> not just to be as safe as modern engines, but to be far safer
A worthy goal! However, I'm still concerned. If the project is sufficiently secure without multi-process, adding layers only increases the surface area for attack vectors. Sandboxing not only increases the surface area of your (now) multiple processes, but also introduces the OS layer as an arbiter of communication between them, which we can safely assume does not have memory safety guarantees (though is probably quite hardened).
Of course, the developers would not claim that Servo is "sufficiently secure" right now, especially since (as brson mentioned) it still includes C & C++ source. My point is, sandboxing can be a huge win in terms of security, especially for now; but any complex feature has tradeoffs and the efficacy of those tradeoffs may not continue to hold through the future and should remain open to consideration.