if google would for some reason have hardware different than the specifications, it wont be something that you can see.
If i remeber correcrly, one of the apple processors had a secret hidden register, which wasnt documented at all and was found by chance.
And yes the firmware is not open source and really hard to check, but there is no other option.
In theory all of it can be malicouse, but that doesnt mean that it is so in reality. For google and almost all these companys, normal software is already enough to get the data they desire.
If you really want to know you probably have to either learn the skills to do so yourself or pay someone who can to do it.
I dont think the grapheneOs developers, who already make an whole OS which we dont have to pay for, can be exspected to also verify firmware and hardware, im a way that would statify this level of assurance.
this is my opinion on this