I don't want to discomfort the developers and I think it's stunning what they are creating...
But under the aspect that they are working on a security product, I'm concerned by their overall code quality and testing strategy.
They might want to consider taking a step back and reevaluating how they are going to direct their development in terms of secure (c-)coding practices.
*Disclaimer: Not a developer, just a sysadmin, but reviewing some of their code/profiles/CI-jobs in their git repo [1] leaves a bad feeling.
[0]: https://www.exploit-db.com/exploits/43359/ [1]: https://github.com/netblue30/firejail/tree/6830065197cc57489...