Custom roms with relocked bootloader only work on pixels by design. You’ll have to live with an unlocked bootloader.
As for easy installs, Murena’s e/os exists with support. But I can’t vouch for their cloud ecosystem. Other than that, maybe an officially supported lineage device. You will lose safetynet on both unless you want to root.
Afaik google-pay is prone to fail even with faked safetynet. Magisk can also fix safetynet, but I don’t want to enable root-access. Kinda dumb that the way to fix overcritical security checks is to break security even more. :)
Thanks for the idea though.