Pretty big “if” since I’m the only one who knows the long password, I rotate it often, and I hold the keys to encrypt everything. You’re right it’s a single point of fail but a LOT would have to go wrong for it to fail.
Edit: plus 1P supports physical 2FAs to get into the vault itself, if that helps
Paranoia, mostly 😅