Just a note - most LineageOS installs aren't secure unless you re-lock the bootloader, as data can be extracted with some fairly standard mobile phone forensics kits. Unfortunately, not many devices support bootloader re-lock. The Google Pixel series is a notable exception.
Ideally, you would want a security hardened Android OS like GrapheneOS. Graphene only runs on Pixels as the development team specifically disallows it running on hardware with an unlocked bootloader for security reasons.
Hah, do they not just block the whole /64? That's actually really funny.