

On #3: every modern phone running encryption has a BFU (before-first-unlock) state where the data on the device is more secure than after its first unlock because you haven’t entered your password/PIN to decrypt the data. GrapheneOS also has this, but it is not unique to GOS.





No. Even on standard Android, you must enter the password/PIN on first unlock because that is required to load the decryption keys that make biometric authentication work.