GrapheneOS user here. Happy to share experience and talk through how to set things up.
Iāve run almost every flavour of secure comms/OS imaginable, including some of the commercial ones, but ended up sticking with GrapheneOS plus an iPhone/iPad for other business use.
I used to travel with multiple Pixels, but nothing draws more unwarranted attention from government parasites than walking around with a stack of post-crypto phones. On top of that, iOS/iPadOS remains far better supported for the banking apps that now strictly enforce Play Integrity.
I run about 10 profiles on the Pixel and use those as the isolation boundary. For each profile I have Seedvault set up to back up to a WebDAV location of my choosing.
On the resilience side I completely feel you. It happened to me recently that some freshly installed profiles werenāt configured properly for backups. If you donāt explicitly specify certain files/directories, Seedvault simply wonāt back them up. That wiped quite a bit of history and made recovery impossible.
Where possible I try to avoid Wi-Fi and run a couple of layers of active/passive network protection (think something along the lines of SASE, but working across multiple layers).
What are you trying to achieve specifically? Happy to go into more detail on profiles, Seedvault config, network hardening or whatever.