@rqsd @freemo You'd have to contact the lead developer on Matrix or via email to find out. I haven't asked this question.
What I do know is GrapheneOS builds and signs everything on a dedicated, offline server, completely isolated to everything else. They do use HSMs, but unsure to what extent.
https://daniel.micay.dev/