With certificates/"delegates" (nip-26) you can entrust the private key -- non-extractable -- to a hardware key store like Android Keystore, TPM, dunno what iShnitzels have. Everything else is nincompoop shenanigans.
idk, i've had an idea about wireguard proxies and nsec bunkers (with bonus VPN and nip-05) all configurable from a nostr chatbot, then you can get an antique computer to run that shit for you, would just be a live USB stick with a basic GUI and text editor with hot reload