I can tell you it has NOTHING to do with developer, but more the business/content protection people say unlocked bootloader is not secured.

GrapheneOS runs with a locked bootloader. You temporarily unlock during installation but after re-locking, boot integrity can be validated against GrapheneOS' verified-boot keys. See: https://grapheneos.org/articles/attestation-compatibility-gu...