

The GrapheneOS team makes their hardware security requirments very clear.
Its up to the hardware manufactures to include a few additional components used for securely storing keys, so far Google Pixles are the only consistent line of products that do so.
My mental image the solution of your last paragraph is a guy and their counsoler just chatting outside chopping firewood or other simple/quiet lawn work.
“I need a therapist, and a lumberjack”