I would actually like to know what apps want in /proc that they can't get through the API.
The above makes sense if you want to assume that you need /proc at least at some permission level. If you don't (which I think you don't), then it should simply be unmounted in the sandbox.
IPC is the standard way to get out of the sandbox, and should be used also for whatever features the APIs need /proc for.