From my understanding it has to do with the fact that only Google phones contain a security chip which allows you to use verified boot and re-lock the bootloader on a custom ROMS. Graphene's threat model places security over privacy so if that doesn't align with your goals then it probably isn't the product for you
I didn't know Sony had an "Open Devices" program, so thanks for bringing it to my attention. Apart from the price of their phones, I think that makes Sony a strong competitor to Google for people who value privacy over security and want a really good phone (spec-wise) that can flash a custom ROM out of the box.