A complete trusted boot chain, lack of third-party kernel modules, and remote attestation. Nothing runs in iOS kernel space without Apple saying so (which is NOT the case for desktop operating systems), which is a prerequisite for remote attestation (which iOS also supports).
None of these properties are compromised by allowing arbitrary user-space code, which is what is one of the parents thought would happen.