Mseal alone doesn't seem enough for that. There are plenty of other API's that would also need locking down - and many future API's too. This looks like a big maintenance burden forever into the future.
Perhaps a better model is seccomp BPF. Allow a process to install a seccomp BPF filter on itself. The filter could prevent calling mmap, mprotect, mremap and friends. The filter could also prevent the modification of the installed filter.
That seems far more general and far more powerful and requires less kernel code with only a handful of uses.