Subgraph is also based on Debian and is closer to our philosophy of implementing security features (make any security addition to PureOS that doesn't break user workflow or slows down significantly the OS).
Be sure to use this as main bug but break into all little pieces parts that you find interesting.