> uses unprivileged containers by default and can be hardened with additional software for syscall filtering
You also described docker.
I agree that docker's main focus isn't to be a security oriented sandbox, but perhaps you need to find a different wording of what exactly makes LXD (or others) so different.