Yes, but iirc they configured their verified boot setup incorrectly (using the keys Google provides publicly for debug/testing purposes instead of their own secret ones) so someone can easily bypass verified boot and install whatever OS or root kit or whatever they want on your phone if they get physical access to it without the phone detecting that and erasing your personal info. That's why GraphineOS doesn't support the fairphone IIRC.
Yes, but iirc they configured their verified boot setup incorrectly (using the keys Google provides publicly for debug/testing purposes instead of their own secret ones) so someone can easily bypass verified boot and install whatever OS or root kit or whatever they want on your phone if they get physical access to it without the phone detecting that and erasing your personal info. That's why GraphineOS doesn't support the fairphone IIRC.