it doe's not even protect the keys. Just the PIN. More info in official documentation - https://trezor.io/learn/a/secure-element-in-trezor-safe-3
edit: It also takes care of the device authentication, so you can verify your device really came from Trezor.