Prioritizing compactness on a Phone while maintaining privacy (& security) within the constraints

for resigning and locking the bootloader, can it at least guarantee the attacker wont be able to modify the OS without my signing key?