Here is place where I and maybe some other people will share useful info.
Googler: "At the moment, any non-official build will not pass SafetyNet because the system image signature isn't what was expected"
Verified boot (PDF): "Verified boot devices ship with an “OEM Keystore” which is built into the system and signed by a key managed by the OEM"