
I remember one cybersec company got hit with an internal communications leak that suggested they could get into any GrapheneOS device before the Pixel 9, AFU or BFU. They were still having trouble with BFU Pixel 9. But this was a year or two ago.
Device wipe before capture/seizure seems to be the highest guarantee.
https://www.androidauthority.com/cellebrite-leak-google-pixel-grapheneos-security-3611794/
Appears I was partially misremembering, they were able to get into older phones on older security patches.