Shure, but that’s information only FP can provide contactsupport, this is a thread about getting out of the bootloader, hence my suggestion.
If the previous owner didn’t add a Google account there’s a way to trigger a factory reset from recovery via command line IIRC.
If they did or the system is otherwise unbootable you’re out of luck.
Not only that, since the ROMs are signed with test keys the moment that loader becomes available someone could theoratically just include malicious code in one of the partitions, sign it themselves, and switch those out on the phone (still needs physical access though).
Significant parts of the security model (at least for FPOS) rely on EDL to never become accessible, they’ll never release this officially (and there’s probably a bunch of Qualcomm NDAs involved that wouldn’t make it possible anyway).