Isn't this rather a security theater for the more naive prospective buyers? Even if the device is verified to comply with high-level schematics, it still may not comply on the micro-level. There is the problem with all modem chips being able to access/control phone memory and being potentially controllable by the mobile network operator. How are we going to verify this vulnerability has been removed?
[0] https://wiki.pine64.org/index.php/PinePhone#PinePhone_board_...
[1] https://source.puri.sm/Librem5/community-wiki/-/wikis/Freque...
[2] https://puri.sm/posts/anti-interdiction-services/