Both OpenBSD and FreeBSD have laughable security disclosures and absolute lack of any compliance processes, which is the most important part as a vendor of anything.
FreeBSD even got that far that they invented their own VuXML format (without a spec, of course) instead of adopting an open standard like OVAL, which is used by most enterprise distributions. In the BSD world, vulnerability disclosures happen via mailing lists, aka, bad luck if you missed the email. And that's the definition of being 100% unreliable.
OpenBSD doesn't even have a VuXML file. Only free form text archive of emails that is unparseable.
I don't understand how anyone can claim they are so super duper secure in their development cycle, while not even having a web page of security disclosures that happened in the past. It's pretty damn narcisstic to be honest.