I don't run GrapheneOS, but I have an >15 character passphrase that must be used before biometrics can be used after reboot. I haven't used a 4-digit pin since the option to not use it was available.
The specific extra that grapheneOS adds is that you can have a required Fingerprint + PIN with a shorter easier to enter pin while also having a long first unlock passcode. Only a first unlock passcode then biometrics is not secure in the US if your device is in the AFU/biometric-only (after first unlock) state because you can be easily and legally compelled to provide a biometric unlock.
The specific extra that grapheneOS adds is that you can have a required Fingerprint + PIN with a shorter easier to enter pin while also having a long first unlock passcode. Only a first unlock passcode then biometrics is not secure in the US if your device is in the AFU/biometric-only (after first unlock) state because you can be easily and legally compelled to provide a biometric unlock.
https://threecats.au/two-factor-pin-fingerprint-unlock-graph...