Thanks for raising closed hardware too, and I presume you are talking about the Intel ME (backdoor spyware [1] that Intel puts into all their chips via their closed source proprietary firmware). It's a complete blackbox, other CPU that no one knows entirely what it does, but has full access to your main CPU/memory/computer, and allows it to be remotely controlled by anyone with Intels signing keys.
We need to open this too, or at least be transparent, and your points on closed firmware/hardware is really important.
You can never truly be sure as it's can't be entirely removed. There has to be a little bit remaining, just the first few modules or the machine will shut down after 30 minutes, but the Librem 15 is a beautiful machine and Puri.sm are really awesome.
Not your OS, not your firmware. Not your hardware. It’s the browser