Can't speak for all projects using STM32.
But every single OP code on COLDCARD is open to review and reproducible. RDP=2 changes the memory map to put our reset vector as first bytes executed. Full part number: STM32L4S5VIT6 check the COLDCARD code and docs to verify it yourself.
It was quite the feat to make it work like that in conjunction with the 2 other secure elements!