OpenBSD was stagnant when it came to hardening for a while, but the last few releases really added new defense in depth technologies e.g. whitelisting all syscall entry points at link time -> if your process doesn't contain fork() and execve() they're is unavailable even after you exploited a RCE. If the process is already restricted by pledge() and unveil() it can't just regain the disabled system calls. These technologies are not a fine grained and "theoretical sound" like a pure capability like FreeBSD's Capsicum, but they're a whole lot easier to retrofit to existing non-trivial applications which means more code is covered by good enough mitigations to drive the attack costs up significantly and make certain (classes of) bugs unexploitable.