Maz34 GrapheneOS is working on adding the owner profile lock pin/password as required or optional before the device can load the system. It will prevent the device from connecting to any saved WiFi or connect to the cellular network in BFU if the sim has no pin code.
As for what can be extracted from a device in BFU state, it would be nice if a kind soul who's in the forensic field can give us a detailed answer about that but from what I know, it can be WiFi saved network, Bluetooth devices paired with the phone, installed apps list, sometimes cell towers the phone has connect, the google email address that is linked with the device in stock os ect.