If your threat model concerns with hardware/firmware exploits, then you can't trust the physical switches unless they cut all the wires - and unless you can validate that this is what they do. Theoretically speaking, a malicious (or threatened/persuaded/forced) manufacturer may implement a non-standard way to power the supposedly disconnected component using still-connected wiring, to be used for a special occasions.
/tinfoil