Keystone has open source everything and bitcoin only firmware.
From my understanding ColdCard uses a secure element that is not open source. They just use two secure elements from different manufacturers to stratify and offset hardware risk.
I actually like the ColdCard more and use both of these devices. But objectively Keystone is fully open source and ColdCard is not.