I understand that HD wallet is the most secure.....
The advantage of HD wallets is that it can give you numerous addresses and increase your privacy, not your security.
Exactly, I can decide to generate a paper wallet with BIP38 encryption enabled on an safe, secure and open source airgapped device which offers enough safety and security even without using BIP38 encryption. But just that HD wallet will generate more than enough addresses that can be used for each transaction to enhance privacy.
Also note that 2FA is useless if you install the authenticator application on the same device as your wallet.
This is what most people will be doing, unconscious of the fact that if their device is compromised, the 2FA is also compromised.
But while using 2FA on Electrum, the seed phrase is not stored on the wallet (I am not sure if the seed phrase is stored on the wallet file). If the 2Fa app is on another device, I think this is secure enough also, but TrsutedCoin do request for extra fee which can be discouraging as you mentioned.
If the two wallet is setup appropriately, I think both are good enough, but I will prefer Electrum cold wallet and using watch-only for tracking transactions because its seed phrase and keys are completely generated offline.