Can I lock down the U-Boot shell and restrict bootloader access on the Nitrogen95?

Answer

Yes. The i.MX 95's EdgeLock secure enclave and HAB (High Assurance Boot) infrastructure allow you to disable the U-Boot shell on production devices, enable secure boot so only signed images are accepted, and fuse the device to prevent boot from unauthorized media (e.g. SD card) in production. Ezurio's Yocto BSP includes documentation and tooling for enabling HAB and configuring secure boot on the Nitrogen95.