I am aware you can get most of the way there by simply using PGP on TAILS OS (with handwritten paper backups of your keys). But I think the setup below is slightly more secure than even that.
(In the same way, I think storing crypto directly on TAILS OS + bitcoin client installed + handwritten paper wallet, is slightly less secure as compared to using a hardware wallet.)
Most existing security keys, such as Yubikey and whatnot, completely fail at this because they don't have a separate screen where you can see the plaintext or ciphertext. If the main computer has malware, you will just end up signing / encrypting / decrypting malware using the Yubikey.
Features required
Hardware wallet should have minimal firmware on it, not a full linux OS running. Less functionality means less probability of being hacked.
Keys generated on the hardware wallet only.
Allow handwritten paper backup during generation.
Ensure no way to export keys after generation.
All plaintext encrypted and ciphertext decrypted is shown on a screen that is part of the hardware device. This protects even if the main computer has malware on it.
Subscribe
To subscribe, enter "Subscribe " followed by Signal username, email address or whatsapp phone number. You will receive atmost one update per month.
Alternatively, you can subscribe via RSS, or a third-party service like blogtrottr