Then you should probably point out to OP which VPNs are independently audited and not keeping data or not operating in any country requiring access by law enforcement. As everything else would totally defeat your “but government actors”-argument from above.
There’s one caveat here: The UEFI specification doesn’t strictly require the ability to handle more than one EFI System Partition on a drive, so some simply don’t. So this “use a separate boot partition”-method might fail on some computers that just don’t recognize a second ESP on the same drive and only surely works with a whole separate drive for Linux.