Looks cool, but:
I don’t think they can even boot from a USB drive? I’m thinking of using a hardware-encrypted-USB (like ones with a keypad built in), set to read-only mode which I would have the bootloader stored in, and use as a boot drive to make it evil-maid resistant. AFIAK, Devices such as the Pinephones only accept microsd cards for boot (correct me if I’m wrong).