As far as I can tell, the firmware never writes to either MVBAR or VBAR_EL3, and ends up dropping to EL1-NS just before entering the kernel.
So my guess is that either nothing runs there once the kernel has been entered, or there is something in ROM (though very unlikely)
Either way, it looks like binary patching this firmware is pretty easy, and the rumour is that images are not signed. Yet. I'm planning to try something as soon as I get hold of a 1.8v serial adapter.