By decoupling the baseband from the CPU so that it can't directly access the OS's memory+busses and securing communication on the wire (defaulting to secure messaging over Matrix, and using SSL everywhere) so that it can't be sniffed in transit by the modem.
I'm guessing that what this ends up looking like is a USB modem talking to the OS with pppd or a similar model that also enables voice calls over LTE
I'm guessing that what this ends up looking like is a USB modem talking to the OS with pppd or a similar model that also enables voice calls over LTE