Every GrapheneOS proponent I've seen has claimed that other devices are inferior to Pixel security wise, and that's why they're not supported. That always sounded a bit odd to me and certainly seems to have a bit more nuance based on your comment. Thank you for adding some clarity here.
There's really nothing odd that company that runs Project Zero also builds devices that are well secured.
See their list of device requirements: https://grapheneos.org/faq#future-devices