Pixel 3a has been End of Life since May 2022 and regardless of patch level being set by an alternate OS, if more recent, have not received the full patch set since and are running vulnerable firmware. They are not secure devices.
Updates include a whole bunch of hardware-specific patches for both firmware and software for the hardware used by Pixels. This includes a bunch of critical remote code execution fixes. 3rd Gen Pixels are missing all of these patches and anyone advertising them as secure or falsely claiming to provide full security patches should be avoided.