It really depends. Like most pentesters, I'm looking at two factors when I consider a stack like this: first, how big/complex is the exposed attack surface of the stack, and second, how well tested is that attack surface.
For many applications it seems entirely possible to do better with a single multi-tenant app stack than you could with OS virtualization with the same service model. In particular, if, to get the same service model, you had to customize your OS virtualization stack, I'd tack sharply towards preferring a multi-tenant app stack.
I can easily get my head around auditing the Ruby interpreter and its deployment on a Unix host. I've done projects assessing custom virtualization solutions and they are gigantic and complex to test. I'm pretty sure interrupt timing isn't going to screw up Heroku, but that's a flavor of the kind of stuff you have to test with full virtualization.
Finally, I have to add: everything is going to have bugs. You can fully virtualize every customer and every app and you will still eventually be exposed to something bad. The measure of the team is how they handle the exposure, how they fix it, and what they learn from the experience to make the next one harder to find.