What about a vault backed extension? Keys never leave the vault machine unless accessed physically. Signing happens on the machine, browser never sees any of it. Self hosted of course but could scale if needed. Advanced MFA could happen with browsers which is nice as-well