What does concern me is the apparent lack of a verified boot option for the phone. I'm not sure, but it appears there's no trusted boot option to use signed firmware and OS. Android and iPhone have had verified boot for years now. Given Librem's focus on privacy and security, and assuming my understanding of the phone's current capabilities is correct, I'm surprised that Librem wasn't able to come up with some solution, particularly given their innovative approaches to firmware security in laptops.
And I jumping to the wrong conclusion? Did they end up implementing a verified boot feature? Last I checked, it wasn't looking very likely. They had pretty much ruled out TPM.
Regardless, a big congratulation to librem. They've accomplished a very difficult goal. I'm guessing that if they don't have a verified boot currently, they're working on it for future versions of the phone.