You'll have a hard time keeping out government, given the hw design seems to share eMMC and RAM between the APE core and the modem-radio core, and modem radio stack is very hardly ever getting opened for at least review (and even when it was, it would only reveal that there's no way to make sure there's no OTA backdoor) IOW: modem can access your data, you can't access (or control) modem. Not even cryptfs will help to fix this. /j