Way heavier weight, but it seems like the only realistic security layer on the horizon. VMs have it in their bones to be an isolation layer. Everything else has been trying to bolt security onto some fragile bones.
Then again, all theoretical on my part. I keep messing around with Qubes, but not enough to make it my daily driver.
-Access to your private data
-Exposure to untrusted content
-The ability to externally communicate
Then it's not "locked down"
Depending on your security requirements you should have only one or two of those capabilities per VM