@Mary the ones worth looking at all do the same three things. open source firmware you can verify, a screen that shows the address you're actually signing, and the option to roll your own entropy. coldcard, jade and trezor safe all clear that bar. pick whichever one you'll actually check the firmware on.