The Debug Policy apdp partition is flashed with an ELF “mbn” file. It is possible that sections are encrypted. At the very least it is likely signed. From a security perspective, hopefully the vendor signed with a prod key and not a test key.
In my experience, it is possible read to the fuses with a TrustZone TA, at least on a non-secure device.