I didn’t actually specify it out, but my third backup is an offline SSD that I plug in every once in a while and store at my office. I only mentioned the RAID for local redundancy reasons.
You are right about the data being corrupted, either maliciously or bitrot. The NAS is not accessible outside my home network, so I think I am ok there.
Bitrot would require snapshots and full backups stored over time, which I could do fairly easily but I am currently not.