Wth. Does it at least have the decency to use aosp attestation? Or are they just happy to give the keys to the kingdom to Google and require Play Protect?
The point is that the signatures are compared against a database of certified builds - and that exists on Google servers.
If you want AOSP attestation, you need to build your own database to compare against.
It exists on Google's servers for lock in reasons alone.
Which makes sense for them - after all, that makes their competitors break and their ROM doens't.