Does it protect it in After First Unlock mode? I often use my device and if I lock it before LE or another bad actor catches it then it's kind of useless if it doesn't protect my data in after first unlock (locked) mode. Especially with LE agencies having tools like Cellebrite at their station for same day analysis. Most people probably won't have time to reboot their device.

Similar to how I use Veracrypt, but I leave my PC running, because I hate spending time booting up again. So LE could decrypt my stuff using RAM extraction stuff.

Yes, it provides strong protection while profiles are in After First Unlock state. It automatically reboots 18 hours after locking by default so there's a time limit on having a working exploit which is highly unlikely. The timer can be set as low as 10 minutes by users.

18 hours was chosen to avoid ever triggering for people who use their phone a couple times a day. For most people, it only needs to be a bit longer than their maximum sleep time to avoid triggering in practice. It's mostly fine if it reboots during the night anyway but people may miss an urgent non-carrier call, etc.

Cellebrite's documentation on Cellebrite Premium capabilities is repeatedly leaked. As of a couple months ago, it still shows they lack exploits for locked GrapheneOS devices updated past a certain 2022 patch level.