Maybe generate the key in the normal processor, send it to apple for escrow, and then push the key to the secure enclave? I have no idea whether the secure enclave supports loading existing keys, but generally this is how it's done.
Rohrer und Klingner Dokumentus ink works great too, it's certified to withstand water, organic solvents, bleach, acids and the lot. It bonds with cellulose, but it won't stick to your fingers!
These people make a VSCode build without M$ telemetry/tracking enabled.