It relies on Heads (
https://github.com/osresearch/heads), tamper-evident boot software that loads from within coreboot and uses the TPM chip and the user’s own GPG keys to detect tampering within the BIOS. Here are some explanations:
https://puri.sm/posts/pureboot-101-first-boot-first-update-a...,
https://docs.puri.sm/Librem_Key/Getting_Started/User_Manual....