1) any currently-supported device is good, but i'd say go for minimum pixel 8a if you can
it ships with Memory Tagging Extensions (armv9 security feature) and two more years of support than previous generations; pixel 7 might be eol in oct 2027 https://grapheneos.org/faq#device-lifetime
official recommendation page: https://grapheneos.org/faq#recommended-devices
2) there is no real graphene alternative for other devices. I would say DivestOS at least made sane compromises to support less secure devices, but it's unfortunately defunct now. Yes lineage is still around and still the go-to clean 'ROM' but far from security focused. just avoid stuff like /e/ os
What are the reasons to avoid /e/, according to you? (And not according to the GrapheneOS maintainer).
Thanks! (And thanks to the others responding here too.)