Wipe the device as a condition of unlocking the bootloader root trust keyset. Easy, and more secure than any classic x86 UEFI bootloader. That gets rid of the threat of dodgy repair shops.
The only issue will be manipulating devices before they're sold the first time, but tamper-proof packaging resolves that.