> the first and foremost threat that security auditors would find was "The app runs on a rooted phone!!!".

GrapheneOS is not rooted, or is not required to be.

No it's not, but it's bundled in the same basket. "Didn't pass DEVICE_INTEGRITY -> rooted"