The one question you really want answered from any "secure" or "private" browser fork of Chromium or Firefox is: exactly how, in excruciating detail, do they track upstream security fixes? Are they getting notification of issues alongside the browser vendor, or do they find out only when the public does, when the embargo on disclosure is lifted?
Keeping up with vulnerabilities in browser codebases is a full-time job and there are very few teams in the world who can fund it, so odds are, forked browsers are going to need creative ways to piggyback on their upstream.