Seed XOR is an excellent way to make a redundant backup of your seed however. Passphrase risk can be mitigated by using pre-spelled BIP39 words on the ColdCard so I wouldn't panic.
Put copies of two parts in various locations with small bounties but never all the parts
I stop using my coldcard once the mk3 quit getting updates.
At first, I used a 2-of-3 multisig with CoboVault, but the wallet stopped working because of some update. I didn't lose my stack because I had access to the other two keys and I was able to use the CoboVault key with a Seed Signer.
I also had a cobovault. Same situation for me. @SeedSigner is what I recommend now