I'd personally say something like a one time pad so you can keep it all analog never hurts. Basically turns your single sig backups into two part backup, in that you need to use both the pad you used to encrypt the seed phrase, as well as the ciphertext of the seedphrase, to recover the plaintext of the seedphrase.
Sort of clunky to implement, and requires a lot more hammering into steel, but avoids needing to rely on any sort of algorithmic cryptography that may or may not be as future proof as you really hope it will be.