Just got the Model T and using it in place of due to it's backup benefits (thanks to for trying to explain this to me last month), and for for pointing out that the Nitrokey, despite being advertised as such and certified by
Conversation
On-device passphrase entry and confirmation are also really nice features. The main niche is for cryptocurrency wallets but it would be more than worth it for me just for SSH, GPG, U2F and other future encryption / signing use cases. They've got a great core design model for it.

