I’ve never felt comfortable with the OS side they provide: strange versions of Debian from unknown github accounts or links from their wiki to other third party sites I’ve never heard of. I can build from source but don’t have anything like the resources I’d need to audit the source code, again from third party hacker sites, and it doesn’t feel like there are enough collective eyeballs on the OS forks and patches to feel completely confident nothing careless or nefarious made its way into the codebase.
I’ve no real reason not to trust them, but if they could roll what they need for their system into an upstream vendor with a brand name I’ve heard of it would give me more faith in using their devices in high trust roles (ie: anything other than local coding or web browsing.)