I'm building Nucleus for exactly this problem - using information flow control and formal methods, we can prevent confused deputies by proofs instead of heuristics.
Very much WIP, would appreciate any feedback. https://github.com/coproduct-opensource/nucleus