Earlier quoted context omitted.
Disabling Verified Boot and not having Google Play Services would dramatically reduce the security posture of an Android device. Disclaimer: I work at Google.
you can keep verified boot on custom roms. play services expose you to googles nsa'd taps we'll hear about in 5y. source: im another google engineer
How do you propose a custom rom can establish hardware root of trust without being signed by the device manufacturer?