I'd take a look at seedsigner. It may not be the most straightforward but you learn much through the process. As you mentioned, having a secre seed is key. The rest is finding an airgapped or minimal-trust solution to sign your seed.
I've used both closed and open-source hw wallets and no problems with using multi-sigs.
If single-sig cold storage will suffice for your needs, I guess bitcoin-core should not be overlooked.
Safety tends to be a trade off between simplicity and security, IMO. But don't overlook either.