As a startup, I’m ok. But customers will be hit by vulns every year, either with the OS or any layer up to my software, and one of them will have to be upgraded.
The initial release of gadget is released with firmware build by the escrow build process. This will ensure the company actually provides tree that builds the real thing.
But that doesn’t solve the vulnerabilities and the need to have 0-day updates.
You provide a copy to a specified organisation which will keep the physical copy locked until date X. If you release something on local market and the source is not deposited, you get fined until you do. It would only need regulation - which of course we won't get due to many companies that would fight this idea.
Unless you want patent protection, you have no obligation to show your process.