lynx forget the hypervisor of choice for a minute, what's your objective? If your windows session is in a VM, what are you trying to isolate it from and why? If your primary objective is security against physical theft, then I wouldn't trust most setups. GrapheneOS in "desktop mode" would arguably be the best, with MacOS on modern Apple hardware coming in second.
I do use Proxmox (both personally and professionally), but I understand it's limitations and act accordingly.